ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://nesofirenit.gq/stats/fre.php.

Database Entry


IOC ID:281757
IOC: http://nesofirenit.gq/stats/fre.php
IOC Type :url
Threat Type :botnet_cc
Malware: Loki Password Stealer (PWS)
Malware alias:Burkina, Loki, LokiBot, LokiPWS
Confidence Level : Confidence level is elevated (75%)
First seen:2021-12-22 16:36:47 UTC
Last seen:never
UUID:5b32f7aa-6345-11ec-8ab6-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:LokiBot
Reference: https://bazaar.abuse.ch/sample/d95f6a672a8cd7ef0b155d0696e245403611190ff51dccc9f58a0c7f4c90df2e/

Avatar
abuse_ch
lokibot (aka Burkina,Loki,LokiBot,LokiPWS) botnet C2

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2022-01-04 08:25:17 fa8f78ecc58a01cf50c5a60e0ca499da6c5f09171f96cd3b1664ed879f11ae8e
2022-01-03 11:06:05 b81b502e281bc0b2350909e4d3bc2f0695ca1113d44785780225c2d4e0244ff8