Back to Malware Drops

936f299c0c6605bef1afc842cbf8b34c83cd245118085fe2b989013c7054ad7d

MD50e54c0e97504d0ce174fb62e2a041c0c
SSDEEP
File Typetext/x-script
Size1.3 KB
Sources37
Downloads0
First SeenApr 23, 2019
Last SeenApr 23, 2019
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

domain (1)

  • upajmeter[.]com

url (5)

  • hxxp://upajmeter[.]com/[.]foo/nano[.]php
  • hxxp://upajmeter[.]com/[.]foo/remote/cron[.]sh
  • hxxp://upajmeter[.]com/[.]foo/remote/info[.]php
  • hxxp://upajmeter[.]com/[.]foo/remote/info[.]php`
  • hxxp://upajmeter[.]com/[.]foo/sslm[.]tgz