00000000.00000002.1656396355.0000000006A83000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_Lokibot | Yara detected Lokibot | Joe Security | |
00000000.00000002.1656396355.0000000006A83000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_aPLib_compressed_binary | Yara detected aPLib compressed binary | Joe Security | |
00000000.00000002.1656396355.0000000006A83000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | |
00000000.00000002.1656396355.0000000006A83000.00000004.00000800.00020000.00000000.sdmp | Windows_Trojan_Lokibot_1f885282 | unknown | unknown | - 0x17900:$a1: MAC=%02X%02X%02XINSTALL=%08X%08Xk
|
00000000.00000002.1656396355.0000000006A83000.00000004.00000800.00020000.00000000.sdmp | Windows_Trojan_Lokibot_0f421617 | unknown | unknown | - 0x4ccb:$a: 08 8B CE 0F B6 14 38 D3 E2 83 C1 08 03 F2 48 79 F2 5F 8B C6
|
00000000.00000002.1656396355.0000000006A83000.00000004.00000800.00020000.00000000.sdmp | Lokibot | detect Lokibot in memory | JPCERT/CC Incident Response Group | - 0x1350f:$des3: 68 03 66 00 00
- 0x17900:$param: MAC=%02X%02X%02XINSTALL=%08X%08X
- 0x179cc:$string: 2D 00 75 00 00 00 46 75 63 6B 61 76 2E 72 75 00 00
|
00000002.00000002.1643221958.0000000000400000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_Lokibot | Yara detected Lokibot | Joe Security | |
00000002.00000002.1643221958.0000000000400000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_aPLib_compressed_binary | Yara detected aPLib compressed binary | Joe Security | |
00000002.00000002.1643221958.0000000000400000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | |
00000002.00000002.1643221958.0000000000400000.00000040.00000400.00020000.00000000.sdmp | Windows_Trojan_Lokibot_1f885282 | unknown | unknown | - 0x187f0:$a1: MAC=%02X%02X%02XINSTALL=%08X%08Xk
|
00000002.00000002.1643221958.0000000000400000.00000040.00000400.00020000.00000000.sdmp | Windows_Trojan_Lokibot_0f421617 | unknown | unknown | - 0x53bb:$a: 08 8B CE 0F B6 14 38 D3 E2 83 C1 08 03 F2 48 79 F2 5F 8B C6
|
00000002.00000002.1643221958.0000000000400000.00000040.00000400.00020000.00000000.sdmp | Loki_1 | Loki Payload | kevoreilly | - 0x151b4:$a1: DlRycq1tP2vSeaogj5bEUFzQiHT9dmKCn6uf7xsOY0hpwr43VINX8JGBAkLMZW
- 0x153fc:$a2: last_compatible_version
|
00000002.00000002.1643221958.0000000000400000.00000040.00000400.00020000.00000000.sdmp | Lokibot | detect Lokibot in memory | JPCERT/CC Incident Response Group | - 0x13bff:$des3: 68 03 66 00 00
- 0x187f0:$param: MAC=%02X%02X%02XINSTALL=%08X%08X
- 0x188bc:$string: 2D 00 75 00 00 00 46 75 63 6B 61 76 2E 72 75 00 00
|
00000002.00000002.1643221958.0000000000400000.00000040.00000400.00020000.00000000.sdmp | INDICATOR_SUSPICIOUS_GENInfoStealer | Detects executables containing common artifcats observed in infostealers | ditekSHen | - 0x17936:$f1: FileZilla\recentservers.xml
- 0x17976:$f2: FileZilla\sitemanager.xml
- 0x15be6:$b2: Mozilla\Firefox\Profiles
- 0x15950:$b3: Software\Microsoft\Internet Explorer\IntelliForms\Storage2
- 0x15afa:$s4: logins.json
- 0x169a4:$s6: wand.dat
- 0x15424:$a1: username_value
- 0x15414:$a2: password_value
- 0x15a5f:$a3: encryptedUsername
- 0x15acc:$a3: encryptedUsername
- 0x15a72:$a4: encryptedPassword
- 0x15ae0:$a4: encryptedPassword
|
00000000.00000002.1654874181.00000000036A4000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_Lokibot | Yara detected Lokibot | Joe Security | |
00000000.00000002.1654874181.00000000036A4000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_aPLib_compressed_binary | Yara detected aPLib compressed binary | Joe Security | |
00000000.00000002.1654874181.00000000036A4000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | |
00000000.00000002.1654874181.00000000036A4000.00000004.00000800.00020000.00000000.sdmp | Windows_Trojan_Lokibot_1f885282 | unknown | unknown | - 0x19c18:$a1: MAC=%02X%02X%02XINSTALL=%08X%08Xk
|
00000000.00000002.1654874181.00000000036A4000.00000004.00000800.00020000.00000000.sdmp | Windows_Trojan_Lokibot_0f421617 | unknown | unknown | - 0x6fa3:$a: 08 8B CE 0F B6 14 38 D3 E2 83 C1 08 03 F2 48 79 F2 5F 8B C6
|
00000000.00000002.1654874181.00000000036A4000.00000004.00000800.00020000.00000000.sdmp | Lokibot | detect Lokibot in memory | JPCERT/CC Incident Response Group | - 0x157e7:$des3: 68 03 66 00 00
- 0x19c18:$param: MAC=%02X%02X%02XINSTALL=%08X%08X
- 0x19ce4:$string: 2D 00 75 00 00 00 46 75 63 6B 61 76 2E 72 75 00 00
|
00000000.00000002.1654874181.00000000036DC000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_Lokibot | Yara detected Lokibot | Joe Security | |
00000000.00000002.1654874181.00000000036DC000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_aPLib_compressed_binary | Yara detected aPLib compressed binary | Joe Security | |
00000000.00000002.1654874181.00000000036DC000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | |
00000000.00000002.1654874181.00000000036DC000.00000004.00000800.00020000.00000000.sdmp | Windows_Trojan_Lokibot_1f885282 | unknown | unknown | - 0x19fc8:$a1: MAC=%02X%02X%02XINSTALL=%08X%08Xk
|
00000000.00000002.1654874181.00000000036DC000.00000004.00000800.00020000.00000000.sdmp | Windows_Trojan_Lokibot_0f421617 | unknown | unknown | - 0x7353:$a: 08 8B CE 0F B6 14 38 D3 E2 83 C1 08 03 F2 48 79 F2 5F 8B C6
|
00000000.00000002.1654874181.00000000036DC000.00000004.00000800.00020000.00000000.sdmp | Lokibot | detect Lokibot in memory | JPCERT/CC Incident Response Group | - 0x15b97:$des3: 68 03 66 00 00
- 0x19fc8:$param: MAC=%02X%02X%02XINSTALL=%08X%08X
- 0x1a094:$string: 2D 00 75 00 00 00 46 75 63 6B 61 76 2E 72 75 00 00
|
00000000.00000002.1654874181.00000000036C0000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_Lokibot | Yara detected Lokibot | Joe Security | |
00000000.00000002.1654874181.00000000036C0000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_aPLib_compressed_binary | Yara detected aPLib compressed binary | Joe Security | |
00000000.00000002.1654874181.00000000036C0000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | |
00000000.00000002.1654874181.00000000036C0000.00000004.00000800.00020000.00000000.sdmp | Windows_Trojan_Lokibot_1f885282 | unknown | unknown | - 0x19df0:$a1: MAC=%02X%02X%02XINSTALL=%08X%08Xk
|
00000000.00000002.1654874181.00000000036C0000.00000004.00000800.00020000.00000000.sdmp | Windows_Trojan_Lokibot_0f421617 | unknown | unknown | - 0x717b:$a: 08 8B CE 0F B6 14 38 D3 E2 83 C1 08 03 F2 48 79 F2 5F 8B C6
|
00000000.00000002.1654874181.00000000036C0000.00000004.00000800.00020000.00000000.sdmp | Lokibot | detect Lokibot in memory | JPCERT/CC Incident Response Group | - 0x159bf:$des3: 68 03 66 00 00
- 0x19df0:$param: MAC=%02X%02X%02XINSTALL=%08X%08X
- 0x19ebc:$string: 2D 00 75 00 00 00 46 75 63 6B 61 76 2E 72 75 00 00
|
00000001.00000002.1680125185.0000000000F08000.00000004.00000020.00020000.00000000.sdmp | JoeSecurity_Lokibot_1 | Yara detected Lokibot | Joe Security | |
00000000.00000002.1654874181.0000000003520000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_Lokibot | Yara detected Lokibot | Joe Security | |
00000000.00000002.1654874181.0000000003520000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_aPLib_compressed_binary | Yara detected aPLib compressed binary | Joe Security | |
00000000.00000002.1654874181.0000000003520000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | |
00000000.00000002.1654874181.0000000003520000.00000004.00000800.00020000.00000000.sdmp | Windows_Trojan_Lokibot_1f885282 | unknown | unknown | - 0x181a40:$a1: MAC=%02X%02X%02XINSTALL=%08X%08Xk
|
00000000.00000002.1654874181.0000000003520000.00000004.00000800.00020000.00000000.sdmp | Windows_Trojan_Lokibot_0f421617 | unknown | unknown | - 0x16edcb:$a: 08 8B CE 0F B6 14 38 D3 E2 83 C1 08 03 F2 48 79 F2 5F 8B C6
|
00000000.00000002.1654874181.0000000003520000.00000004.00000800.00020000.00000000.sdmp | Lokibot | detect Lokibot in memory | JPCERT/CC Incident Response Group | - 0x17d60f:$des3: 68 03 66 00 00
- 0x181a40:$param: MAC=%02X%02X%02XINSTALL=%08X%08X
- 0x181b0c:$string: 2D 00 75 00 00 00 46 75 63 6B 61 76 2E 72 75 00 00
|
Process Memory Space: lqoUUYTMsL.exe PID: 7104 | JoeSecurity_Lokibot | Yara detected Lokibot | Joe Security | |
Process Memory Space: lqoUUYTMsL.exe PID: 7104 | JoeSecurity_aPLib_compressed_binary | Yara detected aPLib compressed binary | Joe Security | |
Process Memory Space: lqoUUYTMsL.exe PID: 7104 | Windows_Trojan_Lokibot_1f885282 | unknown | unknown | - 0x14019:$a1: MAC=%02X%02X%02XINSTALL=%08X%08Xk
- 0x4db76:$a1: MAC=%02X%02X%02XINSTALL=%08X%08Xk
- 0x1463e3:$a1: MAC=%02X%02X%02XINSTALL=%08X%08Xk
- 0x149402:$a1: MAC=%02X%02X%02XINSTALL=%08X%08Xk
- 0x1af305:$a1: MAC=%02X%02X%02XINSTALL=%08X%08Xk
|
Process Memory Space: lqoUUYTMsL.exe PID: 6464 | JoeSecurity_Lokibot_1 | Yara detected Lokibot | Joe Security | |
Process Memory Space: lqoUUYTMsL.exe PID: 6408 | JoeSecurity_Lokibot | Yara detected Lokibot | Joe Security | |
Process Memory Space: lqoUUYTMsL.exe PID: 6408 | JoeSecurity_aPLib_compressed_binary | Yara detected aPLib compressed binary | Joe Security | |
Process Memory Space: lqoUUYTMsL.exe PID: 6408 | Windows_Trojan_Lokibot_1f885282 | unknown | unknown | - 0x1f78:$a1: MAC=%02X%02X%02XINSTALL=%08X%08Xk
|
Click to see the 41 entries |