ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://128.199.46.58/~hgyf/?search=804bbca69db34fdedd7e35b325f9dcac.

Database Entry


IOC ID:375437
IOC: http://128.199.46.58/~hgyf/?search=804bbca69db34fdedd7e35b325f9dcac
IOC Type :url
Threat Type :botnet_cc
Malware: Loki Password Stealer (PWS)
Malware alias:Burkina, Loki, LokiBot, LokiPWS
Confidence Level : Confidence level is high (100%)
ASN:AS14061 DIGITALOCEAN-ASN
Country:- US
First seen:2022-02-02 07:06:56 UTC
Last seen:never
UUID:b531c8ed-83f6-11ec-a824-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:Loki

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2022-02-06 08:29:56 20e7a6550c29fbb3eebd0905011654a9889979f01391fff4710121a79bbb4423
2022-02-02 07:06:58 7cd30803ea76bb0063f8a90f91638ae08bbcfd3370d4634f5840014357c29733