216.73.217.80

Indicator (IOC)

stix Revoked AlienVault · Published 20/12/2025 19:48 · Modified 21/12/2025 08:03

Essential information

Value / Name
http://weg7sdx54bevnvulapqu6bpzwztryeflq3s23tegbmnhkbpqz637f2yd.onion/?id=[ID]
Confidence
100/100
Revoked
Yes
Valid from
20/11/2024 23:03
Valid until
06/01/2025 23:03
Pattern type
stix
Published
20/12/2025 19:48
Modified
21/12/2025 08:03
Author / Source
AlienVault

Description

No description.

Pattern

[url:value = 'http://weg7sdx54bevnvulapqu6bpzwztryeflq3s23tegbmnhkbpqz637f2yd.onion/?id=[ID]']

Labels / Tags

Labels: blacksuit cobalt strike credential theft data exfiltration extortion gootloader lateral movement mimikatz nanodump ransomware supply chain attack systembc

Marking (TLP)

TLP:CLEAR