THE HUNTER’S LEDGER
IOC Feed
Chaos Ransomware (TorBrowserTor) Multi-Stage Loader (94.103.1.13)
99 indicators extracted from this investigation's feed. Filter by type, then copy or download exactly what is on screen.
99 shown
TypeIndicator
ipv4 172.86.76.198
ipv4 178.20.159.99
ipv4 185.237.218.100
ipv4 192.227.108.142
ipv4 192.227.113.124
ipv4 37.17.245.209
ipv4 85.238.98.37
ipv4 94.103.1.13
domain bulgainme.pro
domain dhost.su
domain forumrutor24.com
domain gtanuncios.com
domain interact.py
domain mail.bulgainme.pro
domain mail.gtanuncios.com
domain slayer.ktx.ro
domain www.forumrutor24.com
url http://172.86.76.198:3000/api/auth/verify-otp
url http://94.103.1.13/gp.xor
sha256 008d097e1fcb21be25a99d435f76e2728fe5bcf90a0b7882899d61334a82f119
sha256 028f91c8430b11f62ebc08ea0e5199589283ab9d4bcec44381877ec59a7c1e2d
sha256 06f6df0f5e37620beb9e3e24a8d0f7742e7d5db7d0f8c1bd4fc10a869443e4e4
sha256 13665bd2b75f8ff7d51e6e7d1d5213f4e1143aedf995258117d3e603e5c69d1c
sha256 13faff78c8da6b10c8e28ed735484cf6c5ece9498a5d6e040828d46352f3519c
sha256 165f4f41542937bc61aa09e5d3c5c3d81e120e11c4a1bf24b461b0a81f18de9e
sha256 3027a212272957298bf4d32505370fa63fb162d6a6a6ec091af9d7626317a858
sha256 36dc72542530ff9707e4c2dcd935edac71129fcb9b7122502a8295264e86a504
sha256 38c5737b1b417d70da8ba72f1b53babc5377733648c2e4b80ba33a991c0e3e9f
sha256 3b5d30e35f8e4f31a3e70d3754d02d0f045e39b6e0cfde22b1754667b7eb60a4
sha256 4430a828f2b19bc729b2eea0405b27d19c568a769b12f0731c720a0ed888de1b
sha256 4b4418928f1b445d555ded02a34ff3f378809d5aeb9da10649cc3562eaa2e5c0
sha256 58592e4b16f28cbcca420ab96f9303f71ba0062260a6eb71ebf0b1e34f3ca3d7
sha256 5b0f529d2834ddb678a309954476a113b1d77ea19bd2b30d299ceee6b06d55b9
sha256 61c0810a23580cf492a6ba4f7654566108331e7a4134c968c2d6a05261b2d8a1
sha256 66928c3316a12091995198710e0c537430dacefac1dbe78f12a331e1520142bd
sha256 7ad4db7a3294b2e1017686c97f9617a0c5f1ce5fcd0cbe58f8d6401d29ecbf39
sha256 8524fbc0d73e711e69d60c64f1f1b7bef35c986705880643dd4d5e17779e586d
sha256 8c3ef59cbc6f44ee96d6e5746fafb2288df3868c5fffa87dc7af24b302a45430
sha256 929cc7bcdff39d5ba305603b475cde8d86c2f6b69532cde8e27ea7e3710efbaa
sha256 9a8e9d587b570d4074f1c8317b163aa8d0c566efd88f294d9d85bc7776352a28
sha256 ad8b5fc7533eefc16ca6e5e52c231abce1c87b9a01c290ec16f9b39a7778fbc2
sha256 aef6ce3014add838cf676b57957d630cd2bb15b0c9193cf349bcffecddbc3623
sha256 b9ffbeed12325c450ba0f3c55cdcd243cdb704115aa3aee784bbdee3243f84e5
sha256 bec87d17b1c1ea975a3ad07fb6e1a79268a563321ffc5525af9dc4e48ea8c9fc
sha256 c2a3592cf37b67b1bdcb389947e6469602b0e52bf247017740c7cc3dddc1e8ae
sha256 cbcaa2bd24ca5ff49aa19790b882aeab5e14da4cf5a9bfcf7747dc5777abdca9
sha256 cc585d962904351ce1d92195b0fc79034dc3b13144f7c7ff24cd9f768b25e9ef
sha256 da302511ee77a4bb9371387ac9932e6431003c9c597ecbe0fd50364f4d7831a8
sha256 e452de35020f6f9dc818a13e299c15893c61b3c98d7883514c6ecede6cd136a3
sha256 e788f829b1a0141a488afb5f82b94f13035623609ca3b83f0c6985919cd9e83b
sha256 f7a4fe18d838e9d87db2db6378ffb21b90c3881d28d70871b8c2a661c6a78a6a
sha256 f90fd97e5cdc1dd6262df9f56068b6ccb753268eaea5a06178856c35f57eeaad
sha256 fb39fa0dd70a8c7bee8c3b68d8ee2d93aa7ed34f358dd5174c8492bc0d3af316
sha1 1e68314f5a42897cea61456add6ffdd6048a9c99
md5 76007508b8317dd76e31996c6adc875a
md5 a0414bc80a594d0796188160ce0db8d8
md5 b12f3970cc224d0eb98b4030f9c2e753
md5 c933e2c2722049c6a8047ceaae1f547f
md5 e3c6cefd462d48f0b30a5ebcd238b5b1
path %APPDATA%\Microsoft\Speech\AudioDriver.exe
path %APPDATA%\READ ME PLEASE.txt
path %APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.url
path %APPDATA%\projectxx.exe
path %APPDATA%\svchost.exe
path %TEMP%\VBE\
path %TEMP%\mapping.csv
path C:\Users\[user]\AppData\Roaming\svchost.exe (mymain) or projectxx.exe (myfile)
path C:\Windows\System32
path C:\cmd_log.txt
registry HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
registry HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr
registry HKCU\Software\Microsoft\Windows\CurrentVersion\Run
registry HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Audio HD Driver
registry HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Store
registry HKLM\Software\Microsoft Defender
registry HKLM\Software\Microsoft Defender\Payload
filename audiodriver.exe
filename chisel.exe
filename gp.exe
filename gp2.exe
filename gp_fat.exe
filename gp_obf.exe
filename indf.exe
filename mimidrv.sys
filename mimikatz.exe
filename mimilib.dll
filename mimilove.exe
filename mimispool.dll
filename mydfile.exe
filename myfile.bat
filename myfile.exe
filename mymain.bat
filename p.exe
filename plink.exe
filename printspoofer.exe
filename projectxx.exe
filename surprise.exe
filename svc.exe
filename uacbypass.exe

111 further values in this feed are not shown above, because they are not an indicator type that can be recognised reliably by shape: command names, fingerprints and behavioural patterns among them. They are all in the raw JSON, which remains the complete record.

Licensed CC BY 4.0, free to use commercially with attribution to The Hunters Ledger.