ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://montblancgroup.cfd/New/PWS/fre.php.

Database Entry


IOC ID:1605485
IOC: http://montblancgroup.cfd/New/PWS/fre.php
IOC Type :url
Threat Type :botnet_cc
Malware: Loki Password Stealer (PWS)
Malware alias:Burkina, Loki, LokiBot, LokiPWS
Confidence Level : Confidence level is high (100%)
ASN:AS13335 CLOUDFLARENET
Country:- US
First seen:2025-10-02 06:04:09 UTC
Last seen:never
UUID:9c80d6d5-9f55-11f0-894e-42010aa4000a
Reporter DonPasci
Reward 5 credits from ThreatFox
Tags:c2 Loki LokiBot triage
Reference: https://tria.ge/251002-d2zwssgk9v

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2025-10-02 11:50:04 47e2bd28e93c047783c899c3f76765ddb263b3062f50a55c11d32fc354b15c6b