216.73.216.36

Indicator (IOC)

stix Revoked AlienVault · Published 20/12/2025 19:39 · Modified 21/12/2025 04:00

Essential information

Value / Name
5655a2981fa4821fe09c997c84839c16d582d65243c782f45e14c96a977c594e
Confidence
100/100
Revoked
Yes
Valid from
04/04/2024 23:07
Valid until
08/07/2025 23:07
Pattern type
stix
Published
20/12/2025 19:39
Modified
21/12/2025 04:00
Author / Source
AlienVault

Description

compromised_site_redirector_fromcharcode

Pattern

[file:hashes.'SHA-256' = '5655a2981fa4821fe09c997c84839c16d582d65243c782f45e14c96a977c594e']

Labels / Tags

Labels: apt17 apt41 backdoor cyber-espionage data-theft dropper espionage financial-fraud islamic lancefly loader lsass merdoor merdoor loader plugx powershell rat rotbot saudi arabia shadowpad smb activity social-media trojan vietnam winrar xclient xor algorithm zardoor zxshell zxshell rootkit

Marking (TLP)

TLP:CLEAR