Warning! We are currently in recovery mode. The complete archive is not available.

Sample details: 4fe69092dde36efa3db33b9a2daae13f --

Hashes
MD5: 4fe69092dde36efa3db33b9a2daae13f
SHA1: 149214cd5dd89ddecfc6b57cff1ddbef21013d38
SHA256: 2eb4c2ad432fde73d7d46d7c915d9a36f7e2e8b5ddf0a75ecad12ff633bd8b22
SSDEEP: 12:4xAyBnMcpfJgA6jcD0FrXPmqJmr5t7fJgA6jcD0FrXGEdJA7Fz4AEdeRmral0wcO:ufnM2fJgZdJ4t7fJgZdWwARNEIvlCg
Details
File Type: HTML
Yara Hits
Source
http://mx2-dokidoki-ne.gq/exe/ALVINRIC.exe
Strings
		<html> 
  <head>
    <title>mx2-dokidoki-ne.gq</title>
    <meta http-equiv="refresh" content="1; URL=http://domain.dot.tk/p/?d=MX2-DOKIDOKI-NE.GQ&i=173.254.233.139&c=1&ro=0&ref=unknown&_=1549947541961"/>
    <script type="text/javascript">
    <!--
      function redir(){ var $fwd = 'http://domain.dot.tk/p/?d=MX2-DOKIDOKI-NE.GQ&i=173.254.233.139&c=1&ro=0&ref=unknown&_=1549947541961'; if(window.parent){ window.parent.location=$fwd; }else{ window.location=$fwd; }}
    //-->
    </script>
  </head>
  <body onload="redir()">
    <script language="text/javascript">
    <!--
      window.setTimeout('redir();', 50 * 1);
    //-->
    </script>
  </body>
</html>