Back to Malware Drops

35bc8d41eb573e8553bb7be33ab0b2ca1ce3b87842e8f6e8f383e6f13b57d9e5

MD59bd509238c2e3e4801daba9ca2860a4d
SSDEEP12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrraT6yF8EEP4UlUuTh1AG:FBXmkN/+Fhu/Qo4h9L+zNNaBVEBl/91h
File Typeapplication/x-executable
Size611.2 KB
Sources4
Downloads0
First SeenDec 31, 2020
Last SeenFeb 7, 2021
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

domain (2)

  • dkuug[.]dk
  • www[.]gnu[.]org

email (1)

  • keld@dkuug[.]dk

ipv4 (3)

  • 127[.]0[.]0[.]1
  • 8[.]8[.]4[.]4
  • 8[.]8[.]8[.]8

url (1)

  • hxxp://www[.]gnu[.]org/software/libc/bugs[.]html