Back to Malware Drops

2ebb4fa022e5698c07c274ccbb8e6f08fe45713728ca303d73e5bafc97ef9ee5

MD5dd5d6bc848a848990a233eed2e751044
SSDEEP
File Typetext/x-script
Size1.5 KB
Sources28
Downloads0
First SeenApr 26, 2021
Last SeenApr 26, 2021
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

ipv4 (1)

  • 199[.]188[.]103[.]138

url (12)

  • hxxp://199[.]188[.]103[.]138/ARMV4L;
  • hxxp://199[.]188[.]103[.]138/ARMV5L;
  • hxxp://199[.]188[.]103[.]138/ARMV6L;
  • hxxp://199[.]188[.]103[.]138/I586;
  • hxxp://199[.]188[.]103[.]138/I686;
  • hxxp://199[.]188[.]103[.]138/M68K;
  • hxxp://199[.]188[.]103[.]138/MIPS;
  • hxxp://199[.]188[.]103[.]138/MIPSEL;
  • hxxp://199[.]188[.]103[.]138/POWERPC;
  • hxxp://199[.]188[.]103[.]138/SH4;
  • hxxp://199[.]188[.]103[.]138/SPARC;
  • hxxp://199[.]188[.]103[.]138/X86_64;