Rewterz Threat Alert – LokiBot Malware – IOCs - Rewterz
Tags
attack-pattern: | Data Malware - T1587.001 Malware - T1588.001 Server - T1583.004 Server - T1584.004 Vulnerabilities - T1588.006 Denial Of Service |
Common Information
Type | Value |
---|---|
UUID | 775da34e-064c-42cc-817a-6f9cb96b730a |
Fingerprint | 85926455ffddefcf |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | Nov. 3, 2020, 3:18 p.m. |
Added to db | Dec. 19, 2024, 9 a.m. |
Last updated | Dec. 21, 2024, 9:08 a.m. |
Headline | Rewterz Threat Alert – LokiBot Malware – IOCs |
Title | Rewterz Threat Alert – LokiBot Malware – IOCs - Rewterz |
Detected Hints/Tags/Attributes | 22/1/17 |
Source URLs
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | CVE | 7 | cve-2020-7760 |
|
Details | Domain | 1 | magicview.ga |
|
Details | Domain | 1 | stdygreenkegheedahatakankeadeshnaastfaw.ydns.eu |
|
Details | Domain | 1 | stdyunitedfrkesokoriorimistreetsmsttyr.ydns.eu |
|
Details | Domain | 1 | greenthdykegheedahatakankeadeshnaathfgh.ydns.eu |
|
Details | File | 995 | node.js |
|
Details | IPv4 | 1 | 103.125.191.229 |
|
Details | IPv4 | 2 | 209.141.35.239 |
|
Details | Url | 1 | http://103.125.191.229/office360/regasm.exe |
|
Details | Url | 1 | http://magicview.ga/ibiki/gate.php |
|
Details | Url | 1 | http://stdygreenkegheedahatakankeadeshnaastfaw.ydns.eu/office360/regasm.exe |
|
Details | Url | 1 | http://magicview.ga/kung/gate.php |
|
Details | Url | 1 | http://stdyunitedfrkesokoriorimistreetsmsttyr.ydns.eu/chnsfrnd1/vbc.exe |
|
Details | Url | 1 | http://magicview.ga/rojas/gate.php |
|
Details | Url | 1 | http://greenthdykegheedahatakankeadeshnaathfgh.ydns.eu/office360/regasm.exe |
|
Details | Url | 2 | http://209.141.35.239/33/mto-0217.jpg |
|
Details | Url | 2 | http://209.141.35.239/33/rf-10665.jpg |