Back to Malware Drops
fc95f9ffb98b274d16d044082c6ff0fe23dd0da58e435fce131b89040c23c40a
MD53cf3e49218623dff4c3ced4bffcf8f95
SSDEEP—
File Typetext/x-script
Size1.0 KB
Sources44
Downloads0
First SeenOct 26, 2018
Last SeenNov 13, 2018
Download sample (.zip, password: infected)
Live malware — handle only in an isolated analysis environment.
Originating Attacks
Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.
- Dropped in this session (no command captured).Oct 26, 2018, 2:51:43 AMView attack session
- Dropped in this session (no command captured).Oct 26, 2018, 2:51:43 AMView attack session
- Dropped in this session (no command captured).Oct 26, 2018, 2:51:43 AMView attack session
- Dropped in this session (no command captured).Oct 26, 2018, 2:51:43 AMView attack session
- Dropped in this session (no command captured).Oct 26, 2018, 2:51:43 AMView attack session
Indicators of Compromise
Values are defanged (e.g. hxxp://, [.]) — not live links.
domain (1)
- www[.]karaibe[.]us
ipv4 (1)
- 67[.]205[.]129[.]169
url (7)
- hxxp://67[.]205[.]129[.]169/[.]foo/monero[.]tgz
- hxxp://67[.]205[.]129[.]169/[.]foo/sslm[.]tgz
- hxxp://www[.]karaibe[.]us/[.]foo/monero[.]tgz
- hxxp://www[.]karaibe[.]us/[.]foo/remote/cron[.]sh
- hxxp://www[.]karaibe[.]us/[.]foo/remote/info[.]php
- hxxp://www[.]karaibe[.]us/[.]foo/remote/info[.]php`
- hxxp://www[.]karaibe[.]us/[.]foo/sslm[.]tgz