Back to Malware Drops

549b84b5841e824c9da92d8f2b8179d3dc88a36be666b7eb1db850d6039be8ff

MD574f94c26c6fcccb1106d195f7ebb0514
SSDEEP49152:FcXS0KUlIx32lkpQmQkpfb4Zs7SLGHrWu9Paue/Yr/S+iGonw3Eb0Q4eHJHme6V4:FcXS1UlIx32lk7pfb4Zs7SL7J1I/SMo9
File Typeapplication/x-executable
Size2.3 MB
Sources1
Downloads0
First SeenMay 13, 2019
Last SeenMay 13, 2019
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

domain (2)

  • dkuug[.]dk
  • www[.]gnu[.]org

email (1)

  • keld@dkuug[.]dk

url (1)

  • hxxp://www[.]gnu[.]org/software/libc/bugs[.]html