Back to Malware Drops
eca94f5cde6f1e30efba2a5ea33f9ff5dfdc6934e337fc75589cdc2ca0c059ab
MD57b8101b426d0f38eabc94ea636b5c1c2
SSDEEP192:3se8qBmCdlAv1vPsveBO6tkwtmbWRdXFpxSF459KpNfErCTo3d/7VdGQUhUVs9gC:3LZlAvlsuO6t1mb5fECToNo9k+
File Typetext/x-script
Size32.6 KB
Sources2
Downloads0
First SeenJun 18, 2018
Last SeenJun 18, 2018
Download sample (.zip, password: infected)
Live malware — handle only in an isolated analysis environment.
Originating Attacks
Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.
- Dropped in this session (no command captured).Jun 18, 2018, 8:05:33 PMView attack session
- Dropped in this session (no command captured).Jun 18, 2018, 8:05:33 PMView attack session
Indicators of Compromise
Values are defanged (e.g. hxxp://, [.]) — not live links.
domain (1)
- dvl[.]by[.]ru
ipv4 (1)
- 81[.]4[.]106[.]63
url (1)
- hxxp://dvl[.]by[.]ru/xpl