216.73.216.6

Indicator (IOC)

stix Revoked AlienVault · Published 21/12/2025 01:43 · Modified 21/12/2025 01:43

Essential information

Value / Name
http://162.243.71.6/ais_binded_moderate_halt_vm_enabled_2840.msi
Confidence
100/100
Revoked
Yes
Valid from
24/10/2023 17:55
Valid until
10/12/2023 16:55
Pattern type
stix
Published
21/12/2025 01:43
Modified
21/12/2025 01:43
Author / Source
AlienVault

Description

Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Title: Application Verifier x64 External Package - UNREGISTERED - Wrapped using MSI Wrapper from www.exemsi.com 3.3.14.5, Subject: Application Verifier x64 External Package - UNREGISTERED - Wrapped using MSI Wrapper from www.exemsi.com, Author: Microsoft, Keywords: Installer, Template: Intel;1033, Revision Number: {C2990676-8624-4A8E-B979-5326889BC8B1}, Create Time/Date: Sat Jul 23 12:0 8c4fa2e64e0bd3b3e162e6f74fab12efdb30df68db69c12506038c54ed601580

Pattern

[url:value = 'http://162.243.71.6/ais_binded_moderate_halt_vm_enabled_2840.msi']

Labels / Tags

Labels: autoit corsair darkgate ducktail google drive infostealer linkedin lobshot msi files rat redline stealer url shortener vbs script

Marking (TLP)

TLP:CLEAR

Related entities

No linked attack reports or intrusion sets yet.