ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://63.141.228.141/32.php/o0zZsfEfA0S9K.

Database Entry


IOC ID:85839
IOC: http://63.141.228.141/32.php/o0zZsfEfA0S9K
IOC Type :url
Threat Type :botnet_cc
Malware: Loki Password Stealer (PWS)
Malware alias:Burkina, Loki, LokiBot, LokiPWS
Confidence Level : Confidence level is high (100%)
ASN:AS33387 NOCIX
Country:- US
First seen:2021-06-10 11:35:49 UTC
Last seen:never
UUID:016c9fb4-c9e0-11eb-b17b-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:Loki

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2021-06-11 09:15:08 9f00d2c67b04faada1cba4e07202fb6cb56c1590d5a4a9e5af7342e0b655c96c
2021-06-11 07:40:09 0edd52e3a9ccf4fb316dacf8c22508439e2c90bf32a3d569d1247a9100027cea
2021-06-10 11:35:52 6cf9e4b9b854c6c49ff023d06c345892b9b41810aa0e9c13adce3df6d89f522e