Trojan

What is “Trojan:Win32/LokiBot.UY!MTB”?

Malware Removal

The Trojan:Win32/LokiBot.UY!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/LokiBot.UY!MTB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Oriya
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/LokiBot.UY!MTB?


File Info:

name: F1B297FBFE7AD7DE8B95.mlw
path: /opt/CAPEv2/storage/binaries/d22963823c4a95a127af41b39598171b0d919a3aa1c5405d0b19982e48e9cba4
crc32: AA11E9E4
md5: f1b297fbfe7ad7de8b956d1d44966d30
sha1: 7a5f509db3fe63850ddc89f17019e9ee482ba1c8
sha256: d22963823c4a95a127af41b39598171b0d919a3aa1c5405d0b19982e48e9cba4
sha512: 69bb19d5823805d34a6c2bed5881aa1b0c60b19c95449d36fc0c80db0933f9482dd309f76636b17139d4e397234a3ae4f758e480e1b187b95a9f9517b50c5626
ssdeep: 3072:Z0e4k5ZfcxdKd4V+pTXb32kObkCS4FUyAXaLrbbJYOsd2:74k5ZfcxdKdu+tL32kOQCS42AbbJD9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FC24BD2126E2CCB1D5E35A3064B1DAA1DF7B78731230829B6B9437EE4F732D08A75752
sha3_384: 9725afc8ad8657b32dbfbe1baab6fe060ea8a779e204499b240d4b9fe1b455e5358c3d45ab78a1cf0b460a9ff60320c8
ep_bytes: e85a310000e989feffff8bff558bec8b
timestamp: 2020-08-06 22:40:48

Version Info:

InternalName: bomgpiaruci.iwa
Copyright: Copyrighz (C) 2021, fudkat
ProductVersion: 13.54.77.27
Translation: 0x0124 0x046a

Trojan:Win32/LokiBot.UY!MTB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.80876
FireEyeGeneric.mg.f1b297fbfe7ad7de
CAT-QuickHealTrojan.Multi
ALYacTrojan.GenericKDZ.80876
MalwarebytesTrojan.MalPack
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00564bda1 )
K7GWTrojan ( 00564bda1 )
Cybereasonmalicious.db3fe6
CyrenW32/Kryptik.FUG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNMU
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Exploit.Win32.Shellcode.gen
BitDefenderTrojan.GenericKDZ.80876
AvastWin32:Trojan-gen
TencentWin32.Exploit.Shellcode.Ectm
Ad-AwareTrojan.GenericKDZ.80876
SophosML/PE-A + Troj/Krypt-BO
DrWebTrojan.Siggen15.58513
TrendMicroTROJ_GEN.R002C0PKU21
McAfee-GW-EditionBehavesLike.Win32.Lockbit.dh
EmsisoftTrojan.Crypt (A)
IkarusTrojan-Ransom.StopCrypt
AviraTR/Crypt.Agent.qzwot
Antiy-AVLTrojan/Generic.ASMalwS.34DE1A1
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/LokiBot.UY!MTB
GDataWin32.Trojan.BSE.11GYDBI
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.MalPE.R454658
Acronissuspicious
McAfeeLockbit-FSWW!F1B297FBFE7A
MAXmalware (ai score=83)
VBA32Trojan.Sabsik.FL
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002C0PKU21
RisingMalware.Heuristic!ET#99% (RDMK:cmRtazo/gYvmPKVLw9232n5ftQhk)
YandexTrojan.Kryptik!0ApRPg8VrJs
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_73%
FortinetW32/Lockbit.FSWW!tr
BitDefenderThetaGen:NN.ZexaF.34062.mC0@aac@JLTG
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan:Win32/LokiBot.UY!MTB?

Trojan:Win32/LokiBot.UY!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment