216.73.216.36

Indicator (IOC)

stix AlienVault · Published 27/03/2026 01:03 · Modified 08/04/2026 13:02

Essential information

Value / Name
tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io
Confidence
100/100
Revoked
No
Valid from
24/03/2026 11:50
Valid until
26/02/2027 20:33
Pattern type
stix
Published
27/03/2026 01:03
Modified
08/04/2026 13:02
Author / Source
AlienVault

Description

No description.

Pattern

[hostname:value = 'tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io']

Labels / Tags

Labels: apt canisterworm credential theft cve-2025-55182 daemonset docker api exfiltration government iran kubernetes msbuild.exe muddywater persistence pypi rat seedworm steganography stryker supply chain supply chain attack sysmon.py teampcp trivy wiper

Marking (TLP)

TLP:CLEAR