216.73.217.22

Indicator (IOC)

stix Revoked AlienVault · Published 21/12/2025 13:28 · Modified 21/12/2025 13:28

Essential information

Value / Name
http://92.42.96.30/Activation/Certificate+AF8hFgBf-45052389+AF8-005553.exe
Confidence
100/100
Revoked
Yes
Valid from
10/04/2025 20:50
Valid until
27/05/2025 20:50
Pattern type
stix
Published
21/12/2025 13:28
Modified
21/12/2025 13:28
Author / Source
AlienVault

Description

No description.

Pattern

[url:value = 'http://92.42.96.30/Activation/Certificate+AF8hFgBf-45052389+AF8-005553.exe']

Labels / Tags

Labels: apt-c-36 colombia cve-2024-43451 government heartcrypt phishing purecrypter remcos remcos rat webdav

Marking (TLP)

TLP:CLEAR