216.73.217.22

Indicator (IOC)

stix Revoked AlienVault · Published 13/04/2026 17:17 · Modified 09/06/2026 11:00

Essential information

Value / Name
https://136.0.141.138:8406/rcv/
Confidence
100/100
Revoked
Yes
Valid from
13/04/2026 17:03
Valid until
12/05/2026 22:46
Pattern type
stix
Published
13/04/2026 17:17
Modified
09/06/2026 11:00
Author / Source
AlienVault

Description

No description.

Pattern

[url:value = 'https://136.0.141.138:8406/rcv/']

Labels / Tags

Labels: credential theft cve-2025-6218 cve-2025-8088 data exfiltration gammasteel giftedcrook giftedcrook stealer hta infection chain information stealer phishing campaign powershell payload rc4 encryption russia-aligned threats stealer ukraine targeting winrar exploitation

Marking (TLP)

TLP:CLEAR