Back to Malware Drops
f572475f74bf2ebcfb0cc6463221829bc4b24567c0ef40576ca8a901f549b924
MD588a9bec9194e5fc11f06f66854568dbc
SSDEEP384:I4NqqoC/XqXIEe4Xz2Ye6/NBYLQ4zfftyRFXyzujt6JJJFJJJ5ifvzM5re2Mj:b+XIEe4Xz2YeGNBYLDfUBUOgm
File Typetext/x-script
Size38.1 KB
Sources4
Downloads0
First SeenMay 21, 2021
Last SeenMay 26, 2021
Download sample (.zip, password: infected)
Live malware — handle only in an isolated analysis environment.
Originating Attacks
Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.
- Dropped in this session (no command captured).May 21, 2021, 6:27:09 AMView attack session
- Dropped in this session (no command captured).May 21, 2021, 6:27:09 AMView attack session
- Dropped in this session (no command captured).May 21, 2021, 6:27:09 AMView attack session
- Dropped in this session (no command captured).May 21, 2021, 6:27:09 AMView attack session
Indicators of Compromise
Values are defanged (e.g. hxxp://, [.]) — not live links.
ipv4 (2)
- 142[.]93[.]169[.]146
- 8[.]8[.]8[.]8
url (1)
- hxxp://([^/: