ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://191.101.42.43/fdgd/five/fre.php.

Database Entry


IOC ID:389296
IOC: http://191.101.42.43/fdgd/five/fre.php
IOC Type :url
Threat Type :botnet_cc
Malware: Loki Password Stealer (PWS)
Malware alias:Burkina, Loki, LokiBot, LokiPWS
Confidence Level : Confidence level is high (100%)
ASN:AS212238 CDNEXT
Country:- CZ
First seen:2022-02-19 10:36:01 UTC
Last seen:never
UUID:bb56c389-916f-11ec-a022-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:Loki

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2022-02-20 07:30:09 54cdb71f3d085e8b71384a239116e85f164cf985f03638d752c41acbf62e6a57
2022-02-19 10:36:03 eb34916f411d08471e533196784a1c29ab806a1243cb081443fe3e89ac92aef8