Back to Malware Drops
8e3f3cef620f28881a88e685cda157a1fae53525b4e11d83915cfdd413b53c1a
MD57bc4c22b0f34ef28b69d83a23a6c88c5
SSDEEP384:QcU5HNi/c2IyEe4Xz2Oe6rDBPX94zBXgPDehElu/tYBnJJJPOfskU/TkU/97M8J:aiIyEe4Xz2OeIDBPXYXcCKBp7lTl1
File Typetext/x-script
Size43.7 KB
Sources153
Downloads0
First SeenNov 9, 2022
Last SeenJul 8, 2023
Download sample (.zip, password: infected)
Live malware — handle only in an isolated analysis environment.
Originating Attacks
Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.
- Dropped in this session (no command captured).Nov 9, 2022, 10:04:38 PMView attack session
- Dropped in this session (no command captured).Nov 9, 2022, 10:04:38 PMView attack session
- Dropped in this session (no command captured).Nov 9, 2022, 10:04:38 PMView attack session
- Dropped in this session (no command captured).Nov 9, 2022, 10:04:38 PMView attack session
- Dropped in this session (no command captured).Nov 9, 2022, 10:04:38 PMView attack session
Indicators of Compromise
Values are defanged (e.g. hxxp://, [.]) — not live links.
btc (1)
- 3QeXceeDeDMaXseNDQeXceeDeDMaX6
domain (2)
- api[.]dev[.]c0llision[.]net
- d00r[.]110mb[.]com
ipv4 (1)
- 192[.]3[.]141[.]163
url (4)
- hxxp://([^/:
- hxxp://api[.]dev[.]c0llision[.]net/json/crack/md5/
- hxxp://d00r[.]110mb[.]com
- hxxp://d00r[.]110mb[.]com/hash[.]php?enc=