216.73.217.172

Indicator (IOC)

stix Revoked AlienVault · Published 20/12/2025 19:57 · Modified 21/12/2025 15:22

Essential information

Value / Name
http://ag2qts4t6fy6x475c5xuknlwdugdoy33oueejdv5lkfavah73g6mvlyd.onion:4853
Confidence
100/100
Revoked
Yes
Valid from
07/08/2025 12:38
Valid until
23/09/2025 12:38
Pattern type
stix
Published
20/12/2025 19:57
Modified
21/12/2025 15:22
Author / Source
AlienVault

Description

No description.

Pattern

[url:value = 'http://ag2qts4t6fy6x475c5xuknlwdugdoy33oueejdv5lkfavah73g6mvlyd.onion:4853']

Labels / Tags

Labels: cve-2024-38196 downloader encryption evasion obfuscation privilege-escalation raspberry robin roshtyak tor usb usb-spread

Marking (TLP)

TLP:CLEAR

Related entities

No linked attack reports or intrusion sets yet.