THE HUNTER’S LEDGER
IOC Feed
Remcos RAT OpenDirectory Campaign
24 indicators extracted from this investigation's feed. Filter by type, then copy or download exactly what is on screen.
24 shown
TypeIndicator
ipv4 203.159.90.147
url http://203.159.90.147/Backdoor.exe
url http://203.159.90.147/Payload.exe
sha256 db218dd5f53fbcf39a6db043c8455667c3dbef44abe14865e8b962b4c676372e
sha256 ebdd31a7622288b15439396a5758ffb0133d28b4bb11e9386187661a4b7d5f82
sha1 45aa592f3b30ef526e380978338718f540cff5d2
sha1 d71f4efb31786ae71bdd5e7e32531a2698455954
md5 04693af3b0a7c9788daba8e35f429ba6
md5 3d7b442573acf64c3aad17b23d224dc9
path C:\Users\*\AppData\Local\Temp\0.dll
path C:\Users\*\AppData\Local\Temp\install.bat
path C:\Users\*\AppData\Roaming\remcos\remcos.exe
path C:\Users\*\Desktop\desktop.ini, C:\Users\*\Documents\desktop.ini
path C:\Users\[USERNAME]\AppData\Roaming\remcos\remcos.exe
path C:\WINDOWS\system32\userinit.exe,
path C:\WINDOWS\system32\userinit.exe, "C:\Users\[USERNAME]\AppData\Roaming\remcos\remcos.exe"
registry HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
registry HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
registry HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
registry HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
filename backdoor.exe
filename p.ini
filename payload.exe

84 further values in this feed are not shown above, because they are not an indicator type that can be recognised reliably by shape: command names, fingerprints and behavioural patterns among them. They are all in the raw JSON, which remains the complete record.

Licensed CC BY 4.0, free to use commercially with attribution to The Hunters Ledger.