Back to Malware Drops

45290dad2f3ef5dfbaac4a7490a8a933f410d9e7b67692b0a0bb07f4cfc616ff

MD50c707d1793ca59308856fa1038028574
SSDEEP12288:RBRO1UmJJ0nHgBL9YfJip2qm+x4h1TonDp6y07l7mtBDvnD/u9hMHDB:RBRpmJ+HyL9AiAqm+x4h1mD6wvnDWXMN
File Typeapplication/x-executable
Size647.3 KB
Sources1
Downloads0
First SeenJun 18, 2018
Last SeenJun 18, 2018
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

domain (2)

  • dkuug[.]dk
  • www[.]gnu[.]org

email (1)

  • keld@dkuug[.]dk

ipv4 (4)

  • 103[.]25[.]9[.]229
  • 114[.]114[.]114[.]114
  • 127[.]0[.]0[.]1
  • 8[.]8[.]8[.]8

url (1)

  • hxxp://www[.]gnu[.]org/software/libc/bugs[.]html