ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://45.61.136.20/index.php/jlbcyg0q595vs4hef0.

Database Entry


IOC ID:1303634
IOC: http://45.61.136.20/index.php/jlbcyg0q595vs4hef0
IOC Type :url
Threat Type :botnet_cc
Malware: Loki Password Stealer (PWS)
Malware alias:Burkina, Loki, LokiBot, LokiPWS
Confidence Level : Confidence level is high (100%)
ASN:AS399629 BLNWX
Country:- NL
First seen:2024-07-25 16:50:18 UTC
Last seen:never
UUID:f929526b-4aa5-11ef-ae0a-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:Loki

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2024-07-26 06:55:07 ee98f6ee8e92f87f03ff4d3c5764a3b8d384aa0130ce1e7a4d77bd091e8beea3
2024-07-25 16:50:20 ce03ff47b601e4154e103927e9b8e9f9f54f18653fe4bebf0a25f6458009dc0d