216.73.216.36

Indicator (IOC)

stix Revoked AlienVault · Published 20/12/2025 19:34 · Modified 20/12/2025 22:11

Essential information

Value / Name
http://rwwmefkauiaa.ru/u84ls.exe
Confidence
100/100
Revoked
Yes
Valid from
23/09/2022 14:31
Valid until
09/11/2022 13:31
Pattern type
stix
Published
20/12/2025 19:34
Modified
20/12/2025 22:11
Author / Source
AlienVault

Description

PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows beedb7cc465933bc983dab4c41f8464d985ec15680f60dec4f27e0a96e88939d

Pattern

[url:value = 'http://rwwmefkauiaa.ru/u84ls.exe']

Labels / Tags

Labels: arkei babadeda downloader eternity stealer nft nft-001 office macro pdf phishing remcos stealer

Marking (TLP)

TLP:CLEAR

Related entities

No linked attack reports or intrusion sets yet.