Vojtěch Hronn00bDebugger

Indicators of compromise

Indicators from all my analyses in one place. Each set downloads as CSV or JSON, ready to drop straight into a blocklist or a SIEM.

Download the complete list · 31 indicators · 2 analysesCSVJSON
HashesPhase 1 (dropper) / SHA-256feb46ecf8212f3d6d43afff5ff37558a97486ebea72059ea03b29b53f42ed23c
HashesPhase 2 (Psyduck) / SHA-2566f732fbbcbce8f4af84d65d6f016113819e3de4616e1b644b3d4c2086fdabe09
NetworkC2 domainduck12.dynuddns.net
NetworkC2 port1234
NetworkC2 protocolHTTP
NetworkC2 endpoint/Vre
NetworkC2 endpoint/AW
NetworkC2 endpoint/SS
NetworkC2 endpoint/CF
NetworkC2 endpoint/DF
NetworkC2 endpoint/DR
NetworkExternal IP lookup servicehttps://icanhazip.com
HostTemporary created file%TEMP%\agent_1781054578.ps1
HostSaved executable filename%TEMP%\ce.exe (CK command)
HostSaved executable filename%TEMP%\update.exe (/DLF default)
HostGlobal mutex nameGlobal\677d95b1-c2a4-4c21-a54f-874ddf08e8c9
HostVictim unique ID prefixapp_
HostC2 command delimiter|V|
HostMasquerade stringApex Monitoring Co Fleet Monitor Agent
BehaviorUser-Agent patternapp_<random>\<hostname>\<user>\<OS>\<AV>\<UAC>\<.NET>\<exclusions>\<window>
BehaviorExecution Policy bypass parameter-ep bypass
BehaviorHidden execution parameter-WindowStyle Hidden
BehaviorWMI namespace and classroot/SecurityCenter2: AntiVirusProduct
BehaviorRegistry key readHKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System (ConsentPromptBehaviorAdmin)
Files and paths/tmp/alego.zip
Files and paths/tmp/stravy/
Files and paths~/.pwd
Files and paths~/.username
Networkuterimoxis.com
Networkmekoilsuharum.com
Processes / BehaviorAppleScript dialog titled “macOS Protection Service” requesting the system password