ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://45.133.1.45/me/five/fre.php.

Database Entry


IOC ID:518528
IOC: http://45.133.1.45/me/five/fre.php
IOC Type :url
Threat Type :botnet_cc
Malware: Loki Password Stealer (PWS)
Malware alias:Burkina, Loki, LokiBot, LokiPWS
Confidence Level : Confidence level is high (100%)
ASN:AS203320 TURIEN-AS
Country:- NL
First seen:2022-04-11 11:41:24 UTC
Last seen:2022-04-21 12:32:13 UTC
UUID:51080184-b98c-11ec-8873-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:Loki

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2022-04-12 06:25:28 86c6cc93d8405840ca3be8cbc58db75d6ed324c115461969aebcbf0a84f13a21
2022-04-11 19:26:19 716cef6988e3d7cc2a4bbcc7140995c280a23b2e6b54824eac031fdb4905be9b
2022-04-11 11:41:27 0bcb4c2c798db189132b9e70588a72df14efdc5ee998ba4203aed16fbe56960f