Back to Malware Drops

7e4869bd5d13789bdf9fba180f5b9c2c815a0f43d15b6bcd98e96a33f78b08b6

MD50d294133edebfe425a0fa4b19b044b31
SSDEEP49152:bNihhOhBNhKhyu7cYx9z2rAnKsfR+aFyZB5Ss5+Nu:5ihhOhBNhKhRwwJ2ro4aFyZB5Ss5+Nu
File Typeapplication/x-executable
Size1.8 MB
Sources1
Downloads0
First SeenDec 12, 2018
Last SeenDec 12, 2018
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

domain (2)

  • dkuug[.]dk
  • www[.]gnu[.]org

email (1)

  • keld@dkuug[.]dk

ipv4 (1)

  • 192[.]168[.]1[.]101

url (1)

  • hxxp://www[.]gnu[.]org/software/libc/bugs[.]html