MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1016ef2316ea1fa97ef9c8942743dd4d5cc79eeeae4c549fd4e58eafe088bead. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 1016ef2316ea1fa97ef9c8942743dd4d5cc79eeeae4c549fd4e58eafe088bead
SHA3-384 hash: 9221042b33ad3b58a38f16151f68f28dd58987a3496a641e82371223405340e95ce60bc178ccbc3e6081e12557ac1815
SHA1 hash: 8212f58e1cfbdde45d9dda3b6dbd20c152b096aa
MD5 hash: b8fe6529b283649e10101af154772018
humanhash: magnesium-dakota-seven-johnny
File name:b8fe6529_by_Libranalysis
Download: download sample
Signature Formbook
File size:545'328 bytes
First seen:2021-05-07 19:02:21 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:bHaPZBSQRwL032gcQPYotLbsbMQLor3geHjbva:GP2EwdYXLbsXsbjbva
TLSH 50C4232C4E35AF8EEDA4D84652AD3CD24D77B4BA9CD3294D53809DC23A4ECEC4662F11
Reporter Libranalysis


Avatar
Libranalysis
Uploaded as part of the sample sharing project

Intelligence


File Origin
# of uploads :
1
# of downloads :
118
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Malware family:
lokibot
Score:
  10/10
Tags:
family:lokibot spyware stealer trojan
Behaviour
Creates scheduled task(s)
Suspicious behavior: RenamesItself
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Suspicious use of SetThreadContext
Lokibot
Malware Config
C2 Extraction:
http://megatechs8.com/chief/dv2/blly/fre.php
http://kbfvzoboss.bid/alien/fre.php
http://alphastand.trade/alien/fre.php
http://alphastand.win/alien/fre.php
http://alphastand.top/alien/fre.php
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments