ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://185.198.57.204/kboy/sync/fre.php.

Database Entry


IOC ID:139716
IOC: http://185.198.57.204/kboy/sync/fre.php
IOC Type :url
Threat Type :botnet_cc
Malware: Loki Password Stealer (PWS)
Malware alias:Burkina, Loki, LokiBot, LokiPWS
Confidence Level : Confidence level is high (100%)
ASN:AS60117 HS
Country:- AE
First seen:2021-06-22 00:11:05 UTC
Last seen:never
UUID:5644bce2-d2ee-11eb-b17b-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:Loki

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2021-06-22 12:10:37 95adc30ed6495e078a795b6184442b4147e87e1e48bd040467c0d190cabbf092
2021-06-22 00:11:08 ab1cef822f66d7b77574a21c8154d4a6e9fcd196a6659637f1d662f0ef7df3bd