Lokibot was developed in 2015 to steal information from a variety of applications. Despite the age, this malware is still rather popular among cybercriminals.
MALICIOUS | SUSPICIOUS | INFO |
---|---|---|
Detected artifacts of LokiBot
|
Loads DLL from Mozilla Firefox
|
No info indicators. |
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x0003B0BD | 0x0003B200 | IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ | 6.21675 |
.rdata | 0x0003D000 | 0x000048A1 | 0x00004A00 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ | 3.14547 |
.data | 0x00042000 | 0x000AC0B8 | 0x00002000 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE | 1.26873 |
.idata | 0x000EF000 | 0x00001D25 | 0x00001200 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE | 3.77503 |
.rsrc | 0x000F1000 | 0x0000ADDC | 0x0000AE00 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ | 4.18287 |
.reloc | 0x000FC000 | 0x00001987 | 0x00001A00 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_DISCARDABLE,IMAGE_SCN_MEM_READ | 4.4608 |
No exports.
Click at the process to see the details.
Image |
---|
c:\users\admin\appdata\local\temp\d2790a8d06ab8df067a43d792df8ceb0cab7fb5358235efd4165aa085e79623e.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\msimg32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\ws2_32.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\nsi.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\msvcr100.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\cryptsp.dll |
c:\windows\system32\rsaenh.dll |
c:\windows\system32\cryptbase.dll |
c:\program files\mozilla firefox\nss3.dll |
c:\program files\mozilla firefox\mozglue.dll |
c:\windows\system32\dbghelp.dll |
c:\windows\system32\version.dll |
c:\windows\system32\msvcp140.dll |
c:\windows\system32\vcruntime140.dll |
c:\windows\system32\api-ms-win-crt-runtime-l1-1-0.dll |
c:\windows\system32\ucrtbase.dll |
c:\windows\system32\api-ms-win-core-timezone-l1-1-0.dll |
c:\windows\system32\api-ms-win-core-file-l2-1-0.dll |
c:\windows\system32\api-ms-win-core-localization-l1-2-0.dll |
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll |
c:\windows\system32\api-ms-win-core-processthreads-l1-1-1.dll |
c:\windows\system32\api-ms-win-core-file-l1-2-0.dll |
c:\windows\system32\api-ms-win-crt-heap-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-string-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-stdio-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-locale-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-math-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-time-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-environment-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-utility-l1-1-0.dll |
c:\windows\system32\winmm.dll |
c:\windows\system32\wsock32.dll |
c:\windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll |
c:\program files\mozilla firefox\softokn3.dll |
c:\program files\mozilla firefox\freebl3.dll |
c:\windows\system32\crypt32.dll |
c:\windows\system32\msasn1.dll |
c:\windows\system32\vaultcli.dll |
c:\windows\system32\wininet.dll |
c:\windows\system32\urlmon.dll |
c:\windows\system32\iertutil.dll |
c:\windows\system32\sspicli.dll |
c:\windows\system32\profapi.dll |
c:\windows\system32\netapi32.dll |
c:\windows\system32\netutils.dll |
c:\windows\system32\srvcli.dll |
c:\windows\system32\wkscli.dll |
c:\windows\system32\samcli.dll |
c:\windows\system32\samlib.dll |
c:\windows\system32\userenv.dll |
c:\windows\system32\mswsock.dll |
c:\windows\system32\dnsapi.dll |
c:\windows\system32\iphlpapi.dll |
c:\windows\system32\winnsi.dll |
c:\windows\system32\fwpuclnt.dll |
c:\windows\system32\rasadhlp.dll |
c:\windows\system32\wship6.dll |
c:\windows\system32\wshtcpip.dll |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3236 | d2790a8d06ab8df067a43d792df8ceb0cab7fb5358235efd4165aa085e79623e.exe | POST | 404 | 31.31.196.251:80 | http://mbixch.site/kill/playbook/onelove/fre.php | RU |
binary
text
|
|
malicious |
3236 | d2790a8d06ab8df067a43d792df8ceb0cab7fb5358235efd4165aa085e79623e.exe | POST | 404 | 31.31.196.251:80 | http://mbixch.site/kill/playbook/onelove/fre.php | RU |
binary
text
|
|
malicious |
3236 | d2790a8d06ab8df067a43d792df8ceb0cab7fb5358235efd4165aa085e79623e.exe | POST | 200 | 31.31.196.251:80 | http://mbixch.site/kill/playbook/onelove/fre.php | RU |
binary
binary
|
|
malicious |
PID | Process | IP | ASN | CN | Reputation |
---|---|---|---|---|---|
3236 | d2790a8d06ab8df067a43d792df8ceb0cab7fb5358235efd4165aa085e79623e.exe | 31.31.196.251:80 | Domain names registrar REG.RU, Ltd | RU | malicious |
Domain | IP | Reputation |
---|---|---|
mbixch.site | 31.31.196.251
|
malicious |
dns.msftncsi.com | 131.107.255.255
|
whitelisted |
PID | Process | Class | Message |
---|---|---|---|
3236 | d2790a8d06ab8df067a43d792df8ceb0cab7fb5358235efd4165aa085e79623e.exe | A Network Trojan was detected | ET TROJAN LokiBot User-Agent (Charon/Inferno) |
3236 | d2790a8d06ab8df067a43d792df8ceb0cab7fb5358235efd4165aa085e79623e.exe | A Network Trojan was detected | ET TROJAN LokiBot Checkin |
3236 | d2790a8d06ab8df067a43d792df8ceb0cab7fb5358235efd4165aa085e79623e.exe | A Network Trojan was detected | ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M1 |
3236 | d2790a8d06ab8df067a43d792df8ceb0cab7fb5358235efd4165aa085e79623e.exe | A Network Trojan was detected | ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M2 |
3236 | d2790a8d06ab8df067a43d792df8ceb0cab7fb5358235efd4165aa085e79623e.exe | A Network Trojan was detected | MALWARE [PTsecurity] Loki Bot Check-in M2 |
3236 | d2790a8d06ab8df067a43d792df8ceb0cab7fb5358235efd4165aa085e79623e.exe | A Network Trojan was detected | ET TROJAN LokiBot User-Agent (Charon/Inferno) |
3236 | d2790a8d06ab8df067a43d792df8ceb0cab7fb5358235efd4165aa085e79623e.exe | A Network Trojan was detected | ET TROJAN LokiBot Checkin |
3236 | d2790a8d06ab8df067a43d792df8ceb0cab7fb5358235efd4165aa085e79623e.exe | A Network Trojan was detected | ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M1 |
3236 | d2790a8d06ab8df067a43d792df8ceb0cab7fb5358235efd4165aa085e79623e.exe | A Network Trojan was detected | ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M2 |
3236 | d2790a8d06ab8df067a43d792df8ceb0cab7fb5358235efd4165aa085e79623e.exe | A Network Trojan was detected | MALWARE [PTsecurity] Loki Bot Check-in M2 |
3236 | d2790a8d06ab8df067a43d792df8ceb0cab7fb5358235efd4165aa085e79623e.exe | A Network Trojan was detected | ET TROJAN LokiBot User-Agent (Charon/Inferno) |
3236 | d2790a8d06ab8df067a43d792df8ceb0cab7fb5358235efd4165aa085e79623e.exe | A Network Trojan was detected | ET TROJAN LokiBot Checkin |
3236 | d2790a8d06ab8df067a43d792df8ceb0cab7fb5358235efd4165aa085e79623e.exe | A Network Trojan was detected | ET TROJAN LokiBot Request for C2 Commands Detected M1 |
3236 | d2790a8d06ab8df067a43d792df8ceb0cab7fb5358235efd4165aa085e79623e.exe | A Network Trojan was detected | ET TROJAN LokiBot Request for C2 Commands Detected M2 |
3236 | d2790a8d06ab8df067a43d792df8ceb0cab7fb5358235efd4165aa085e79623e.exe | A Network Trojan was detected | MALWARE [PTsecurity] Loki Bot Check-in M2 |
No debug info.