Back to Malware Drops
936f299c0c6605bef1afc842cbf8b34c83cd245118085fe2b989013c7054ad7d
MD50e54c0e97504d0ce174fb62e2a041c0c
SSDEEP—
File Typetext/x-script
Size1.3 KB
Sources37
Downloads0
First SeenApr 23, 2019
Last SeenApr 23, 2019
Download sample (.zip, password: infected)
Live malware — handle only in an isolated analysis environment.
Originating Attacks
Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.
- Dropped in this session (no command captured).Apr 23, 2019, 9:54:53 AMView attack session
- Dropped in this session (no command captured).Apr 23, 2019, 9:54:53 AMView attack session
- Dropped in this session (no command captured).Apr 23, 2019, 9:54:53 AMView attack session
- Dropped in this session (no command captured).Apr 23, 2019, 9:54:53 AMView attack session
- Dropped in this session (no command captured).Apr 23, 2019, 9:54:53 AMView attack session
Indicators of Compromise
Values are defanged (e.g. hxxp://, [.]) — not live links.
domain (1)
- upajmeter[.]com
url (5)
- hxxp://upajmeter[.]com/[.]foo/nano[.]php
- hxxp://upajmeter[.]com/[.]foo/remote/cron[.]sh
- hxxp://upajmeter[.]com/[.]foo/remote/info[.]php
- hxxp://upajmeter[.]com/[.]foo/remote/info[.]php`
- hxxp://upajmeter[.]com/[.]foo/sslm[.]tgz