ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://checkvim.com/fd3/fre.php.

Database Entry


IOC ID:203455
IOC: http://checkvim.com/fd3/fre.php
IOC Type :url
Threat Type :botnet_cc
Malware: Loki Password Stealer (PWS)
Malware alias:Burkina, Loki, LokiBot, LokiPWS
Confidence Level : Confidence level is elevated (75%)
ASN:AS14618 AMAZON-AES
Country:- US
First seen:2021-08-31 08:35:33 UTC
Last seen:never
UUID:686db40e-0a36-11ec-830d-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:LokiBot
Reference: https://bazaar.abuse.ch/sample/cf9a76a34d8ba45262e4daf903087552f7eae0afb172895aa35aced004565403/

Avatar
abuse_ch
lokibot (aka Loki,LokiPWS,LokiBot) botnet C2

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2021-08-31 19:00:22 feae546686ead19e83ee7f1b9f153f131322e1dc497b0925258bfa93d7e47b1b
2021-08-31 19:00:21 25090850b697f62e5653403538224825541b1a9a1cbc347700e18c9dfb1d67c7
2021-08-31 19:00:20 9ec0497927b9737d71ff1974665ba63edae46533202dab36c23b5b57c7597146