THE HUNTER’S LEDGER
IOC Feed
Arsenal-237 New Files: rootkit.dll (Kernel-Mode Rootkit)
19 indicators extracted from this investigation's feed. Filter by type, then copy or download exactly what is on screen.
19 shown
TypeIndicator
sha256 47ec51b5f0ede1e70bd66f3f0152f9eb536d534565dbb7fcc3a05f542dbe4428
sha256 e71240f26af1052172b5864cdddb78fcb990d7a96d53b7d22d19f5dfccdf9012
sha1 148c0cde4f2ef807aea77d7368f00f4c519f47ef
sha1 483feeb4e391ae64a7d54637ea71d43a17d83c71
sha1 65439929b67973eb192d6ff243e6767adf0834e4
md5 674795d4d4ec09372904704633ea0d86
md5 ced47b89212f3260ebeb41682a4b95ec
path %SYSTEMROOT%\System32\drivers\BdApiUtil64.sys
path %TEMP%\BdApiUtil64.sys
path C:\Windows\System32\rootkit.dll
registry HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
registry HKLM\SOFTWARE\Policies\Microsoft\Windows Defender
registry HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot
registry HKLM\SYSTEM\CurrentControlSet\Services\
registry HKLM\SYSTEM\CurrentControlSet\Services\BdApiUtil64
filename bdapiutil64.sys
filename cb.exe
filename repmgr.exe
filename rootkit.dll

21 further values in this feed are not shown above, because they are not an indicator type that can be recognised reliably by shape: command names, fingerprints and behavioural patterns among them. They are all in the raw JSON, which remains the complete record.

Licensed CC BY 4.0, free to use commercially with attribution to The Hunters Ledger.