Back to Malware Drops
388a83e48ac4fc3433c1721b461166316b9e9c78488b421c030879395df8e9d7
MD5a8d67adb7bfb118cb559c1192af059af
SSDEEP12:HfEda03JWWKJY6BfEdMOBvNPSm0fEdQ2rkL2nTvyaty:m3J2Y6mBmALTKwy
File Typetext/x-script
Size538 B
Sources21
Downloads0
First SeenSep 2, 2018
Last SeenSep 2, 2018
Download sample (.zip, password: infected)
Live malware — handle only in an isolated analysis environment.
Originating Attacks
Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.
- Dropped in this session (no command captured).Sep 2, 2018, 6:50:17 AMView attack session
- Dropped in this session (no command captured).Sep 2, 2018, 6:50:17 AMView attack session
- Dropped in this session (no command captured).Sep 2, 2018, 6:50:17 AMView attack session
- Dropped in this session (no command captured).Sep 2, 2018, 6:50:17 AMView attack session
- Dropped in this session (no command captured).Sep 2, 2018, 6:50:17 AMView attack session
Indicators of Compromise
Values are defanged (e.g. hxxp://, [.]) — not live links.
domain (1)
- bookaires[.]com
url (3)
- hxxp://bookaires[.]com/feed/remote/hist[.]sh
- hxxp://bookaires[.]com/feed/remote/nano[.]sh
- hxxp://bookaires[.]com/feed/sslm[.]tgz