ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://185.246.220.85/ugopounds/five/fre.php.

Database Entry


IOC ID:1137116
IOC: http://185.246.220.85/ugopounds/five/fre.php
IOC Type :url
Threat Type :botnet_cc
Malware: Loki Password Stealer (PWS)
Malware alias:Burkina, Loki, LokiBot, LokiPWS
Confidence Level : Confidence level is high (100%)
ASN:AS44477 UNKNOWN
Country:- MD
First seen:2023-07-10 12:08:02 UTC
Last seen:never
UUID:6b51d6f9-1f1a-11ee-b1e6-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:Loki

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2023-07-11 09:50:11 05a5142cdbaea5fc5bc534e7a6b6cf81e4667e445c50b67ad9afbe692cb29f56
2023-07-10 12:08:04 71c93b4b1cef4f5c4f562ea58850fc63f945c4f7932f0d78d7912fbbf1fa1cee