216.73.216.133

Indicator (IOC)

stix Revoked AlienVault · Published 21/12/2025 00:02 · Modified 21/12/2025 00:02

Essential information

Value / Name
http://172.86.75.220/02.08.2022.exe
Confidence
100/100
Revoked
Yes
Valid from
14/03/2023 20:38
Valid until
30/04/2023 21:38
Pattern type
stix
Published
21/12/2025 00:02
Modified
21/12/2025 00:02
Author / Source
AlienVault

Description

PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows db9a6efd5d64ba0ba1783c51b6d430873518fa032bf5265c6837c7674321e183

Pattern

[url:value = 'http://172.86.75.220/02.08.2022.exe']

Labels / Tags

Labels: avemaria espionage infostealer lodarat meterpreter phishing stink telegram warzone yorotrooper

Marking (TLP)

TLP:CLEAR

Related entities

No linked attack reports or intrusion sets yet.