216.73.216.36

Indicator (IOC)

stix Revoked AlienVault · Published 20/12/2025 19:39 · Modified 21/12/2025 00:31

Essential information

Value / Name
fcdec9d9b195b8ed827fb46f1530502816fe6a04b1f5e740fda2b126df2d9fd5
Confidence
100/100
Revoked
Yes
Valid from
15/05/2023 16:34
Valid until
17/08/2024 16:34
Pattern type
stix
Published
20/12/2025 19:39
Modified
21/12/2025 00:31
Author / Source
AlienVault

Description

ALF:Trojan:Win32/Cevarast.A

Pattern

[file:hashes.'SHA-256' = 'fcdec9d9b195b8ed827fb46f1530502816fe6a04b1f5e740fda2b126df2d9fd5']

Labels / Tags

Labels: apt17 apt41 dropper lancefly loader lsass merdoor merdoor loader plugx powershell shadowpad smb activity trojan winrar xor algorithm zxshell zxshell rootkit

Marking (TLP)

TLP:CLEAR