Lokibot was developed in 2015 to steal information from a variety of applications. Despite the age, this malware is still rather popular among cybercriminals.
MALICIOUS | SUSPICIOUS | INFO |
---|---|---|
Application was dropped or rewritten from another process
|
Executable content was dropped or overwritten
|
Manual execution by user
|
Click at the process to see the details.
Image |
---|
c:\program files\winrar\winrar.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\comdlg32.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\powrprof.dll |
c:\windows\system32\setupapi.dll |
c:\windows\system32\cfgmgr32.dll |
c:\windows\system32\devobj.dll |
c:\windows\system32\uxtheme.dll |
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll |
c:\windows\system32\msimg32.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\system32\clbcatq.dll |
c:\windows\system32\propsys.dll |
c:\windows\system32\ntmarta.dll |
c:\windows\system32\wldap32.dll |
c:\windows\system32\riched20.dll |
c:\program files\common files\microsoft shared\ink\tiptsf.dll |
c:\windows\system32\windowscodecs.dll |
c:\windows\system32\apphelp.dll |
c:\windows\system32\ehstorshell.dll |
c:\windows\system32\cscui.dll |
c:\windows\system32\cscdll.dll |
c:\windows\system32\cscapi.dll |
c:\windows\system32\ntshrui.dll |
c:\windows\system32\srvcli.dll |
c:\windows\system32\slc.dll |
c:\windows\system32\imageres.dll |
c:\windows\system32\mpr.dll |
c:\windows\system32\drprov.dll |
c:\windows\system32\winsta.dll |
c:\windows\system32\ntlanman.dll |
c:\windows\system32\davclnt.dll |
c:\windows\system32\davhlpr.dll |
c:\windows\system32\wkscli.dll |
c:\windows\system32\netutils.dll |
c:\windows\system32\wpdshext.dll |
c:\windows\system32\winmm.dll |
c:\windows\system32\portabledeviceapi.dll |
c:\windows\system32\wintrust.dll |
c:\windows\system32\crypt32.dll |
c:\windows\system32\msasn1.dll |
c:\windows\system32\audiodev.dll |
c:\windows\system32\wmvcore.dll |
c:\windows\system32\wmasf.dll |
c:\windows\system32\ehstorapi.dll |
c:\windows\system32\shdocvw.dll |
c:\windows\system32\secur32.dll |
c:\windows\system32\sspicli.dll |
c:\windows\system32\samcli.dll |
c:\windows\system32\samlib.dll |
c:\windows\system32\networkexplorer.dll |
c:\windows\system32\profapi.dll |
c:\windows\system32\explorerframe.dll |
c:\windows\system32\duser.dll |
c:\windows\system32\dui70.dll |
Image |
---|
c:\users\admin\desktop\барање за понуда 2-12-2019·pdf.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\ole32.dll |
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll |
c:\windows\system32\comdlg32.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\olepro32.dll |
c:\windows\system32\apphelp.dll |
Image |
---|
c:\windows\system32\vaultcli.dll |
c:\program files\mozilla firefox\softokn3.dll |
c:\windows\system32\api-ms-win-crt-time-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-math-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-stdio-l1-1-0.dll |
c:\windows\system32\api-ms-win-core-file-l1-2-0.dll |
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll |
c:\windows\system32\api-ms-win-core-localization-l1-2-0.dll |
c:\windows\system32\api-ms-win-core-timezone-l1-1-0.dll |
c:\windows\system32\vcruntime140.dll |
c:\windows\system32\version.dll |
c:\windows\system32\wininet.dll |
c:\windows\system32\netapi32.dll |
c:\windows\system32\srvcli.dll |
c:\windows\system32\wkscli.dll |
c:\windows\system32\userenv.dll |
c:\windows\system32\dnsapi.dll |
c:\windows\system32\rasadhlp.dll |
c:\users\admin\desktop\барање за понуда 2-12-2019·pdf.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\ws2_32.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\nsi.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\cryptsp.dll |
c:\windows\system32\rsaenh.dll |
c:\windows\system32\cryptbase.dll |
c:\program files\mozilla firefox\nss3.dll |
c:\program files\mozilla firefox\mozglue.dll |
c:\windows\system32\dbghelp.dll |
c:\windows\system32\msvcp140.dll |
c:\windows\system32\api-ms-win-crt-runtime-l1-1-0.dll |
c:\windows\system32\ucrtbase.dll |
c:\windows\system32\api-ms-win-core-file-l2-1-0.dll |
c:\windows\system32\api-ms-win-core-processthreads-l1-1-1.dll |
c:\windows\system32\api-ms-win-crt-heap-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-string-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-locale-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-environment-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-utility-l1-1-0.dll |
c:\windows\system32\winmm.dll |
c:\windows\system32\wsock32.dll |
c:\windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll |
c:\program files\mozilla firefox\freebl3.dll |
c:\windows\system32\crypt32.dll |
c:\windows\system32\msasn1.dll |
c:\windows\system32\urlmon.dll |
c:\windows\system32\iertutil.dll |
c:\windows\system32\sspicli.dll |
c:\windows\system32\profapi.dll |
c:\windows\system32\netutils.dll |
c:\windows\system32\samcli.dll |
c:\windows\system32\samlib.dll |
c:\windows\system32\mswsock.dll |
c:\windows\system32\wshtcpip.dll |
c:\windows\system32\wship6.dll |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
1576 | Барање за понуда 2-12-2019·pdf.exe | POST | –– | 107.175.150.73:80 | http://107.175.150.73/~giftioz/.coed/fre.php | US |
binary
––
|
––
|
malicious |
1576 | Барање за понуда 2-12-2019·pdf.exe | POST | –– | 107.175.150.73:80 | http://107.175.150.73/~giftioz/.coed/fre.php | US |
binary
––
|
––
|
malicious |
1576 | Барање за понуда 2-12-2019·pdf.exe | POST | –– | 107.175.150.73:80 | http://107.175.150.73/~giftioz/.coed/fre.php | US |
binary
––
|
––
|
malicious |
PID | Process | IP | ASN | CN | Reputation |
---|---|---|---|---|---|
1576 | Барање за понуда 2-12-2019·pdf.exe | 107.175.150.73:80 | ColoCrossing | US | malicious |
PID | Process | Class | Message |
---|---|---|---|
1576 | Барање за понуда 2-12-2019·pdf.exe | A Network Trojan was detected | ET TROJAN LokiBot User-Agent (Charon/Inferno) |
1576 | Барање за понуда 2-12-2019·pdf.exe | A Network Trojan was detected | ET TROJAN LokiBot Checkin |
1576 | Барање за понуда 2-12-2019·pdf.exe | A Network Trojan was detected | ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M1 |
1576 | Барање за понуда 2-12-2019·pdf.exe | A Network Trojan was detected | ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M2 |
1576 | Барање за понуда 2-12-2019·pdf.exe | A Network Trojan was detected | MALWARE [PTsecurity] Loki Bot Check-in M2 |
1576 | Барање за понуда 2-12-2019·pdf.exe | A Network Trojan was detected | ET TROJAN LokiBot User-Agent (Charon/Inferno) |
1576 | Барање за понуда 2-12-2019·pdf.exe | A Network Trojan was detected | ET TROJAN LokiBot Checkin |
1576 | Барање за понуда 2-12-2019·pdf.exe | A Network Trojan was detected | ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M1 |
1576 | Барање за понуда 2-12-2019·pdf.exe | A Network Trojan was detected | ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M2 |
1576 | Барање за понуда 2-12-2019·pdf.exe | A Network Trojan was detected | MALWARE [PTsecurity] Loki Bot Check-in M2 |
1576 | Барање за понуда 2-12-2019·pdf.exe | A Network Trojan was detected | ET TROJAN LokiBot User-Agent (Charon/Inferno) |
1576 | Барање за понуда 2-12-2019·pdf.exe | A Network Trojan was detected | ET TROJAN LokiBot Checkin |
1576 | Барање за понуда 2-12-2019·pdf.exe | A Network Trojan was detected | ET TROJAN LokiBot Request for C2 Commands Detected M1 |
1576 | Барање за понуда 2-12-2019·pdf.exe | A Network Trojan was detected | ET TROJAN LokiBot Request for C2 Commands Detected M2 |
1576 | Барање за понуда 2-12-2019·pdf.exe | A Network Trojan was detected | MALWARE [PTsecurity] Loki Bot Check-in M2 |
No debug info.