MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4e21a93e941a2e0899526af6e6196ab23b2c916bdd01a396a7c546122b1980df. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 15


Intelligence 15 IOCs YARA 2 File information Comments 1

SHA256 hash: 4e21a93e941a2e0899526af6e6196ab23b2c916bdd01a396a7c546122b1980df
SHA3-384 hash: ecd3dced0473b15beb9281b6403b1e2232c217a9810def6ec7bb3c288529a2f76c5d67b232d2d4f5a90f33aac04a2c7e
SHA1 hash: 237e14531cc7c09613edda27ac048aacb46c9efc
MD5 hash: 038cfde5d531e51f39388d24c70e34e9
humanhash: friend-kentucky-alpha-hawaii
File name:038cfde5d531e51f39388d24c70e34e9
Download: download sample
Signature Loki
File size:631'296 bytes
First seen:2023-05-25 15:48:54 UTC
Last seen:2023-05-25 16:13:10 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'740 x AgentTesla, 19'597 x Formbook, 12'241 x SnakeKeylogger)
ssdeep 12288:jaWIm6lVvtzZBEP85enVrcBufSpyX9/iRi6D0WwxnUZf:+TmIt9BEP8YVyXyX9oUn
Threatray 4'199 similar samples on MalwareBazaar
TLSH T1D1D422B03767276AEAEA077104551BF0937F8FAA3472D3971E4BE5C9FB027096441A0B
TrID 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
10.2% (.EXE) Win64 Executable (generic) (10523/12/4)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.3% (.EXE) Win32 Executable (generic) (4505/5/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
File icon (PE):PE icon
dhash icon f89cb2b02cb9f060 (7 x SnakeKeylogger, 5 x Loki, 3 x Formbook)
Reporter zbetcheckin
Tags:32 exe Loki

Intelligence


File Origin
# of uploads :
2
# of downloads :
272
Origin country :
FR FR
Vendor Threat Intelligence
Malware family:
lokibot
ID:
1
File name:
038cfde5d531e51f39388d24c70e34e9
Verdict:
Malicious activity
Analysis date:
2023-05-25 15:50:03 UTC
Tags:
trojan lokibot

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Sending a custom TCP request
Enabling the 'hidden' option for analyzed file
Moving of the original file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
lokibot packed
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Lokibot
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Found malware configuration
Injects a PE file into a foreign processes
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Tries to steal Mail credentials (via file registry)
Yara detected aPLib compressed binary
Yara detected Lokibot
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.LokiBot
Status:
Malicious
First seen:
2023-05-25 08:25:52 UTC
File Type:
PE (.Net Exe)
Extracted files:
7
AV detection:
8 of 23 (34.78%)
Threat level:
  5/5
Result
Malware family:
lokibot
Score:
  10/10
Tags:
family:lokibot collection spyware stealer trojan
Behaviour
Suspicious behavior: RenamesItself
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
outlook_win_path
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Reads user/profile data of web browsers
Lokibot
Malware Config
C2 Extraction:
http://185.246.220.85/fresh/five/fre.php
http://kbfvzoboss.bid/alien/fre.php
http://alphastand.trade/alien/fre.php
http://alphastand.win/alien/fre.php
http://alphastand.top/alien/fre.php
Unpacked files
SH256 hash:
07686bd3670d7660420f09f8771135bb16588e15b45561219ead1841952d38f1
MD5 hash:
046a6366921953d042f7a0ffcb26c50d
SHA1 hash:
2dd27e32320fc0277397f57d24ed4b13d99e09ac
Detections:
lokibot win_lokipws_auto win_lokipws_g0
Parent samples :
4de70d7c97aac4c236396bb488f748b432fda9537e06afa042a77235b1cb8117
36ffec829c35dbf09529550e086446cfd835b4a43c71014ab217783fde2bdb9f
dc77fa38dcbfa8304ae07b051d7658f367286bc92005d327a34c944975719b00
ae4a3ef24f5482b9344969457ac89e08d2598a3721f1725325e86039758f91a2
763fc70c680ac478f31474306d6bb7a0f34893f98d691e0a49b6948a800cf7d4
307b462b554900aa1b0802f4e89752cde49cb4045bc83ac8708578d37ebdadb0
db182e4d02790fa627a9d62e3b9439203d2dd5c88c44a5355a7681b7defe24da
93cc16dfe8c10579f28d8d70196f5c64044493818861f32c9d3e8f15cc3b7aaa
f85b9025ca21804e4ef484b69c89ab2f70de661606b5987e8ff32111256b2a70
90d7dc2cd673fb159368c95d06eb59523898f1498a6d9ce5eb8618690d93e724
15a2d3053598efc70f0ac04252def24ef4dcb216b0ef0a25a957916c8a42207c
72e9d6672de64aae16ae8f4433a9ed08171a7f86decb0d134a03123dd93035d8
21e0ec96d06a0b1e71712fd34ce50e1e4c5a937e8fe8c21f89c5eade948affd5
b6219cebfd6180b0278dc07062893751f3e9c056a23b0b876b2752513cc4a1a5
d3d3facae5e604eded7bf28b146dff57334aa0d9691f1f32eb6f0a30f819bcb8
b7af929b8d99a8a2ec29774cd6c8cf77071b4c865bfe140aedf8b181ce54df89
63b5c9b4340cab3bacf97fd686e3990fef6f00eb6e2f75770d2d8711d09c2464
da108473566740a4ecd7f86677ee7a22779808be300f3329ca4a6d8877d0fcdf
4e21a93e941a2e0899526af6e6196ab23b2c916bdd01a396a7c546122b1980df
d9b8816dc05c98d38419c94b02dc18ebd9494d13088ca2e1bb757f987001c1fd
0709f9e2f76a07b22aa5361179d7120bd8127fc42a0f5c289f73e8f764460092
07d199eaef476d20fa7fde86555086bc6193f7426f4b38513299928f06939d8f
1290e2fa7dd284fcddc2bf9caeac02ccbae1f1e715766eefd7644c245a6ecc53
35c38475ab2e902a2f2c56b2b17f27afb10b3b56365c853a8bb33a9c906366e8
48e32c11cf9fe47ee75f05a9cd9c1bf4598869fe1564eaf7c1bbabf309e823b1
9d19092e410ffb1914d7cd9271ec34b5aa8973eda65fd821851e53921a7017fe
SH256 hash:
e695b2a09ef583eab3ac8be747fb920bba4211b478a4fc9213b339b8dc56bd45
MD5 hash:
f7ab37e7412f3bc65b63b5714c5cc9e9
SHA1 hash:
18b4e1113a2aacd1dfea45eb2f5039551d36b1cb
SH256 hash:
4ecf0883584dd2d9e4e5e3704a9053733d798a14ff518779ddbdfb32aae71807
MD5 hash:
ae61b4fea8f49fccb10fc058968c8f47
SHA1 hash:
a8306fce1883905a6c3e2a54df963bd9ed84faf9
SH256 hash:
b2876080a8892ec02a11cc322cc18952d45f9e419c1cb6d4d070860c59fe87eb
MD5 hash:
803e0c67b76960ff5d9ccb360ba9636b
SHA1 hash:
836d339682618638c6b2e3d156ad66a56e4f9ba5
SH256 hash:
b52c29ba9ef8996bdf721950d900db96f1befb9883eb38c2075528e60c7aabd4
MD5 hash:
7b6143d9d94c8b80d191b77d8b6d1ba2
SHA1 hash:
1c91704ff6da2a9dd8aaa2ff2d5a5f69a445f76b
SH256 hash:
4e21a93e941a2e0899526af6e6196ab23b2c916bdd01a396a7c546122b1980df
MD5 hash:
038cfde5d531e51f39388d24c70e34e9
SHA1 hash:
237e14531cc7c09613edda27ac048aacb46c9efc
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Loki

Executable exe 4e21a93e941a2e0899526af6e6196ab23b2c916bdd01a396a7c546122b1980df

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
zbet commented on 2023-05-25 15:49:02 UTC

url : hxxp://103.14.224.41/510/IE_NET.exe