216.73.217.80

Indicator (IOC)

stix Revoked AlienVault · Published 21/12/2025 12:43 · Modified 02/03/2026 00:58

Essential information

Value / Name
79c64d2e77acdbcdbd35cbb29497941335d7e3ab6ebb474064f095e745f0d643
Confidence
100/100
Revoked
Yes
Valid from
05/03/2025 17:04
Valid until
02/03/2026 00:58
Pattern type
stix
Published
21/12/2025 12:43
Modified
02/03/2026 00:58
Author / Source
AlienVault

Description

RansomWin32Nobig

Pattern

[file:hashes.'SHA-256' = '79c64d2e77acdbcdbd35cbb29497941335d7e3ab6ebb474064f095e745f0d643']

Labels / Tags

Labels: agent c2 server corrupt pdf phishing screen capture team uacme valleyrat wechat

Marking (TLP)

TLP:CLEAR

Related entities

No linked attack reports or intrusion sets yet.