ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://209.141.34.39/pote/pin.php.

Database Entry


IOC ID:158384
IOC: http://209.141.34.39/pote/pin.php
IOC Type :url
Threat Type :botnet_cc
Malware: Loki Password Stealer (PWS)
Malware alias:Burkina, Loki, LokiBot, LokiPWS
Confidence Level : Confidence level is elevated (75%)
ASN:AS53667 PONYNET
Country:- CA
First seen:2021-07-07 18:52:37 UTC
Last seen:never
UUID:7f829bf9-df54-11eb-b17b-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:LokiBot
Reference: https://bazaar.abuse.ch/sample/00dc81db82fd264aa369b855dc21957ad780742f0f62ab3d62408e13a457199d/

Avatar
abuse_ch
lokibot (aka Loki,LokiPWS,LokiBot) botnet C2

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2021-07-08 11:45:17 d70f6f599cff525b117325b63eb2b77f07b8569df8f7d9afdffe2125d2814f8e
2021-07-07 19:11:11 00dc81db82fd264aa369b855dc21957ad780742f0f62ab3d62408e13a457199d