216.73.216.226

Indicator (IOC)

stix Revoked AlienVault · Published 21/12/2025 02:10 · Modified 21/12/2025 02:10

Essential information

Value / Name
657c0cce98d6e73e53b4001eeea51ed91fdcf3d47a18712b6ba9c66d59677980
Confidence
100/100
Revoked
Yes
Valid from
12/01/2024 00:34
Valid until
16/04/2025 01:34
Pattern type
stix
Published
21/12/2025 02:10
Modified
21/12/2025 02:10
Author / Source
AlienVault

Description

SUSP_XORed_URL_in_EXE

Pattern

[file:hashes.'SHA-256' = '657c0cce98d6e73e53b4001eeea51ed91fdcf3d47a18712b6ba9c66d59677980']

Labels / Tags

Labels: aes256 asm guard connectwise cyrillic script ioctl code jscript medusa ransomware powershell ransomware-as-a-service (raas) safengine shielden telegram vbscript wmi

Marking (TLP)

TLP:CLEAR