216.73.217.80

Indicator (IOC)

stix Revoked AlienVault · Published 20/12/2025 19:35 · Modified 20/12/2025 22:12

Essential information

Value / Name
944a8fac13b495f11628696c04673115c90ee650fc8ff3e440335e6d73df2496
Confidence
100/100
Revoked
Yes
Valid from
25/10/2022 16:10
Valid until
28/01/2024 15:10
Pattern type
stix
Published
20/12/2025 19:35
Modified
20/12/2025 22:12
Author / Source
AlienVault

Description

SNH:Script\ [Dropper] SHA256 of 020ea21556b56229bb9714e721d893df

Pattern

[file:hashes.'SHA-256' = '944a8fac13b495f11628696c04673115c90ee650fc8ff3e440335e6d73df2496']

Labels / Tags

Labels: amsi bypass asyncrat crackmapexe dwservice lnk file metasploit poshc2 powershell smartassembly

Marking (TLP)

TLP:CLEAR

Related entities

No linked attack reports or intrusion sets yet.