Back to Malware Drops

976f687aa79ffae3a8285100d5fcfd3ff41ff8266338bde9c7b339a726567f80

MD5c62f7e204d88d61f73493565fde607a0
SSDEEP12288:VOAeE6Gb997NOAeE6Gb997Jbkk+0Ok9+eznL6mhYhrWrfpVngfGg69vMbadCqHxg:VOE6Gb997NOE6Gb997Jbkk+0eeznLJhu
File Typeapplication/x-executable
Size651.4 KB
Sources1
Downloads0
First SeenAug 1, 2018
Last SeenAug 1, 2018
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

domain (2)

  • dkuug[.]dk
  • www[.]gnu[.]org

email (1)

  • keld@dkuug[.]dk

ipv4 (4)

  • 114[.]114[.]114[.]114
  • 1[.]9[.]0[.]5
  • 192[.]168[.]3[.]100
  • 8[.]8[.]8[.]8

url (2)

  • hxxp://%s%s
  • hxxp://www[.]gnu[.]org/software/libc/bugs[.]html