Rewterz
Rewterz Threat Alert – LokiBot Malware – Active IOCs
December 6, 2021
Rewterz – Annual Threat Intelligence Report 2021
December 6, 2021

Rewterz Threat Alert – CryptBot Trojan – Active IOCs

Severity

High

Analysis Summary

Cryptbot is delivered as a Trojan malware. The Cryptbot Trojan Malware hides within legitimate software in order to be installed by its victims. Some malicious websites and many of them appear on the top pages such as cracks and serials of popular commercial software are entered in search engines, many victims have downloaded this malware and execute on their systems.

Impact

  • Credential Theft
  • Information Theft
  • Expose of Sensitive Data

Indicators of Compromise

MD5

  • 281a1e013820e94ca0e8733e05829291
  • 2ca4e0dff15609405826cd1a22603f14
  • c09964f46df24f2da5fc8849cdf51232

SHA-256

  • 8e77c7965e78ba66409c8ce66e80ac0008a7ea7e8986cc4f78dda1cbf07703d7
  • c2e81d3ed6e8c5b3d95bf1e17ee1014a57491aade546586364c5d6ecf5f73ecc
  • 0982093fa97fd91b15f4dc1db6bb27a2fecd436d431df52ab57357197aa68cee

SHA-1

  • 6692d87a9504172bc2f84cc5c15b14e1bf32460d
  • 5e0399e0141e55fd04e01b7e6dbb991fd75ecce9

Remediation

  • Block all threat indicators at your respective controls.
  • Search for IOCs in your environment.