ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://mainpage-auth.ml/alhaji/fre.php.

Database Entry


IOC ID:832342
IOC: http://mainpage-auth.ml/alhaji/fre.php
IOC Type :url
Threat Type :botnet_cc
Malware: Loki Password Stealer (PWS)
Malware alias:Burkina, Loki, LokiBot, LokiPWS
Confidence Level : Confidence level is elevated (75%)
First seen:2022-07-13 06:50:15 UTC
Last seen:never
UUID:0d20c2fa-0278-11ed-bde9-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:LokiBot
Reference: https://bazaar.abuse.ch/sample/b7d4a8fbba540672a302dadee7f076321a6abf9dd5c2e0f2a30b17e0b98b622b/

Avatar
abuse_ch
lokibot (aka Burkina,Loki,LokiBot,LokiPWS) botnet C2

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2022-07-21 18:40:22 74ac7ead214cbcbdc49a18f1ab29d3b9f2a6a86af34e1611491bcd8f55a6e34b