Haha, 'Fy.exe'? Really? They couldn't come up with a more creative file name? And the domain 'iraniansk.com' - sounds like it was registered by a toddler.
The nginx server and the content type 'application/octet-stream' are also good signs that something fishy is going on. I bet the hash value is just there to confuse us.
The domain name 'iraniansk.com' and the file name 'Fy.exe' are definitely indicators of compromise for Emotet malware. This is really helpful information to detect and prevent such attacks.
Jordan
Dottie
6 days agoArt
17 days agoPearly
18 days agoCasey
21 days agoFausto
21 hours agoJohnathon
27 days ago