Back to Malware Drops

801191eea50b531eefe6bb461bc5265da26eab2d46d4d64d9abaaf432b1b5b6f

MD508c6ac693d5d43fb8dec0451fe413e34
SSDEEP24576:e845rGHu6gVJKG75oFpA0VWIX4y2y1q2rJp0:745vRVJKGtSA0VWIoBu9p0
File Typeapplication/x-executable
Size1.2 MB
Sources52
Downloads0
First SeenJul 30, 2018
Last SeenAug 27, 2018
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

domain (2)

  • dkuug[.]dk
  • www[.]gnu[.]org

email (1)

  • keld@dkuug[.]dk

ipv4 (37)

  • 1[.]0[.]0[.]0
  • 10[.]0[.]0[.]0
  • 1[.]0[.]0[.]1
  • 101[.]47[.]189[.]10
  • 101[.]47[.]189[.]18
  • 10[.]255[.]255[.]255
  • 112[.]100[.]100[.]100
  • 112[.]4[.]0[.]55
  • 113[.]111[.]211[.]22
  • 114[.]114[.]114[.]114
  • 114[.]114[.]115[.]115
  • 116[.]228[.]111[.]118
  • 118[.]29[.]249[.]50
  • 118[.]29[.]249[.]54
  • 119[.]233[.]255[.]228
  • 119[.]6[.]6[.]6
  • 122[.]72[.]33[.]240
  • 124[.]161[.]97[.]234
  • 124[.]161[.]97[.]238
  • 124[.]161[.]97[.]242
  • 124[.]207[.]160[.]110
  • 127[.]0[.]0[.]0
  • 127[.]0[.]0[.]1
  • 127[.]255[.]255[.]255
  • 139[.]175[.]10[.]20
  • 139[.]175[.]150[.]20
  • 139[.]175[.]252[.]16
  • 139[.]175[.]55[.]244
  • 168[.]95[.]1[.]1
  • 168[.]95[.]192[.]1
  • 168[.]95[.]192[.]174
  • 172[.]16[.]0[.]0
  • 172[.]31[.]255[.]255
  • 180[.]168[.]255[.]18
  • 192[.]168[.]0[.]0
  • 192[.]168[.]255[.]255
  • 202[.]100[.]192[.]68