Back to Malware Drops

7384d6cad439bf3e56a5d40af3b8c190acbb9914d6cc60ef05c6a9fd3c038461

MD55a7e3ab1311ac0c48b74c32b963289ae
SSDEEP1536:YRlihXw+3jJYqQwaAub/J0lBHOJWWkiju/1J5sSgz5t6Y:HhXfTJxdaAkJ0ltOJrkiju/1cSOz
File Typeapplication/x-executable
Size56.9 KB
Sources10
Downloads0
First SeenJul 13, 2020
Last SeenJul 13, 2020
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

domain (2)

  • cnc[.]devilsden[.]net
  • schemas[.]xmlsoap[.]org

ipv4 (1)

  • 185[.]172[.]110[.]179

url (5)

  • hxxp://185[.]172[.]110[.]179/666[.]sh
  • hxxp://185[.]172[.]110[.]179/666[.]sh%20-O%20-%3E%20/tmp/jno;sh%20/tmp/jno%27/&waninf=1_INTERNET_R_VID_154$
  • hxxp://cnc[.]devilsden[.]net/666[.]sh%20-O%20-%3E%20/tmp/jno;sh%20/tmp/jno%27/&sessionKey=1039230114
  • hxxp://schemas[.]xmlsoap[.]org/soap/encoding/
  • hxxp://schemas[.]xmlsoap[.]org/soap/envelope/