Rewterz Threat Alert – LokiBot Malware – Active IOCs
December 6, 2021Rewterz – Annual Threat Intelligence Report 2021
December 6, 2021Rewterz Threat Alert – LokiBot Malware – Active IOCs
December 6, 2021Rewterz – Annual Threat Intelligence Report 2021
December 6, 2021Severity
High
Analysis Summary
Cryptbot is delivered as a Trojan malware. The Cryptbot Trojan Malware hides within legitimate software in order to be installed by its victims. Some malicious websites and many of them appear on the top pages such as cracks and serials of popular commercial software are entered in search engines, many victims have downloaded this malware and execute on their systems.
Impact
- Credential Theft
- Information Theft
- Expose of Sensitive Data
Indicators of Compromise
MD5
- 281a1e013820e94ca0e8733e05829291
- 2ca4e0dff15609405826cd1a22603f14
- c09964f46df24f2da5fc8849cdf51232
SHA-256
- 8e77c7965e78ba66409c8ce66e80ac0008a7ea7e8986cc4f78dda1cbf07703d7
- c2e81d3ed6e8c5b3d95bf1e17ee1014a57491aade546586364c5d6ecf5f73ecc
- 0982093fa97fd91b15f4dc1db6bb27a2fecd436d431df52ab57357197aa68cee
SHA-1
- 6692d87a9504172bc2f84cc5c15b14e1bf32460d
- 5e0399e0141e55fd04e01b7e6dbb991fd75ecce9
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.