ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://164.90.194.235/?id=17642814389135937.

Database Entry


IOC ID:516971
IOC: http://164.90.194.235/?id=17642814389135937
IOC Type :url
Threat Type :botnet_cc
Malware: Loki Password Stealer (PWS)
Malware alias:Burkina, Loki, LokiBot, LokiPWS
Confidence Level : Confidence level is elevated (75%)
ASN:AS14061 DIGITALOCEAN-ASN
Country:- US
First seen:2022-04-07 04:52:21 UTC
Last seen:never
UUID:827c15ab-b62e-11ec-8873-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:LokiBot
Reference: https://bazaar.abuse.ch/sample/a412a5da88b8066b205c9fb016c8bc6b28399901c0dda795577f0c466f4f7183/

Avatar
abuse_ch
lokibot (aka Burkina,Loki,LokiBot,LokiPWS) botnet C2

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2022-04-11 07:21:59 5a69a833f77c140256e7381adda4344dcf36245eb4de205d39d1910b0277941d
2022-04-11 01:01:40 a29bc3f87e03f2c38a81fa063f8aebf220fca4f9b488b85cb82d23465f55d068