216.73.216.36

Indicator (IOC)

stix AlienVault · Published 20/12/2025 19:42 · Modified 21/12/2025 20:01

Essential information

Value / Name
bd4635d582413f84ac83adbb4b449b18bac4fc87ca000d0c7be84ad0f9caf68e
Confidence
100/100
Revoked
No
Valid from
10/07/2025 20:31
Valid until
07/07/2026 04:24
Pattern type
stix
Published
20/12/2025 19:42
Modified
21/12/2025 20:01
Author / Source
AlienVault

Description

ConventionEngine_Keyword_Proxy

Pattern

[file:hashes.'SHA-256' = 'bd4635d582413f84ac83adbb4b449b18bac4fc87ca000d0c7be84ad0f9caf68e']

Labels / Tags

Labels: brand impersonation chinese-speaking targets cloud infrastructure cyber warfare dll side-loading domain generation evasion techniques fox kitten gh0st rat jsx korplug luminousmoth mimic multi-stage infection mustang panda pay2key raas ransomware rat c

Marking (TLP)

TLP:CLEAR