Warning! We are currently in recovery mode. The complete archive is not available.

Sample details: 8b80f23808b81fa355700d2770ee1a1e --

Hashes
MD5: 8b80f23808b81fa355700d2770ee1a1e
SHA1: b4c68b6c1e2f8ff8724924614752be27b6c0b4bb
SHA256: a1bc33f5466b8fbba66d0b7a2745f16aeefe046e04a22a51af47b6b1d70d08ba
SSDEEP: 12:4HlnMcpfJ1YjcD0FrrZmqJmr5t7fJ1YjcD0FrPdJA7Fz4AEdeRmral0wcFzHQL:klnM2fJidr4t7fJidPvARNEIvlCg
Details
File Type: HTML
Yara Hits
Source
http://help-roro.gq/WebOS/install/socks/turbo.exe
Strings
		<html> 
  <head>
    <title>help-roro.gq</title>
    <meta http-equiv="refresh" content="1; URL=http://domain.dot.tk/p/?d=HELP-RORO.GQ&i=173.254.233.139&c=1&ro=0&ref=unknown&_=1549966124503"/>
    <script type="text/javascript">
    <!--
      function redir(){ var $fwd = 'http://domain.dot.tk/p/?d=HELP-RORO.GQ&i=173.254.233.139&c=1&ro=0&ref=unknown&_=1549966124503'; if(window.parent){ window.parent.location=$fwd; }else{ window.location=$fwd; }}
    //-->
    </script>
  </head>
  <body onload="redir()">
    <script language="text/javascript">
    <!--
      window.setTimeout('redir();', 50 * 1);
    //-->
    </script>
  </body>
</html>