THE HUNTER’S LEDGER
IOC Feed
Arsenal-237: agent.exe (PoetRAT)
12 indicators extracted from this investigation's feed. Filter by type, then copy or download exactly what is on screen.
12 shown
TypeIndicator
ipv4 109.230.231.37
sha256 4e856041018242c62b3848d63b94c3763beda01648d3139060700c11e9334ad1
sha256 6b86b273ff34fce19d6b804eff5a3f5747ada4eaa22f1d49c01e52ddb7875b4b
sha256 e7f9a29dde307afff4191dbc14a974405f287b10f359a39305dccdc0ee949385
sha1 e0fe41acd28cae74d75fcbf2f9309ff523c0f36a
md5 b1d5e55b1c15b7cb839138625d9d2efa
path %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\
path %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\WinDefenderSvc.exe
path %LocalAppData%\Temp\.wd_installed
registry HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
filename agent.exe
filename windefendersvc.exe

22 further values in this feed are not shown above, because they are not an indicator type that can be recognised reliably by shape: command names, fingerprints and behavioural patterns among them. They are all in the raw JSON, which remains the complete record.

Licensed CC BY 4.0, free to use commercially with attribution to The Hunters Ledger.