Back to Malware Drops
06e4ae105237c80ec9402bcee919912e17006c532c7e88fcbc76264b433e16f4
MD56dd71eef2f22ba6236bc9192baf3601e
SSDEEP384:00FINvSo5o/D6eIoq47z2YEEFXBwBfZ4zLZP1hncu/tpbOfvuy/97M8T:jC2Ioq47z2YEmXBwBshvbSZX
File Typetext/x-script
Size41.6 KB
Sources28
Downloads0
First SeenMar 16, 2022
Last SeenMar 17, 2022
Download sample (.zip, password: infected)
Live malware — handle only in an isolated analysis environment.
Originating Attacks
Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.
- Dropped in this session (no command captured).Mar 16, 2022, 4:14:51 PMView attack session
- Dropped in this session (no command captured).Mar 16, 2022, 4:14:51 PMView attack session
- Dropped in this session (no command captured).Mar 16, 2022, 4:14:51 PMView attack session
- Dropped in this session (no command captured).Mar 16, 2022, 4:14:51 PMView attack session
- Dropped in this session (no command captured).Mar 16, 2022, 4:14:51 PMView attack session
Indicators of Compromise
Values are defanged (e.g. hxxp://, [.]) — not live links.
ipv4 (1)
- 172[.]104[.]243[.]18
url (1)
- hxxp://([^/: