Back to Malware Drops

79197e90329ff0c84b88e3eaa4f0ce1393bae0df74752272dea84db849798231

MD5ca42fda581175fd85ba7dab8243204e4
SSDEEP384:i+IEe4Xz2Ye6/NB3uva4zBfty1jX1Gujt1lifvzM5re2Mb:i+IEe4Xz2YeGNB3unfcjROgI
File Typetext/x-script
Size33.9 KB
Sources56
Downloads0
First SeenJul 5, 2018
Last SeenNov 9, 2018
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

ipv4 (2)

  • 54[.]37[.]72[.]170
  • 8[.]8[.]8[.]8

url (1)

  • hxxp://([^/: