Back to Malware Drops

f6a6a600b683b2602afbbac7d7cd937f0465e10e2f053591c57675776096104c

MD52116bec57ff86548fd82f0e8065637f7
SSDEEP768:NYdAIMjtlv1UPRLL976ozJxKawa3X8gLKba05lJ/6FnlC4poj6E3o2Z:iG5jtlyJLB6OXK63X8KmaOXSFnnAFo2Z
File Typeapplication/x-executable
Size30.0 KB
Sources21
Downloads0
First SeenJul 29, 2020
Last SeenAug 6, 2020
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

domain (1)

  • upx[.]sf[.]net

url (1)

  • hxxp://upx[.]sf[.]net