216.73.217.172

Indicator (IOC)

stix Revoked AlienVault · Published 20/12/2025 19:41 · Modified 21/12/2025 02:09

Essential information

Value / Name
d4f4069b1c40a5b27ba0bc15c09dceb7035d054a022bb5d558850edfba0b9534
Confidence
100/100
Revoked
Yes
Valid from
06/12/2023 14:44
Valid until
10/03/2025 14:44
Pattern type
stix
Published
20/12/2025 19:41
Modified
21/12/2025 02:09
Author / Source
AlienVault

Description

Trojan:Win32/DorkBot.DU SHA256 of 07610f11d3b8ccb7b60cc8ad033dda6c7d3940c4

Pattern

[file:hashes.'SHA-256' = 'd4f4069b1c40a5b27ba0bc15c09dceb7035d054a022bb5d558850edfba0b9534']

Labels / Tags

Labels: bianlian cobalt strike comspec conti daphne empire et info havoc m2 et metasploit mssql server powershell shell sliver smbexec sql server tor2mine xpcmdshell

Marking (TLP)

TLP:CLEAR

Related entities

No linked attack reports or intrusion sets yet.