Back to Malware Drops

32ef90f8c01e07a79a1dcd02ea4e47098a6a32afbfe7c6f6dc0b360acd1c6584

MD571fda2b561747274016b30b6213134f0
SSDEEP192:miFa1ZIJlwH8czE0Q+IXo3lrXEqdp5OfbWR9C8n2EUGvZa94KkOUOmoGpLreJAYX:miEHell0FIXo3Wq+WRNn2EUGxa94DO/3
File Typetext/x-script
Size10.4 KB
Sources13
Downloads0
First SeenMay 25, 2021
Last SeenMay 25, 2021
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

domain (2)

  • github[.]com
  • moneroocean[.]stream

email (1)

  • support@moneroocean[.]stream

ipv4 (1)

  • 194[.]5[.]250[.]113

url (4)

  • hxxp://194[.]5[.]250[.]113/xmrig[.]tar[.]gz
  • hxxps://github[.]com
  • hxxps://github[.]com/xmrig/xmrig/releases/latest
  • hxxps://moneroocean[.]stream