Back to Malware Drops

d2e1102bd1e275d3bbdcd2463437bbddc27029e1fe0beab53eaed8814947c821

MD5db84009c201908811027b5d66d670870
SSDEEP192:xsj0FBmCdlAv1vPsveB3Otkwt7bWRdXFpxSF459KjNfErCTo3d/7VdGQUhUVs9gC:xRZlAvlsu3Ot17b/fECToNo9k+
File Typetext/x-script
Size32.6 KB
Sources4
Downloads0
First SeenNov 10, 2020
Last SeenNov 10, 2020
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

domain (1)

  • dvl[.]by[.]ru

url (1)

  • hxxp://dvl[.]by[.]ru/xpl