Back to Malware Drops

6326803ec4d972a4f21aade0964ef219fd902b7a6b199ddf93aafd255cd5feac

MD5d125046dc9d6975c934979a470ca1794
SSDEEP24576:yCa8ARRfmnnphS5aczgzKJFVhtwyhLuaX92Io44FbUwaBN6c:ja8AHmnnS5acketwyhL/IE8bUV6c
File Typeapplication/x-executable
Size1.3 MB
Sources2
Downloads0
First SeenNov 14, 2018
Last SeenNov 14, 2018
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

domain (3)

  • dkuug[.]dk
  • upx[.]sf[.]net
  • www[.]gnu[.]org

email (1)

  • keld@dkuug[.]dk

ipv4 (15)

  • 1[.]0[.]0[.]0
  • 10[.]0[.]0[.]0
  • 1[.]0[.]0[.]1
  • 10[.]255[.]255[.]255
  • 127[.]0[.]0[.]0
  • 127[.]0[.]0[.]1
  • 127[.]255[.]255[.]255
  • 172[.]16[.]0[.]0
  • 172[.]31[.]255[.]255
  • 192[.]168[.]0[.]0
  • 192[.]168[.]255[.]255
  • 254[.]255[.]255[.]254
  • 255[.]0[.]0[.]0
  • 8[.]8[.]4[.]4
  • 8[.]8[.]8[.]8

url (2)

  • hxxp://upx[.]sf[.]net
  • hxxp://www[.]gnu[.]org/software/libc/bugs[.]html