216.73.217.50

Indicator (IOC)

stix AlienVault · Published 17/06/2026 22:24 · Modified 17/06/2026 22:24

Essential information

Value / Name
http://64.95.13.238/payload.php'
Confidence
100/100
Revoked
No
Valid from
17/06/2026 20:20
Valid until
17/07/2026 02:03
Pattern type
stix
Published
17/06/2026 22:24
Modified
17/06/2026 22:24
Author / Source
AlienVault

Description

No description.

Pattern

[url:value = 'http://64.95.13.238/payload.php\'']

Labels / Tags

Labels: ai-generated banana rat banking trojan brazil clickfix credential theft fake captcha ghostloader powershell qr code interception remcos rat smartrat typosquatting

Marking (TLP)

TLP:CLEAR