Warning! We are currently in recovery mode. The complete archive is not available.

Sample details: 9c4dc05c758b79db8f5a6e4d66b0d43e --

Hashes
MD5: 9c4dc05c758b79db8f5a6e4d66b0d43e
SHA1: 6dc1971464dd5bd5a91fc701f299e9fd13d12c3c
SHA256: c1751ffd94fedf1df963244686ecebaf3541d89ecc5330185510e03707fef07c
SSDEEP: 12:4DwXMcpfJqwRjcD0Fr+8QmqJmr5t7fJqwRjcD0Fr+8KJA7Fz4AEdeRmral0wcFzg:TXM2fJJRd784t7fJJRd70ARNEIvlCg
Details
File Type: HTML
Yara Hits
Source
http://lokipanelhosting.ga/nnamdibin/cryptednnamdi.exe
Strings
		<html> 
  <head>
    <title>lokipanelhosting.ga</title>
    <meta http-equiv="refresh" content="1; URL=http://domain.dot.tk/p/?d=LOKIPANELHOSTING.GA&i=173.254.233.139&c=1&ro=0&ref=unknown&_=1549993223399"/>
    <script type="text/javascript">
    <!--
      function redir(){ var $fwd = 'http://domain.dot.tk/p/?d=LOKIPANELHOSTING.GA&i=173.254.233.139&c=1&ro=0&ref=unknown&_=1549993223399'; if(window.parent){ window.parent.location=$fwd; }else{ window.location=$fwd; }}
    //-->
    </script>
  </head>
  <body onload="redir()">
    <script language="text/javascript">
    <!--
      window.setTimeout('redir();', 50 * 1);
    //-->
    </script>
  </body>
</html>