ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://104.248.205.66/index.php/pages?s=1.

Database Entry


IOC ID:1295972
IOC: http://104.248.205.66/index.php/pages?s=1
IOC Type :url
Threat Type :botnet_cc
Malware: Loki Password Stealer (PWS)
Malware alias:Burkina, Loki, LokiBot, LokiPWS
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS14061 DIGITALOCEAN-ASN
Country:- US
First seen:2024-07-09 05:05:13 UTC
Last seen:2024-07-09 22:25:08 UTC
UUID:d33bbdaa-3db0-11ef-ae0a-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:Loki

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2024-07-09 22:10:09 0f3fcd1903a9b4ac99cdc7ed5e32f591ce28312d8fe8981e7b66a61e92b4a573
2024-07-09 05:05:16 e4c4990451cfa8c8a75a65d68c8dc7efde67ba3cdca812636895f8488005da54