ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://toprolls.com.tr/css/social/js/tsc/fre.php.

Database Entry


IOC ID:229780
IOC: http://toprolls.com.tr/css/social/js/tsc/fre.php
IOC Type :url
Threat Type :botnet_cc
Malware: Loki Password Stealer (PWS)
Malware alias:Burkina, Loki, LokiBot, LokiPWS
Confidence Level : Confidence level is high (100%)
ASN:AS211859 OZKULA
Country:- TR
First seen:2021-10-02 17:11:13 UTC
Last seen:never
UUID:bf00f5a2-23a3-11ec-a35f-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:Loki

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2021-10-02 17:20:52 9648341f475d3cb186c9e64fc5685eb3b42e6956a331b00a4e9a01377cfe2dda
2021-10-02 17:11:16 b80ed5d939395bd4228ab9bb851ab8415c3459e18d1c0778def8a6704216eb66