ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://208.67.105.148/nze/five/fre.php.

Database Entry


IOC ID:842703
IOC: http://208.67.105.148/nze/five/fre.php
IOC Type :url
Threat Type :botnet_cc
Malware: Loki Password Stealer (PWS)
Malware alias:Burkina, Loki, LokiBot, LokiPWS
Confidence Level : Confidence level is high (100%)
ASN:AS57043 HOSTKEY-AS
Country:- RU
First seen:2022-08-12 08:16:15 UTC
Last seen:never
UUID:090747de-1a17-11ed-8d2e-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:Loki

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2022-08-12 08:16:19 4cc1d7c1de7318ad6e31b2d8653933c450e6ce76c4d750df7d3ff6238d70c404
2022-08-12 08:16:17 4ce80bb4169f81656f9f5a2833aad35378d7e26fe9fcce2da3e5628a8d4693e0