Back to Malware Drops
6326803ec4d972a4f21aade0964ef219fd902b7a6b199ddf93aafd255cd5feac
MD5d125046dc9d6975c934979a470ca1794
SSDEEP24576:yCa8ARRfmnnphS5aczgzKJFVhtwyhLuaX92Io44FbUwaBN6c:ja8AHmnnS5acketwyhL/IE8bUV6c
File Typeapplication/x-executable
Size1.3 MB
Sources2
Downloads0
First SeenNov 14, 2018
Last SeenNov 14, 2018
Download sample (.zip, password: infected)
Live malware — handle only in an isolated analysis environment.
Originating Attacks
Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.
- Dropped in this session (no command captured).Nov 14, 2018, 6:46:52 AMView attack session
- Dropped in this session (no command captured).Nov 14, 2018, 6:46:52 AMView attack session
Indicators of Compromise
Values are defanged (e.g. hxxp://, [.]) — not live links.
domain (3)
- dkuug[.]dk
- upx[.]sf[.]net
- www[.]gnu[.]org
email (1)
- keld@dkuug[.]dk
ipv4 (15)
- 1[.]0[.]0[.]0
- 10[.]0[.]0[.]0
- 1[.]0[.]0[.]1
- 10[.]255[.]255[.]255
- 127[.]0[.]0[.]0
- 127[.]0[.]0[.]1
- 127[.]255[.]255[.]255
- 172[.]16[.]0[.]0
- 172[.]31[.]255[.]255
- 192[.]168[.]0[.]0
- 192[.]168[.]255[.]255
- 254[.]255[.]255[.]254
- 255[.]0[.]0[.]0
- 8[.]8[.]4[.]4
- 8[.]8[.]8[.]8
url (2)
- hxxp://upx[.]sf[.]net
- hxxp://www[.]gnu[.]org/software/libc/bugs[.]html