216.73.216.226

Indicator (IOC)

stix Revoked AlienVault · Published 20/12/2025 19:42 · Modified 21/12/2025 03:04

Essential information

Value / Name
http://adamsresearchshare.com/textcmd/cmd1.php
Confidence
100/100
Revoked
Yes
Valid from
01/03/2024 17:39
Valid until
17/04/2024 18:39
Pattern type
stix
Published
20/12/2025 19:42
Modified
21/12/2025 03:04
Author / Source
AlienVault

Description

No description.

Pattern

[url:value = 'http://adamsresearchshare.com/textcmd/cmd1.php']

Labels / Tags

Labels: apt attack campaign backdoor.oldrea chm darkwatchman havex

Marking (TLP)

TLP:CLEAR