ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://alhajikudi.com/life/five/fre.php.

Database Entry


IOC ID:29373
IOC: http://alhajikudi.com/life/five/fre.php
IOC Type :url
Threat Type :botnet_cc
Malware: Loki Password Stealer (PWS)
Malware alias:Burkina, Loki, LokiBot, LokiPWS
Confidence Level : Confidence level is high (100%)
First seen:2021-05-05 15:55:33 UTC
Last seen:never
UUID:52e047dd-adba-11eb-a134-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:Loki

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2021-05-06 04:25:35 312148dcc6a95e0f52319990b3a3a7bcc7276420a2d79dd693a207c4708179a1
2021-05-05 15:55:35 8fad3bbd940b0d99b7026f217fbb8bd97d561b8081d7058030d1a9ff7e6befc7