ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://apponline97.ir/china/Panel/fre.php.

Database Entry


IOC ID:153074
IOC: http://apponline97.ir/china/Panel/fre.php
IOC Type :url
Threat Type :botnet_cc
Malware: Loki Password Stealer (PWS)
Malware alias:Burkina, Loki, LokiBot, LokiPWS
Confidence Level : Confidence level is high (100%)
First seen:2021-06-24 05:36:56 UTC
Last seen:never
UUID:30277a29-d4ae-11eb-b17b-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:Loki

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2021-06-24 11:41:35 a1fe7846c377b67e98dcb11b0a87dd9f1f994c1910caeaa6ce53402bbcb6f444
2021-06-24 05:36:59 dfd6646d16dce4899cf47affa2d22b58ad515146ba71f3583a8f1d0c9cca4cc5