216.73.216.233

Indicator (IOC)

stix Revoked AlienVault · Published 21/12/2025 04:56 · Modified 21/12/2025 05:10

Essential information

Value / Name
message.ooguy.com
Confidence
100/100
Revoked
Yes
Valid from
06/06/2024 09:55
Valid until
19/09/2025 09:55
Pattern type
stix
Published
21/12/2025 04:56
Modified
21/12/2025 05:10
Author / Source
AlienVault

Description

No description.

Pattern

[hostname:value = 'message.ooguy.com']

Labels / Tags

Labels: .net apt ccoredoor cobalt strike credential access cyberespionage dustyexfiltool eagerbee espionage impersoni-fake-ator intrusion lateral movement malware nupakage phantomnet pocoproxy powheartbeat rudebird sharpjshandler silentgh0st translucentgh0st unfading sea haze

Marking (TLP)

TLP:CLEAR