PULSE NAME
resteex_killnet_LVL0
WHITE resteex0 2022-10-11 Modified: 2022-11-17
116
IOCs
HIGH VOLUME
https://www.forescout.com/resources/analysis-of-killnet-report/
Indicators of Compromise (116)
All URL hostname domain FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
URL https://tor-exit6-readme.dfri.se 2022-10-11
URL https://tor-exit3-readme.dfri.se 2022-10-11
URL https://strepo.dfri.se 2022-10-11
URL https://stboot.dfri.se 2022-10-11
URL https://pkg.dfri.se 2022-10-11
URL https://memento.dfri.se 2022-10-11
URL https://matrix.dfri.se 2022-10-11
URL https://matrix-01.dfri.se 2022-10-11
URL https://lists.dfri.se 2022-10-11
URL https://dev.dfri.se 2022-10-11
URL https://agnosia.dfri.se 2022-10-11
URL http://strepo.dfri.se 2022-10-11
URL http://stboot.dfri.se 2022-10-11
URL http://pkg.dfri.se 2022-10-11
URL http://memento.dfri.se 2022-10-11
URL http://matrix-01.dfri.se 2022-10-11
URL http://lists.dfri.se 2022-10-11
URL http://dev.dfri.se 2022-10-11
URL http://agnosia.dfri.se 2022-10-11
hostname stboot.dfri.se 2022-10-11
hostname memento.dfri.se 2022-10-11
hostname matrix.dfri.se 2022-10-11
hostname matrix-01.dfri.se 2022-10-11
hostname mailman.dfri.se 2022-10-11
hostname mail2.dfri.se 2022-10-11
hostname dnsbeta.dfri.se 2022-10-11
hostname dev.dfri.se 2022-10-11
URL https://t.nn-magazine.com 2022-10-11
URL https://assets.nn-magazine.com 2022-10-11
URL http://t.nn-magazine.com 2022-10-11
URL http://nn-magazine.com/Nonude-club.htm 2022-10-11
URL http://assets.nn-magazine.com 2022-10-11
hostname t.nn-magazine.com 2022-10-11
hostname assets.nn-magazine.com 2022-10-11
URL http://www.nn-magazine.com/ 2022-10-11
URL http://tor-exit4-readme.dfri.se/ 2022-10-11
URL http://tor-exit4-readme.dfri.se 2022-10-11
hostname tor-exit4-readme.dfri.se 2022-10-11
domain nn-magazine.com 2022-10-11
domain dfri.se 2022-10-11
FileHash-SHA256 f6b1772b465d16de3ba427306b051a62486a0589acd46463bcd6cd770582802d 2022-10-11
FileHash-SHA256 f49b387cfc98381dc0ebb8651fc641128c9c5eca4d791e52c8d7b22377088933 2022-10-11
FileHash-SHA256 ec43e150012d049bbdf9a552c9a466482c628db8b981064584998a97d2662914 2022-10-11
FileHash-SHA256 e80daf35bfd38ba3b234064f00d87577c1a76c1c4f771161afe4ca9e316ca0f1 2022-10-11
FileHash-SHA256 d890aeafeeac4d6c2d8a1ff8b4d377d9084455a4d46b642da837c05d9b53cdbb 2022-10-11
FileHash-SHA256 b8f765e5e9932ebe8820755b8d75eb00eb6b097316d98cd38bf9224fbf7fb82d 2022-10-11
FileHash-SHA256 b2b6a773b5613d8d507952b4e26fe1ea4c629c3cad902238258c391150064ed1 2022-10-11
FileHash-SHA256 906145c7fbca605c7b8c863504cbe73186810b2b92c982c2257f9bf2675a76fc 2022-10-11
FileHash-SHA256 857df9f995f743358d9379eb9d8ef7848e7969ecc13394600eadbf973076d664 2022-10-11
FileHash-SHA256 7be3b15f184c96d981d37bac297e38f30ff59dc0bfda81910aa9ad434fc1e6be 2022-10-11
FileHash-SHA256 7b0dad1c77e7e11c5e9fc857bfac196a309d6935b18bdbf4835a359ebd32f186 2022-10-11
FileHash-SHA256 75df48121a7ead2e71fa62fd1f1acf0cbf643a13eac683adace18fd117019ff2 2022-10-11
FileHash-SHA256 7282e2fdb25b07554b082f5cf1697315ed5ce3005f985cbe96a34da965869db5 2022-10-11
FileHash-SHA256 7263f345122d60efe2e68a232a831c10d40c2e533ac21180f298bedb40f4a6de 2022-10-11
FileHash-SHA256 5dca574173ec29eab508ab797c6af88456d9960cc56f42d7b86a06eae0cee317 2022-10-11
FileHash-SHA256 4eb265b48380b715930624a601733dc497db74e98ffca1387780ebf022ae0782 2022-10-11
FileHash-SHA256 2b72ed6cd2e3197e2ce7639bb033fbd23d07687565dd406fa267717ca310b45c 2022-10-11
FileHash-SHA256 25d594e84c0967910e0533ee52d4aee285d7ddd6ba61b58aa9e9269212135859 2022-10-11
FileHash-SHA256 0df8384415de0a1a5c56ab98e81d46150bd65bf8b1a2cb21739e5730ef83366e 2022-10-11
FileHash-SHA256 0c1a8e07813f7aa19b4c3a9b654309780e485b7bda6b5a3fc31d2e6114d8e3ea 2022-10-11
URL https://t.me/killnet_channel 2022-10-11
domain myalkatoneketo.com 2022-10-11
hostname www.myalkatoneketo.com 2022-10-11
hostname www.ketoadvancedweightloss.org 2022-10-11
domain ketoadvancedweightloss.org 2022-10-11
domain justketodietblog.com 2022-10-11
hostname www.justketodietblog.com 2022-10-11
hostname www.ketopurereview.com 2022-10-11
domain ketopurereview.com 2022-10-11
hostname vps-3d00216c.vps.ovh.ca 2022-10-11
hostname block2.mmms.eu 2022-10-11
hostname kiriakou.tor-exit.calyxinstitute.org 2022-10-11
domain 16chan.nl 2022-10-11
hostname tor-exit-14.zbau.f3netze.de 2022-10-11
hostname shadowlegion.ddns.net 2022-10-11
hostname shadowlegion.ddns.net 2022-10-11
hostname clanlegion.ddns.net 2022-10-11
domain nonewbs.com 2022-10-11
domain metrica.com.qa 2022-10-11
domain haydenair.com 2022-10-11
domain menefee.us 2022-10-11
domain nexteraretail.biz 2022-10-11
domain conservationutah.net 2022-10-11
domain conservationutah.net 2022-10-11
domain recoverysystemsinstitute.us 2022-10-11
domain officepoliticssurvey.com 2022-10-11
domain vagareluxurywheels.com 2022-10-11
domain environmentsc.net 2022-10-11
domain m88kiosk.com 2022-10-11
hostname cyber.kenuelfood.online 2022-10-11
hostname berlin01.tor-exit.artikel10.org 2022-10-11
hostname seed.nu.crypto-daio.co.uk 2022-10-11
hostname jocker.ddns.net 2022-10-11
hostname freki.enn.lu 2022-10-11
hostname patarendders.kvrddns.com 2022-10-11
hostname pierihalbi.kvrddns.com 2022-10-11
hostname srv1342.walkerservers.com 2022-10-11
hostname server-10.sndcmdex.com 2022-10-11
hostname server-15.googletestadminwin.com 2022-10-11
hostname server-30.sndcmdex.com 2022-10-11
hostname server-20.prostiforum.com 2022-10-11
hostname server-23.sndcmdex.com 2022-10-11
hostname server-20.sndcmdex.com 2022-10-11
hostname server-18.sndcmdex.com 2022-10-11
hostname server-24.sndcmdex.com 2022-10-11
hostname tor-exit-16.zbau.f3netze.de 2022-10-18
hostname tor-exit-16.zbau.f3netze.de 2022-10-18
hostname seed.bc.crypto-daio.co.uk 2022-10-18
hostname researchplanet.zapto.org 2022-10-18
hostname tor-exit-1.zbau.f3netze.de 2022-10-18
hostname ping-ip.hldns.ru 2022-10-18
hostname tor-exit-4.zbau.f3netze.de 2022-10-18
hostname tor-exit-35.for-privacy.net 2022-10-18
hostname api.twist.moe 2022-10-18
domain cock.network 2022-10-18
hostname thorgan.synology.me 2022-10-18