216.73.217.172

Indicator (IOC)

stix Revoked AlienVault · Published 20/12/2025 19:34 · Modified 20/12/2025 21:27

Essential information

Value / Name
25969ab58383a5fdc53e9861a25c3ed90813e4e5fcc9d8a99df5e9f74b427474
Confidence
100/100
Revoked
Yes
Valid from
26/07/2022 12:54
Valid until
29/10/2023 11:54
Pattern type
stix
Published
20/12/2025 19:34
Modified
20/12/2025 21:27
Author / Source
AlienVault

Description

TEL:Exploit:Win32/ShellPdb SHA256 of e31c43dd8cb17e9d68c65e645fb3f6e8

Pattern

[file:hashes.'SHA-256' = '25969ab58383a5fdc53e9861a25c3ed90813e4e5fcc9d8a99df5e9f74b427474']

Labels / Tags

Labels: cosmicstrand firmware rootkit uefi

Marking (TLP)

TLP:CLEAR

Related entities

No linked attack reports or intrusion sets yet.