IOC Feed
Arsenal-237 New Files: chromelevator.exe (Browser Credential Theft)
20 indicators extracted from this
investigation's feed. Filter by type, then copy or download exactly what is on screen.
20 shown
| Type | Indicator |
|---|---|
| ipv4 | 109.230.231.37 |
| sha256 | 92c4f4b7748f23d6dcd5af43595f34e4bb8e284a85d2c1647b189c1bb59a784a |
| sha1 | 78c8ab4a9932805f5fb32f4a19367642ea8ac6f6 |
| md5 | bc376c951eacb36bf0909a43588e6444 |
| path | %APPDATA%\BraveSoftware\Brave-Browser\User Data\Default\Login Data |
| path | %APPDATA%\Google\Chrome\User Data\Default\Cookies |
| path | %APPDATA%\Google\Chrome\User Data\Default\Login Data |
| path | %APPDATA%\Google\Chrome\User Data\Default\Web Data |
| path | %APPDATA%\Google\Chrome\User Data\Profile *\* |
| path | %APPDATA%\Microsoft\Edge\User Data\Default\Login Data |
| path | %APPDATA%\chromelevator.exe |
| path | %TEMP%\chromelevator.exe |
| path | C:\Windows\Temp\chromelevator.exe |
| path | \\.*\pipe\* |
| registry | HKLM\SOFTWARE\BraveSoftware |
| registry | HKLM\SOFTWARE\BraveSoftware\Brave-Browser |
| registry | HKLM\SOFTWARE\Google\Chrome |
| registry | HKLM\SOFTWARE\Google\Chrome\InstallPath |
| registry | HKLM\SOFTWARE\Microsoft\Edge |
| filename | chromelevator.exe |
76 further values in this feed are not shown above, because they are not an indicator type that can be recognised reliably by shape: command names, fingerprints and behavioural patterns among them. They are all in the raw JSON, which remains the complete record.
Licensed CC BY 4.0, free to use commercially with attribution to The Hunters Ledger.