analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Swift_Doc.zip

Full analysis: https://app.any.run/tasks/63d21891-1011-4de7-b9fc-7ed948b67454
Verdict: Malicious activity
Threats:

LokiBot was developed in 2015 to steal information from a variety of applications. Despite the age, this malware is still rather popular among cybercriminals.

Analysis date: July 12, 2020, 20:34:24
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
lokibot
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

23347B698217D1F9122010E41EF00DCC

SHA1:

C83BC0C5F24C254A840BB4278458290709F05FD5

SHA256:

81ED0BDE4F59ED3F28745D29E08CDEA0BB9F096662476710F910173FC6376311

SSDEEP:

3072:9z0GmqtHkNy60Sx2evolEulxkFY/t49WMR8e1OlZdKbxQbdj8nfpcmp6GeUNQJVE:9z0GTtHaD0V+S2FY/kWw1O3gbxKCp2/i

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Swift Doc.exe (PID: 2004)
      • Swift Doc.exe (PID: 2344)
      • Swift Doc.exe (PID: 3676)
      • Swift Doc.exe (PID: 1992)
      • Swift Doc.exe (PID: 2484)
      • Swift Doc.exe (PID: 1540)
      • Swift Doc.exe (PID: 4060)
      • Swift Doc.exe (PID: 652)
      • Swift Doc.exe (PID: 3624)
      • Swift Doc.exe (PID: 2620)
    • LOKIBOT was detected

      • Swift Doc.exe (PID: 2344)
    • Actions looks like stealing of personal data

      • Swift Doc.exe (PID: 2344)
  • SUSPICIOUS

    • Application launched itself

      • Swift Doc.exe (PID: 1992)
      • Swift Doc.exe (PID: 3676)
      • Swift Doc.exe (PID: 2004)
      • Swift Doc.exe (PID: 2620)
      • Swift Doc.exe (PID: 3624)
    • Loads DLL from Mozilla Firefox

      • Swift Doc.exe (PID: 2344)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1828)
      • Swift Doc.exe (PID: 2344)
    • Creates files in the user directory

      • Swift Doc.exe (PID: 2344)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2020:07:06 01:44:07
ZipCRC: 0x105bf77e
ZipCompressedSize: 195834
ZipUncompressedSize: 287744
ZipFileName: Swift Doc.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
11
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start drop and start drop and start drop and start drop and start start winrar.exe swift doc.exe no specs swift doc.exe no specs swift doc.exe no specs #LOKIBOT swift doc.exe swift doc.exe no specs swift doc.exe no specs swift doc.exe no specs swift doc.exe no specs swift doc.exe no specs swift doc.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1828"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Swift_Doc.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
1992"C:\Users\admin\AppData\Local\Temp\Rar$EXa1828.41509\Swift Doc.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1828.41509\Swift Doc.exeWinRAR.exe
User:
admin
Company:
BOGAZİÇİ ÜNİVERSİTESİ
Integrity Level:
MEDIUM
Description:
Puzzle video game 2048
Exit code:
0
Version:
2.0.4.8
3676"C:\Users\admin\AppData\Local\Temp\Rar$EXa1828.41614\Swift Doc.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1828.41614\Swift Doc.exeWinRAR.exe
User:
admin
Company:
BOGAZİÇİ ÜNİVERSİTESİ
Integrity Level:
MEDIUM
Description:
Puzzle video game 2048
Exit code:
0
Version:
2.0.4.8
2004"C:\Users\admin\AppData\Local\Temp\Rar$EXa1828.42267\Swift Doc.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1828.42267\Swift Doc.exeWinRAR.exe
User:
admin
Company:
BOGAZİÇİ ÜNİVERSİTESİ
Integrity Level:
MEDIUM
Description:
Puzzle video game 2048
Exit code:
0
Version:
2.0.4.8
2344"{path}"C:\Users\admin\AppData\Local\Temp\Rar$EXa1828.41509\Swift Doc.exe
Swift Doc.exe
User:
admin
Company:
BOGAZİÇİ ÜNİVERSİTESİ
Integrity Level:
MEDIUM
Description:
Puzzle video game 2048
Version:
2.0.4.8
2484"{path}"C:\Users\admin\AppData\Local\Temp\Rar$EXa1828.41614\Swift Doc.exeSwift Doc.exe
User:
admin
Company:
BOGAZİÇİ ÜNİVERSİTESİ
Integrity Level:
MEDIUM
Description:
Puzzle video game 2048
Exit code:
0
Version:
2.0.4.8
1540"{path}"C:\Users\admin\AppData\Local\Temp\Rar$EXa1828.42267\Swift Doc.exeSwift Doc.exe
User:
admin
Company:
BOGAZİÇİ ÜNİVERSİTESİ
Integrity Level:
MEDIUM
Description:
Puzzle video game 2048
Exit code:
0
Version:
2.0.4.8
2620"C:\Users\admin\AppData\Local\Temp\Rar$EXa1828.14120\Swift Doc.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1828.14120\Swift Doc.exeWinRAR.exe
User:
admin
Company:
BOGAZİÇİ ÜNİVERSİTESİ
Integrity Level:
MEDIUM
Description:
Puzzle video game 2048
Exit code:
0
Version:
2.0.4.8
3624"C:\Users\admin\AppData\Local\Temp\Rar$EXa1828.14458\Swift Doc.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1828.14458\Swift Doc.exeWinRAR.exe
User:
admin
Company:
BOGAZİÇİ ÜNİVERSİTESİ
Integrity Level:
MEDIUM
Description:
Puzzle video game 2048
Exit code:
0
Version:
2.0.4.8
4060"{path}"C:\Users\admin\AppData\Local\Temp\Rar$EXa1828.14120\Swift Doc.exeSwift Doc.exe
User:
admin
Company:
BOGAZİÇİ ÜNİVERSİTESİ
Integrity Level:
MEDIUM
Description:
Puzzle video game 2048
Exit code:
0
Version:
2.0.4.8
Total events
496
Read events
479
Write events
17
Delete events
0

Modification events

(PID) Process:(1828) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1828) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1828) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1828) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(1828) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Swift_Doc.zip
(PID) Process:(1828) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1828) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1828) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1828) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1828) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
6
Suspicious files
0
Text files
0
Unknown types
2

Dropped files

PID
Process
Filename
Type
2344Swift Doc.exeC:\Users\admin\AppData\Roaming\F63AAA\A71D80.lck
MD5:
SHA256:
1828WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1828.41509\Swift Doc.exeexecutable
MD5:6D5DBEFE732E62FB5164FEAD6AF6A887
SHA256:CA9BE111C1E10B81AB16B5434474F09085C62D8D592FCE7E79810AEF284A675E
2344Swift Doc.exeC:\Users\admin\AppData\Roaming\F63AAA\A71D80.exeexecutable
MD5:6D5DBEFE732E62FB5164FEAD6AF6A887
SHA256:CA9BE111C1E10B81AB16B5434474F09085C62D8D592FCE7E79810AEF284A675E
1828WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1828.42267\Swift Doc.exeexecutable
MD5:6D5DBEFE732E62FB5164FEAD6AF6A887
SHA256:CA9BE111C1E10B81AB16B5434474F09085C62D8D592FCE7E79810AEF284A675E
1828WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1828.14458\Swift Doc.exeexecutable
MD5:6D5DBEFE732E62FB5164FEAD6AF6A887
SHA256:CA9BE111C1E10B81AB16B5434474F09085C62D8D592FCE7E79810AEF284A675E
1828WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1828.14120\Swift Doc.exeexecutable
MD5:6D5DBEFE732E62FB5164FEAD6AF6A887
SHA256:CA9BE111C1E10B81AB16B5434474F09085C62D8D592FCE7E79810AEF284A675E
1828WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1828.41614\Swift Doc.exeexecutable
MD5:6D5DBEFE732E62FB5164FEAD6AF6A887
SHA256:CA9BE111C1E10B81AB16B5434474F09085C62D8D592FCE7E79810AEF284A675E
2344Swift Doc.exeC:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\0f5007522459c86e95ffcc62f32308f1_90059c37-1320-41a4-b58d-2b75a9850d2fdbf
MD5:18B8CFC0185C50383AAC0A4F30A9DAC8
SHA256:913E8CED6A447FE791954D382ABA52D490513C5D2F689B391866C7E561F89A03
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

Domain
IP
Reputation
beckhoff-th.com
malicious

Threats

No threats detected
No debug info