THE HUNTER’S LEDGER
IOC Feed
Arsenal-237 New Files: nethost.dll (DLL Hijacking Persistence)
12 indicators extracted from this investigation's feed. Filter by type, then copy or download exactly what is on screen.
12 shown
TypeIndicator
sha256 158f61b6d10ea2ce78769703a2ffbba9c08f0172e37013de960d9efe5e9fde14
sha1 622ddbacaf769aef383435162a203489c08c8468
md5 f91ff1bb5699524524fff0e2587af040
path %APPDATA%\nethost.dll
path %SYSTEMROOT%\System32\nethost.dll
path %SYSTEMROOT%\nethost.dll
path %TEMP%\nethost.dll
path C:\Windows\System32\drivers\etc\nethost.dll
registry HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
registry HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
filename arsenal-237-nethost-dll.yar
filename nethost.dll

105 further values in this feed are not shown above, because they are not an indicator type that can be recognised reliably by shape: command names, fingerprints and behavioural patterns among them. They are all in the raw JSON, which remains the complete record.

Licensed CC BY 4.0, free to use commercially with attribution to The Hunters Ledger.