Back to Malware Drops
3f6d2a1c45d75163cad1a41de62d28acc82dfb4a8077066e8da4f5138c6d3d47
MD5a1064fd10a51806aee789a4fa40284f1
SSDEEP48:HnTHBEiqf2vq08cx1Gom+RailmVPv4PJdzCfK7/FZVywOEPwbqa6JI/Ov:zHc8q0xvvRP2vuJdWfK7/FZVcEPhsY
File Typetext/x-script
Size5.8 KB
Sources4
Downloads0
First SeenMar 31, 2019
Last SeenApr 13, 2019
Download sample (.zip, password: infected)
Live malware — handle only in an isolated analysis environment.
Originating Attacks
Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.
- Dropped in this session (no command captured).Mar 31, 2019, 5:58:26 PMView attack session
- Dropped in this session (no command captured).Mar 31, 2019, 5:58:26 PMView attack session
- Dropped in this session (no command captured).Mar 31, 2019, 5:58:26 PMView attack session
- Dropped in this session (no command captured).Mar 31, 2019, 5:58:26 PMView attack session
Indicators of Compromise
Values are defanged (e.g. hxxp://, [.]) — not live links.
domain (1)
- yxarsh[.]shop
ipv4 (3)
- 140[.]82[.]52[.]87
- 185[.]71[.]65[.]238
- 69[.]28[.]55[.]86
url (1)
- hxxp://yxarsh[.]shop/364