216.73.217.22

Indicator (IOC)

stix Revoked AlienVault · Published 21/12/2025 12:44 · Modified 02/03/2026 03:15

Essential information

Value / Name
21ff46a6fc9173fcc147d7a5c603032c662c6c1f1b05c1bb1e30e20e168bb056
Confidence
100/100
Revoked
Yes
Valid from
05/03/2025 19:21
Valid until
02/03/2026 03:15
Pattern type
stix
Published
21/12/2025 12:44
Modified
02/03/2026 03:15
Author / Source
AlienVault

Description

XOR_embeded_exefile_xored_with_round_256_bytes_key

Pattern

[file:hashes.'SHA-256' = '21ff46a6fc9173fcc147d7a5c603032c662c6c1f1b05c1bb1e30e20e168bb056']

Labels / Tags

Labels: bandook dark caracal executables phishing poco c++ poco rat rat ultimate packer virtualbox vmware windows

Marking (TLP)

TLP:CLEAR