216.73.216.226

Indicator (IOC)

stix Revoked AlienVault · Published 20/12/2025 23:08 · Modified 20/12/2025 23:26

Essential information

Value / Name
295654e3284158bdb94b40d7fb98ede8f3eab72171e027360a654f9523ece566
Confidence
100/100
Revoked
Yes
Valid from
23/01/2023 17:42
Valid until
27/04/2024 18:42
Pattern type
stix
Published
20/12/2025 23:08
Modified
20/12/2025 23:26
Author / Source
AlienVault

Description

VBA:Gamaredon-E\ [Drp]

Pattern

[file:hashes.'SHA-256' = '295654e3284158bdb94b40d7fb98ede8f3eab72171e027360a654f9523ece566']

Labels / Tags

Labels: apt dns flux gamaredon maldocs phishing powershell russia telegram trident ursa ukraine

Marking (TLP)

TLP:CLEAR

Related entities

No linked attack reports or intrusion sets yet.