ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://sempersim.su/gh5/fre.php.

Database Entry


IOC ID:648071
IOC: http://sempersim.su/gh5/fre.php
IOC Type :url
Threat Type :botnet_cc
Malware: Loki Password Stealer (PWS)
Malware alias:Burkina, Loki, LokiBot, LokiPWS
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
First seen:2022-06-03 06:53:03 UTC
Last seen:2022-06-15 09:44:43 UTC
UUID:d0964129-e309-11ec-a425-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:LokiBot
Reference: https://bazaar.abuse.ch/sample/f1f037f0fa83f72ff5c98f08ec9878abdc585ac23e41eb180b6e289fd8e40bf7/

Avatar
abuse_ch
lokibot (aka Burkina,Loki,LokiBot,LokiPWS) botnet C2

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2022-06-10 06:15:43 2c1ad7493279718dfc88f2a456272ffd34e90361fb44f7d7570aba730248a608
2022-06-09 14:24:59 d9a0c594357e87e17d2bf58efdfda52aec12662fae2f07b922c6c93b8b12b799
2022-06-09 14:18:21 9a3992b900c098237cc06e80ec2f5c16996f386995ec2b1e682f8b247c353bcf