Back to Malware Drops

cae7d1d4c803a2cf6feda5de705efad7693db7746cb40deed05dc23a92e904b4

MD59e33a3523e161fc2628a6c771f8d84e9
SSDEEP384:XdEHebVBNfm1BjfeWBJfitbqTOu0mdxeApKlDU1uRiGfxTS4moGTl15D6/g:Xd4Q3O1FGWLKVqT3rpKlDQuRiGfx15G/
File Typetext/x-script
Size13.2 KB
Sources221
Downloads0
First SeenJun 12, 2021
Last SeenJun 29, 2021
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

domain (2)

  • c3pool[.]com
  • github[.]com

email (1)

  • support@c3pool[.]com

url (4)

  • hxxps://c3pool[.]com
  • hxxps://github[.]com
  • hxxps://github[.]com/xmrig/xmrig/releases/latest
  • hxxps://raw[.]githubusercontent[.]com/C3Pool/xmrig_setup/master/xmrig[.]tar[.]gz