Back to Malware Drops

eca94f5cde6f1e30efba2a5ea33f9ff5dfdc6934e337fc75589cdc2ca0c059ab

MD57b8101b426d0f38eabc94ea636b5c1c2
SSDEEP192:3se8qBmCdlAv1vPsveBO6tkwtmbWRdXFpxSF459KpNfErCTo3d/7VdGQUhUVs9gC:3LZlAvlsuO6t1mb5fECToNo9k+
File Typetext/x-script
Size32.6 KB
Sources2
Downloads0
First SeenJun 18, 2018
Last SeenJun 18, 2018
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

domain (1)

  • dvl[.]by[.]ru

ipv4 (1)

  • 81[.]4[.]106[.]63

url (1)

  • hxxp://dvl[.]by[.]ru/xpl