216.73.217.22

Indicator (IOC)

stix Revoked AlienVault · Published 21/12/2025 07:15 · Modified 21/12/2025 13:43

Essential information

Value / Name
ghostreedmnu.shop
Confidence
100/100
Revoked
Yes
Valid from
21/04/2025 19:31
Valid until
16/09/2025 19:27
Pattern type
stix
Published
21/12/2025 07:15
Modified
21/12/2025 13:43
Author / Source
AlienVault

Description

No description.

Pattern

[domain-name:value = 'ghostreedmnu.shop']

Labels / Tags

Labels: anti-analysis anti-sandbox autoit captcha configuration extractor crc32 cryptocurrency theft data theft fake captcha gdi+ ghostpulse heartcrypt information stealer infrastructure takedown keyboard shortcuts lumma stealer lummac lummac2 lummastealer malware-as-a-service multi-tiered c2 obfuscation packer-as-a-service pixel-level deception png files powershell process hollowing quasar rat redline redline stealer

Marking (TLP)

TLP:CLEAR