Back to Malware Drops

ed4e309708d4923282c847d6326744cbfb5cc55d6a6361bc3c4d612d3fb53fde

MD52a7054a89e506e91fa6efd2227a358d3
SSDEEP
File Typeunknown
Size2.0 KB
Sources13
Downloads0
First SeenApr 16, 2020
Last SeenApr 16, 2020
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

ipv4 (1)

  • 206[.]189[.]20[.]60

url (12)

  • hxxp://206[.]189[.]20[.]60/a-r[.]m-4[.]GHOUL;
  • hxxp://206[.]189[.]20[.]60/a-r[.]m-5[.]GHOUL;
  • hxxp://206[.]189[.]20[.]60/a-r[.]m-6[.]GHOUL;
  • hxxp://206[.]189[.]20[.]60/a-r[.]m-7[.]GHOUL;
  • hxxp://206[.]189[.]20[.]60/i-5[.]8-6[.]GHOUL;
  • hxxp://206[.]189[.]20[.]60/m-6[.]8-k[.]GHOUL;
  • hxxp://206[.]189[.]20[.]60/m-i[.]p-s[.]GHOUL;
  • hxxp://206[.]189[.]20[.]60/m-p[.]s-l[.]GHOUL;
  • hxxp://206[.]189[.]20[.]60/p-p[.]c-[.]GHOUL;
  • hxxp://206[.]189[.]20[.]60/s-h[.]4-[.]GHOUL;
  • hxxp://206[.]189[.]20[.]60/x-3[.]2-[.]GHOUL;
  • hxxp://206[.]189[.]20[.]60/x-8[.]6-[.]GHOUL;