Rewterz Threat Alert – Malspam Campaign Dropping Loki Bot Malware

Thursday, July 11, 2019



Analysis Summary

Loki-Bot (also spelled “Loki Bot” or “LokiBot”) is an information stealer that sends login credentials and other sensitive data from an infected Windows host to a server established for each malware sample. LokiBot is a prolific trojan designed to covertly siphon information from compromised endpoints. The malware is known for being simple and effective and for its adoption of diverse attachment types.


  • Exposure of sensitive information
  • Credential theft

Indicators of Compromise

IP(s) / Hostname(s)



  • hxxp[:]//kamnaexim[.]com/bui/cu/total[.]exe
  • hxxp[:]//www.dnll[.]pw/la/stone/fre[.]php

Email Address


Malware Hash (MD5/SHA1/SH256)

  • 1b76734447ec104a4fc399c430dd007a
  • a427dcac18d98d24d814d279cb436d22bccb84e60b8f0d30ab793262d93f2b92
  • ed9972a3730f4310c70deb88f8e73cdb9bef86a2cc36c0068ea421dc8f932b25
  • 13404b29411193d09f1884147f84dd15
  • 13a35d9c157c65d14ee288b77e1b7eec14142af7
  • 2c249547abd254445b63e8b594eef7503093dcdf


  • Block the threat indicators at their respective controls.
  • Always be suspicious of unsolicited email.
  • Never click/ download any attachments sent from unrecognized senders.

Data Sheets

Corporate Brochure

Our Story



Managed Security

Upcoming Rewterz Trainings/Events

Rewterz News

  • 11, October 2019 Rewterz Threat Alert – Kimsuky Group – IOC’s
  • 11, October 2019 Rewterz Threat Advisory – CVE-2019-10936 – Siemens PROFINET Devices Denial of Service Vulnerability
  • 11, October 2019 Rewterz Threat Advisory – CVE-2019-10923 – Siemens Industrial Real-Time (IRT) Devices DoS Vulnerability
  • 10, October 2019 Rewterz Threat Alert – Another Agenttesla campaign using a compromised Iraq Government site

Copyright © Rewterz. All rights reserved.