Back to Malware Drops
b417a39a274051ac997608490c6e4b1400e74ada8ae3dbda29e760ab8c1d7966
MD5f4922df506326cdf85f5abae704ece52
SSDEEP384:orsevQ4rDp2q7wuGNq6Q2fy4U+07kL3lT:KsevQ4rDp2q7hGNqJZo0oL3N
File Typetext/x-script
Size26.1 KB
Sources6,656
Downloads0
First SeenNov 16, 2018
Last SeenFeb 25, 2019
Download sample (.zip, password: infected)
Live malware — handle only in an isolated analysis environment.
Originating Attacks
Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.
- Dropped in this session (no command captured).Nov 16, 2018, 6:35:51 AMView attack session
- Dropped in this session (no command captured).Nov 16, 2018, 6:35:51 AMView attack session
- Dropped in this session (no command captured).Nov 16, 2018, 6:35:51 AMView attack session
- Dropped in this session (no command captured).Nov 16, 2018, 6:35:51 AMView attack session
- Dropped in this session (no command captured).Nov 16, 2018, 6:35:51 AMView attack session
Indicators of Compromise
Values are defanged (e.g. hxxp://, [.]) — not live links.
domain (1)
- www[.]pairc[.]com
ipv4 (4)
- 2[.]4[.]33[.]3
- 2[.]6[.]18[.]1
- 2[.]6[.]18[.]5
- 91[.]191[.]19[.]205
url (2)
- hxxp://([^/:
- hxxp://www[.]pairc[.]com/\001