ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://hfjv9g950bag53fcbcdnbcbnmhy35zch.ga/Marshall/fre.php.

Database Entry


IOC ID:384551
IOC: http://hfjv9g950bag53fcbcdnbcbnmhy35zch.ga/Marshall/fre.php
IOC Type :url
Threat Type :botnet_cc
Malware: Loki Password Stealer (PWS)
Malware alias:Burkina, Loki, LokiBot, LokiPWS
Confidence Level : Confidence level is elevated (75%)
First seen:2022-02-09 15:26:05 UTC
Last seen:never
UUID:98b27432-89bc-11ec-a022-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:LokiBot
Reference: https://bazaar.abuse.ch/sample/d8b7cd38426de559f4219dfdd6fa935c89a2eaa29a3e5dfb28e8b247321e35f6/

Avatar
abuse_ch
lokibot (aka Burkina,Loki,LokiBot,LokiPWS) botnet C2

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2022-02-09 15:31:13 b41191c76f6c7bc6c66ca5f2987591ab38dd634c5441d2195046b93470096131