Back to Malware Drops
549b84b5841e824c9da92d8f2b8179d3dc88a36be666b7eb1db850d6039be8ff
MD574f94c26c6fcccb1106d195f7ebb0514
SSDEEP49152:FcXS0KUlIx32lkpQmQkpfb4Zs7SLGHrWu9Paue/Yr/S+iGonw3Eb0Q4eHJHme6V4:FcXS1UlIx32lk7pfb4Zs7SL7J1I/SMo9
File Typeapplication/x-executable
Size2.3 MB
Sources1
Downloads0
First SeenMay 13, 2019
Last SeenMay 13, 2019
Download sample (.zip, password: infected)
Live malware — handle only in an isolated analysis environment.
Originating Attacks
Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.
- Dropped in this session (no command captured).May 13, 2019, 3:41:38 AMView attack session
Indicators of Compromise
Values are defanged (e.g. hxxp://, [.]) — not live links.
domain (2)
- dkuug[.]dk
- www[.]gnu[.]org
email (1)
- keld@dkuug[.]dk
url (1)
- hxxp://www[.]gnu[.]org/software/libc/bugs[.]html