ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://rotomet.mycpanel.rs/ssl/zxc/fre.php.

Database Entry


IOC ID:1548755
IOC: http://rotomet.mycpanel.rs/ssl/zxc/fre.php
IOC Type :url
Threat Type :botnet_cc
Malware: Loki Password Stealer (PWS)
Malware alias:Burkina, Loki, LokiBot, LokiPWS
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS31042 SERBIA-BROADBAND-AS
Country:- RS
First seen:2025-06-23 22:15:43 UTC
Last seen:never
UUID:9ac97c90-507f-11f0-a7f6-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:Loki

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2025-06-23 22:15:46 44f290749db0172e44196d4e2ec0709c4f811e9644c30f4e4c5138b17ecb3fd5