ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://45.61.136.239/index.php/gyr.php.

Database Entry


IOC ID:1292470
IOC: http://45.61.136.239/index.php/gyr.php
IOC Type :url
Threat Type :botnet_cc
Malware: Loki Password Stealer (PWS)
Malware alias:Burkina, Loki, LokiBot, LokiPWS
Confidence Level : Confidence level is high (100%)
ASN:AS399629 BLNWX
Country:- NL
First seen:2024-07-02 09:20:19 UTC
Last seen:never
UUID:4d15dcdf-3854-11ef-8261-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:Loki

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2024-07-03 08:05:08 dc98561aa04c9c3d9297d9cbb0612db5c537d2d44381265263c30433b7b955ae
2024-07-02 11:40:18 b2059d6bde8d6af8476a968a13f14486edf3c905495a36cd963dc9765c40863a
2024-07-02 09:20:21 64665200a953a20b6f2a51b1071469a1d4984432da6384b76cc2bd81bd66f85a