Back to Malware Drops

3807990d1963451143b6b1c264d9a887f337c228eea8d6c282d27ab29327eb65

MD56719418281513dffc789f1ec26ccbc54
SSDEEP
File Typetext/x-script
Size1.5 KB
Sources33
Downloads0
First SeenJul 31, 2020
Last SeenAug 2, 2020
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

ipv4 (1)

  • 93[.]114[.]82[.]21

url (12)

  • hxxp://93[.]114[.]82[.]21/armv4l;
  • hxxp://93[.]114[.]82[.]21/armv5l;
  • hxxp://93[.]114[.]82[.]21/armv6l;
  • hxxp://93[.]114[.]82[.]21/i586;
  • hxxp://93[.]114[.]82[.]21/i686;
  • hxxp://93[.]114[.]82[.]21/m68k;
  • hxxp://93[.]114[.]82[.]21/mips;
  • hxxp://93[.]114[.]82[.]21/mipsel;
  • hxxp://93[.]114[.]82[.]21/powerpc;
  • hxxp://93[.]114[.]82[.]21/sh4;
  • hxxp://93[.]114[.]82[.]21/sparc;
  • hxxp://93[.]114[.]82[.]21/x86;