Back to Malware Drops

17c4914752e2ea61cec5f03fd678d726e7fd2c595ae73c7ea8da5391a4ce8e6d

MD504c77fc65cd6a0a531df971cf100ac8e
SSDEEP384:0rsevQ4rDp2q7wuGNq6Q2fy4U+07kL3lT:+sevQ4rDp2q7hGNqJZo0oL3N
File Typetext/x-script
Size26.1 KB
Sources1,793
Downloads0
First SeenJun 19, 2018
Last SeenJun 19, 2018
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

domain (1)

  • www[.]pairc[.]com

ipv4 (4)

  • 185[.]45[.]193[.]228
  • 2[.]4[.]33[.]3
  • 2[.]6[.]18[.]1
  • 2[.]6[.]18[.]5

url (2)

  • hxxp://([^/:
  • hxxp://www[.]pairc[.]com/\001