ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://62.197.136.176/liyan/five/fre.php.

Database Entry


IOC ID:547945
IOC: http://62.197.136.176/liyan/five/fre.php
IOC Type :url
Threat Type :botnet_cc
Malware: Loki Password Stealer (PWS)
Malware alias:Burkina, Loki, LokiBot, LokiPWS
Confidence Level : Confidence level is high (100%)
ASN:AS6762 SEABONE-NET
Country:- IT
First seen:2022-05-03 12:50:51 UTC
Last seen:never
UUID:a99c8819-cadf-11ec-bf24-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:Loki

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2022-05-04 07:55:34 d47067d24dd0d829c1616e232e7e0df717382b7708d6e96bd23ab6ef2936e2f2
2022-05-04 07:50:29 a7ee299c6804573312fb3e6bd3d8b196517608c42f310cfd0bcec25eaffb18f1
2022-05-03 12:50:54 ec68e4a53a49acd215d52b8b85b809c5fd1acb318e1cf9673806ff3d6b57f478