Back to Malware Drops
b4e7c93ad0ead0fc33bc16343657b69ddb92ee8518f92e649647ccbc73a2cc9a
MD58a9295908c1c4a948f3cbf553be30c29
SSDEEP12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrrgT6yF8EEP4UlUuTh1AG:FBXmkN/+Fhu/Qo4h9L+zNNgBVEBl/91h
File Typeapplication/x-executable
Size611.2 KB
Sources9
Downloads0
First SeenJul 16, 2020
Last SeenNov 8, 2020
Download sample (.zip, password: infected)
Live malware — handle only in an isolated analysis environment.
Originating Attacks
Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.
- Dropped in this session (no command captured).Jul 16, 2020, 6:58:53 AMView attack session
- Dropped in this session (no command captured).Jul 16, 2020, 6:58:53 AMView attack session
- Dropped in this session (no command captured).Jul 16, 2020, 6:58:53 AMView attack session
- Dropped in this session (no command captured).Jul 16, 2020, 6:58:53 AMView attack session
- Dropped in this session (no command captured).Jul 16, 2020, 6:58:53 AMView attack session
Indicators of Compromise
Values are defanged (e.g. hxxp://, [.]) — not live links.
domain (2)
- dkuug[.]dk
- www[.]gnu[.]org
email (1)
- keld@dkuug[.]dk
ipv4 (3)
- 127[.]0[.]0[.]1
- 8[.]8[.]4[.]4
- 8[.]8[.]8[.]8
url (1)
- hxxp://www[.]gnu[.]org/software/libc/bugs[.]html