Back to Malware Drops
da93d41cd97589703bed81dcd8dc53c0aff6ba4cc6a11bef94bd3fa5c98a2fc3
MD566d882a33fe378c3f81d0cb2fa3b3810
SSDEEP—
File Typetext/x-script
Size560 B
Sources3
Downloads0
First SeenOct 13, 2018
Last SeenOct 13, 2018
Download sample (.zip, password: infected)
Live malware — handle only in an isolated analysis environment.
Originating Attacks
Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.
- Dropped in this session (no command captured).Oct 13, 2018, 11:30:37 PMView attack session
- Dropped in this session (no command captured).Oct 13, 2018, 11:30:37 PMView attack session
- Dropped in this session (no command captured).Oct 13, 2018, 11:30:37 PMView attack session
Indicators of Compromise
Values are defanged (e.g. hxxp://, [.]) — not live links.
domain (2)
- ghostbin[.]com
- pastebin[.]com
ipv4 (1)
- 185[.]141[.]61[.]17
url (3)
- hxxp://$WEBSERVER/update/$Binary
- hxxps://ghostbin[.]com/paste/j84x6
- hxxps://pastebin[.]com/gUqpAans