Back to Malware Drops

683bf0113027a4ce8c8ab05b84dacb82e7ae0f2b5e9b36846692108805fc0e57

MD5d84b6b9e521ea95ab767becb63e030a6
SSDEEP24576:e845rGHu6gVJKG75oFpA0VWIX4n2y1q2rJp0:745vRVJKGtSA0VWIo2u9p0
File Typeapplication/x-executable
Size1.2 MB
Sources1
Downloads0
First SeenNov 27, 2019
Last SeenNov 27, 2019
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

domain (2)

  • dkuug[.]dk
  • www[.]gnu[.]org

email (1)

  • keld@dkuug[.]dk

ipv4 (37)

  • 1[.]0[.]0[.]0
  • 10[.]0[.]0[.]0
  • 1[.]0[.]0[.]1
  • 101[.]47[.]189[.]10
  • 101[.]47[.]189[.]18
  • 10[.]255[.]255[.]255
  • 112[.]100[.]100[.]100
  • 112[.]4[.]0[.]55
  • 113[.]111[.]211[.]22
  • 114[.]114[.]114[.]114
  • 114[.]114[.]115[.]115
  • 116[.]228[.]111[.]118
  • 118[.]29[.]249[.]50
  • 118[.]29[.]249[.]54
  • 119[.]233[.]255[.]228
  • 119[.]6[.]6[.]6
  • 122[.]72[.]33[.]240
  • 124[.]161[.]97[.]234
  • 124[.]161[.]97[.]238
  • 124[.]161[.]97[.]242
  • 124[.]207[.]160[.]110
  • 127[.]0[.]0[.]0
  • 127[.]0[.]0[.]1
  • 127[.]255[.]255[.]255
  • 139[.]175[.]10[.]20
  • 139[.]175[.]150[.]20
  • 139[.]175[.]252[.]16
  • 139[.]175[.]55[.]244
  • 168[.]95[.]1[.]1
  • 168[.]95[.]192[.]1
  • 168[.]95[.]192[.]174
  • 172[.]16[.]0[.]0
  • 172[.]31[.]255[.]255
  • 180[.]168[.]255[.]18
  • 192[.]168[.]0[.]0
  • 192[.]168[.]255[.]255
  • 202[.]100[.]192[.]68