Back to Malware Drops
3bcb3bb397ed0f5c72de9e19109f6daef8d0a03b8951406b2d442fbb90cdf83d
MD5ea5336057c90d93f0196e60b267a10bc
SSDEEP24576:4vRE7caCfKGPqVEDNLFxKsfahI+gIGYuuCol7r:4vREKfPqVE5jKsfahRHGVo7r
File Typeapplication/x-executable
Size1.1 MB
Sources1
Downloads0
First SeenOct 14, 2018
Last SeenOct 14, 2018
Download sample (.zip, password: infected)
Live malware — handle only in an isolated analysis environment.
Originating Attacks
Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.
- Dropped in this session (no command captured).Oct 14, 2018, 7:10:19 AMView attack session
Indicators of Compromise
Values are defanged (e.g. hxxp://, [.]) — not live links.
domain (2)
- dkuug[.]dk
- www[.]gnu[.]org
email (1)
- keld@dkuug[.]dk
ipv4 (37)
- 1[.]0[.]0[.]0
- 10[.]0[.]0[.]0
- 1[.]0[.]0[.]1
- 101[.]47[.]189[.]10
- 101[.]47[.]189[.]18
- 10[.]255[.]255[.]255
- 112[.]100[.]100[.]100
- 112[.]4[.]0[.]55
- 113[.]111[.]211[.]22
- 114[.]114[.]114[.]114
- 114[.]114[.]115[.]115
- 116[.]228[.]111[.]118
- 118[.]29[.]249[.]50
- 118[.]29[.]249[.]54
- 119[.]233[.]255[.]228
- 119[.]6[.]6[.]6
- 122[.]72[.]33[.]240
- 124[.]161[.]97[.]234
- 124[.]161[.]97[.]238
- 124[.]161[.]97[.]242
- 124[.]207[.]160[.]110
- 127[.]0[.]0[.]0
- 127[.]0[.]0[.]1
- 127[.]255[.]255[.]255
- 139[.]175[.]10[.]20
- 139[.]175[.]150[.]20
- 139[.]175[.]252[.]16
- 139[.]175[.]55[.]244
- 168[.]95[.]1[.]1
- 168[.]95[.]192[.]1
- 168[.]95[.]192[.]174
- 172[.]16[.]0[.]0
- 172[.]31[.]255[.]255
- 180[.]168[.]255[.]18
- 192[.]168[.]0[.]0
- 192[.]168[.]255[.]255
- 202[.]100[.]192[.]68