THE HUNTER’S LEDGER
IOC Feed
CloudSync: An Assembler's Intrusion Toolkit
65 indicators extracted from this investigation's feed. Filter by type, then copy or download exactly what is on screen.
65 shown
TypeIndicator
ipv4 2.27.248.138
ipv4 46.36.217.3
ipv4 65.20.90.34
ipv4 91.197.98.188
ipv4 91.92.43.221
domain aka1.hopto.org
domain api.telegram.org
domain c3lestial.fun
domain download.anydesk.com
domain hopto.org
domain ip-api.com
domain johnathon-yerrow.sahs.ac.zw
domain stolotov.net
domain stolotov.org
url http://91.197.98.188:8000/client.exe
sha256 0ba14e1443c155a0e644b0d83d5f89c2c188556367d15ccd86f0b6787cfac4d7
sha256 0ff0cee1fbf1050fbe3ab91918e56334a93269265e5614717ec0441baa8c42df
sha256 4b115a9f745219e3f3abdea275da89f35e4ec5f3d43286e5efc58eaf8049f3f7
sha256 62aa8e470e60aa9fa77df6e6e63b7c253657e95d6018240b1752a9ca9fe389fa
sha256 6bd0366372b7d765e76c5a888d68a4991ad04ee614bdb589a20ffbe433db58fc
sha256 79b6f2eb6583a83aabe590264de08c0ad1eb7e960ae9a4bdbc6ed84142ce95a9
sha256 7a5c5d1e41d5e2c8c0f09d5dccb78932de535963d21350b2581716c8a753fd66
sha256 9744c12a06b4562e175d4aeb7b8fd5c1e1877ac30222af8243eeaae16df324b0
sha256 b4cc5ac328afd0e7eaf16216879046367e083279bfdb831da3a53c8a31df3d1b
sha256 d25a3a858e28faa68ca6c624d7d19350c11ac798c346be3067307463e40aaff1
sha256 d61419108785340e5b48fb4ef5fec85f46bbeaa86636bdfa9706b7df16a2e0f4
sha256 e924acdb4aea72bdf1db5ab121a2bcbfddd33fd2d3d8c8907441ce3a6dfef10b
sha256 fe9e54800c54efb46301f4cff3c3870be6b617ebdbe2b786220dbd8b337a33b0
sha1 ae5ed7c741695e76561ef0b66b1792fc95a5d1d4
md5 0f59f07585bd3695d4c8fce4a8e46998
md5 135877ecc663ee47340a4726078234f0
md5 1709c1b06eaaf503f70b4d39e7cf131b
md5 2ce0c7b067339c33da3ae88154d0a6b2
md5 631b2c5416914cfd00211b30a94c2e93
md5 b318706357aecc6715c617608ee7e411
path %APPDATA%\...\Startup\~.exe
path %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\~.exe
path %APPDATA%\tor\torrc
path %LOCALAPPDATA%\Photo Studio\PhotoStudio.js
path %LOCALAPPDATA%\Photo Studio\PhotoStudio.vbs
path %TEMP%\log__
path C:\Users\Public\filesystem\
path C:\Users\Public\fs\a.dat
path C:\Users\Public\fs\b.log
path C:\Users\Public\fs\config.json
path C:\Users\Public\fs\first_run.flag
path C:\Users\Public\fs\hidden_service\
path C:\Users\Public\fs\taskhostw.exe
path C:\inetpub\wwwroot\aspnet_client\a.aspx
path C:\inetpub\wwwroot\aspnet_client\log.txt
registry HKCU\Software\Microsoft\Windows\CurrentVersion\Run
registry HKCU\Software\Microsoft\Windows\CurrentVersion\Svc_
registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList
filename ab.exe
filename bk.exe
filename client.exe
filename cls.exe
filename crystal-monk.dll
filename ct.bat
filename q.exe
filename rr.exe
filename s.exe
filename svhost.js
filename svhost4.exe
filename v.exe

39 further values in this feed are not shown above, because they are not an indicator type that can be recognised reliably by shape: command names, fingerprints and behavioural patterns among them. They are all in the raw JSON, which remains the complete record.

Licensed CC BY 4.0, free to use commercially with attribution to The Hunters Ledger.