Back to Malware Drops

388a83e48ac4fc3433c1721b461166316b9e9c78488b421c030879395df8e9d7

MD5a8d67adb7bfb118cb559c1192af059af
SSDEEP12:HfEda03JWWKJY6BfEdMOBvNPSm0fEdQ2rkL2nTvyaty:m3J2Y6mBmALTKwy
File Typetext/x-script
Size538 B
Sources21
Downloads0
First SeenSep 2, 2018
Last SeenSep 2, 2018
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

domain (1)

  • bookaires[.]com

url (3)

  • hxxp://bookaires[.]com/feed/remote/hist[.]sh
  • hxxp://bookaires[.]com/feed/remote/nano[.]sh
  • hxxp://bookaires[.]com/feed/sslm[.]tgz