Saw it on hybrid analysis. I haven't extracted the config.
https://www.hybrid-analysis.com/sample/ ... mentId=100
Unpacked in the attachment
It communicates with 81.177.23.247
https://www.hybrid-analysis.com/sample/ ... mentId=100
Unpacked in the attachment
It communicates with 81.177.23.247
Attachments
password:infected
(62.9 KiB) Downloaded 59 times
(62.9 KiB) Downloaded 59 times
@xorsthingsv2