Back to Malware Drops

3bcb3bb397ed0f5c72de9e19109f6daef8d0a03b8951406b2d442fbb90cdf83d

MD5ea5336057c90d93f0196e60b267a10bc
SSDEEP24576:4vRE7caCfKGPqVEDNLFxKsfahI+gIGYuuCol7r:4vREKfPqVE5jKsfahRHGVo7r
File Typeapplication/x-executable
Size1.1 MB
Sources1
Downloads0
First SeenOct 14, 2018
Last SeenOct 14, 2018
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

domain (2)

  • dkuug[.]dk
  • www[.]gnu[.]org

email (1)

  • keld@dkuug[.]dk

ipv4 (37)

  • 1[.]0[.]0[.]0
  • 10[.]0[.]0[.]0
  • 1[.]0[.]0[.]1
  • 101[.]47[.]189[.]10
  • 101[.]47[.]189[.]18
  • 10[.]255[.]255[.]255
  • 112[.]100[.]100[.]100
  • 112[.]4[.]0[.]55
  • 113[.]111[.]211[.]22
  • 114[.]114[.]114[.]114
  • 114[.]114[.]115[.]115
  • 116[.]228[.]111[.]118
  • 118[.]29[.]249[.]50
  • 118[.]29[.]249[.]54
  • 119[.]233[.]255[.]228
  • 119[.]6[.]6[.]6
  • 122[.]72[.]33[.]240
  • 124[.]161[.]97[.]234
  • 124[.]161[.]97[.]238
  • 124[.]161[.]97[.]242
  • 124[.]207[.]160[.]110
  • 127[.]0[.]0[.]0
  • 127[.]0[.]0[.]1
  • 127[.]255[.]255[.]255
  • 139[.]175[.]10[.]20
  • 139[.]175[.]150[.]20
  • 139[.]175[.]252[.]16
  • 139[.]175[.]55[.]244
  • 168[.]95[.]1[.]1
  • 168[.]95[.]192[.]1
  • 168[.]95[.]192[.]174
  • 172[.]16[.]0[.]0
  • 172[.]31[.]255[.]255
  • 180[.]168[.]255[.]18
  • 192[.]168[.]0[.]0
  • 192[.]168[.]255[.]255
  • 202[.]100[.]192[.]68