Back to Malware Drops
d2e1102bd1e275d3bbdcd2463437bbddc27029e1fe0beab53eaed8814947c821
MD5db84009c201908811027b5d66d670870
SSDEEP192:xsj0FBmCdlAv1vPsveB3Otkwt7bWRdXFpxSF459KjNfErCTo3d/7VdGQUhUVs9gC:xRZlAvlsu3Ot17b/fECToNo9k+
File Typetext/x-script
Size32.6 KB
Sources4
Downloads0
First SeenNov 10, 2020
Last SeenNov 10, 2020
Download sample (.zip, password: infected)
Live malware — handle only in an isolated analysis environment.
Originating Attacks
Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.
- Dropped in this session (no command captured).Nov 10, 2020, 8:55:29 PMView attack session
- Dropped in this session (no command captured).Nov 10, 2020, 8:55:29 PMView attack session
- Dropped in this session (no command captured).Nov 10, 2020, 8:55:29 PMView attack session
- Dropped in this session (no command captured).Nov 10, 2020, 8:55:29 PMView attack session
Indicators of Compromise
Values are defanged (e.g. hxxp://, [.]) — not live links.
domain (1)
- dvl[.]by[.]ru
url (1)
- hxxp://dvl[.]by[.]ru/xpl