Back to Malware Drops

b417a39a274051ac997608490c6e4b1400e74ada8ae3dbda29e760ab8c1d7966

MD5f4922df506326cdf85f5abae704ece52
SSDEEP384:orsevQ4rDp2q7wuGNq6Q2fy4U+07kL3lT:KsevQ4rDp2q7hGNqJZo0oL3N
File Typetext/x-script
Size26.1 KB
Sources6,656
Downloads0
First SeenNov 16, 2018
Last SeenFeb 25, 2019
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

domain (1)

  • www[.]pairc[.]com

ipv4 (4)

  • 2[.]4[.]33[.]3
  • 2[.]6[.]18[.]1
  • 2[.]6[.]18[.]5
  • 91[.]191[.]19[.]205

url (2)

  • hxxp://([^/:
  • hxxp://www[.]pairc[.]com/\001