Back to Malware Drops

da93d41cd97589703bed81dcd8dc53c0aff6ba4cc6a11bef94bd3fa5c98a2fc3

MD566d882a33fe378c3f81d0cb2fa3b3810
SSDEEP
File Typetext/x-script
Size560 B
Sources3
Downloads0
First SeenOct 13, 2018
Last SeenOct 13, 2018
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

domain (2)

  • ghostbin[.]com
  • pastebin[.]com

ipv4 (1)

  • 185[.]141[.]61[.]17

url (3)

  • hxxp://$WEBSERVER/update/$Binary
  • hxxps://ghostbin[.]com/paste/j84x6
  • hxxps://pastebin[.]com/gUqpAans