IOC Feed
Arsenal-237 New Files: rootkit.dll (Kernel-Mode Rootkit)
19 indicators extracted from this
investigation's feed. Filter by type, then copy or download exactly what is on screen.
19 shown
| Type | Indicator |
|---|---|
| sha256 | 47ec51b5f0ede1e70bd66f3f0152f9eb536d534565dbb7fcc3a05f542dbe4428 |
| sha256 | e71240f26af1052172b5864cdddb78fcb990d7a96d53b7d22d19f5dfccdf9012 |
| sha1 | 148c0cde4f2ef807aea77d7368f00f4c519f47ef |
| sha1 | 483feeb4e391ae64a7d54637ea71d43a17d83c71 |
| sha1 | 65439929b67973eb192d6ff243e6767adf0834e4 |
| md5 | 674795d4d4ec09372904704633ea0d86 |
| md5 | ced47b89212f3260ebeb41682a4b95ec |
| path | %SYSTEMROOT%\System32\drivers\BdApiUtil64.sys |
| path | %TEMP%\BdApiUtil64.sys |
| path | C:\Windows\System32\rootkit.dll |
| registry | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System |
| registry | HKLM\SOFTWARE\Policies\Microsoft\Windows Defender |
| registry | HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot |
| registry | HKLM\SYSTEM\CurrentControlSet\Services\ |
| registry | HKLM\SYSTEM\CurrentControlSet\Services\BdApiUtil64 |
| filename | bdapiutil64.sys |
| filename | cb.exe |
| filename | repmgr.exe |
| filename | rootkit.dll |
21 further values in this feed are not shown above, because they are not an indicator type that can be recognised reliably by shape: command names, fingerprints and behavioural patterns among them. They are all in the raw JSON, which remains the complete record.
Licensed CC BY 4.0, free to use commercially with attribution to The Hunters Ledger.