216.73.216.233

Indicator (IOC)

stix AlienVault · Published 20/12/2025 23:21 · Modified 14/01/2026 16:17

Essential information

Value / Name
fb1dd40577af7ac4d8c32506e78e39841ff6d05ee643c18270ef26eac798df3f
Confidence
100/100
Revoked
No
Valid from
09/12/2025 18:09
Valid until
06/12/2026 02:03
Pattern type
stix
Published
20/12/2025 23:21
Modified
14/01/2026 16:17
Author / Source
AlienVault

Description

Ransom:Win32/CVE SHA256 of 323a36c23e61c6b37f28abfd5b7e5dfe

Pattern

[file:hashes.'SHA-256' = 'fb1dd40577af7ac4d8c32506e78e39841ff6d05ee643c18270ef26eac798df3f']

Labels / Tags

Labels: aspxspy badpotato bitlocker china chopper cobaltstrike credential dumping cve-2016-0099 cve-2017-0213 cve-2018-8639 cve-2019-1388 cve-2020-0787 cve-2020-0796 cve-2020-1066 cve-2021-41379 cve-2022-24521 cve-2025-7771 dalbit godzilla groupware guloader lazagne makop mimikatz network scanning privilege escalation ransomware rdp exploitation systemdrive webshell

Marking (TLP)

TLP:CLEAR