Back to Malware Drops
2ebb4fa022e5698c07c274ccbb8e6f08fe45713728ca303d73e5bafc97ef9ee5
MD5dd5d6bc848a848990a233eed2e751044
SSDEEP—
File Typetext/x-script
Size1.5 KB
Sources28
Downloads0
First SeenApr 26, 2021
Last SeenApr 26, 2021
Download sample (.zip, password: infected)
Live malware — handle only in an isolated analysis environment.
Originating Attacks
Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.
- Dropped in this session (no command captured).Apr 26, 2021, 5:31:43 AMView attack session
- Dropped in this session (no command captured).Apr 26, 2021, 5:31:43 AMView attack session
- Dropped in this session (no command captured).Apr 26, 2021, 5:31:43 AMView attack session
- Dropped in this session (no command captured).Apr 26, 2021, 5:31:43 AMView attack session
- Dropped in this session (no command captured).Apr 26, 2021, 5:31:43 AMView attack session
Indicators of Compromise
Values are defanged (e.g. hxxp://, [.]) — not live links.
ipv4 (1)
- 199[.]188[.]103[.]138
url (12)
- hxxp://199[.]188[.]103[.]138/ARMV4L;
- hxxp://199[.]188[.]103[.]138/ARMV5L;
- hxxp://199[.]188[.]103[.]138/ARMV6L;
- hxxp://199[.]188[.]103[.]138/I586;
- hxxp://199[.]188[.]103[.]138/I686;
- hxxp://199[.]188[.]103[.]138/M68K;
- hxxp://199[.]188[.]103[.]138/MIPS;
- hxxp://199[.]188[.]103[.]138/MIPSEL;
- hxxp://199[.]188[.]103[.]138/POWERPC;
- hxxp://199[.]188[.]103[.]138/SH4;
- hxxp://199[.]188[.]103[.]138/SPARC;
- hxxp://199[.]188[.]103[.]138/X86_64;