ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://hstfurnaces.net/gd22/fre.php.

Database Entry


IOC ID:392963
IOC: http://hstfurnaces.net/gd22/fre.php
IOC Type :url
Threat Type :botnet_cc
Malware: Loki Password Stealer (PWS)
Malware alias:Burkina, Loki, LokiBot, LokiPWS
Confidence Level : Confidence level is elevated (75%)
First seen:2022-03-08 11:55:59 UTC
Last seen:never
UUID:b8892238-9ed6-11ec-a022-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:LokiBot
Reference: https://bazaar.abuse.ch/sample/2f0b6e30d2b2ed52391c6fe69af7bc4cf2556ba9e40fc97371194e1fe2cf4910/

Avatar
abuse_ch
lokibot (aka Burkina,Loki,LokiBot,LokiPWS) botnet C2

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2022-03-09 23:26:29 8ddb0758d53faee14a362ad086fdf59ed5bb9dcc308f3619f0fe68cb5cf0c5d8
2022-03-09 22:01:27 c921fbd6370ff582576be23c6bd4e122fd2e4d743c014b41201a6b1b3f3a4521