Back to Malware Drops
53ac3becb0b2b3afecaa34fc8cd78c364dfa52bf9b58edc93165d4c85ee3cd87
MD533b736ad4156314020005094ab2241c4
SSDEEP384:fGQsGaHFHkH1TDKzHwMHPOHMhH75UbGcjpW:fkmH1TDKrwcPeMJ75UbjpW
File Typetext/x-script
Size19.2 KB
Sources47
Downloads0
First SeenAug 29, 2022
Last SeenAug 30, 2022
Download sample (.zip, password: infected)
Live malware — handle only in an isolated analysis environment.
Originating Attacks
Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.
- Dropped in this session (no command captured).Aug 29, 2022, 9:17:38 PMView attack session
- Dropped in this session (no command captured).Aug 29, 2022, 9:17:38 PMView attack session
- Dropped in this session (no command captured).Aug 29, 2022, 9:17:38 PMView attack session
- Dropped in this session (no command captured).Aug 29, 2022, 9:17:38 PMView attack session
- Dropped in this session (no command captured).Aug 29, 2022, 9:17:38 PMView attack session
Indicators of Compromise
Values are defanged (e.g. hxxp://, [.]) — not live links.
domain (2)
- jira[.]letmaker[.]top
- update[.]aegis[.]aliyun[.]com
ipv4 (7)
- 10[.]0[.]0[.]0
- 127[.]0[.]0[.]1
- 172[.]16[.]0[.]0
- 192[.]168[.]0[.]0
- 194[.]38[.]23[.]170
- 51[.]255[.]171[.]23
- 89[.]34[.]27[.]167
url (11)
- hxxp://$url/jira
- hxxp://$url/jira?confluence
- hxxp://194[.]38[.]23[.]170
- hxxp://89[.]34[.]27[.]167
- hxxp://89[.]34[.]27[.]167/jira
- hxxp://89[.]34[.]27[.]167/jira?confluence
- hxxp://jira[.]letmaker[.]top
- hxxp://update[.]aegis[.]aliyun[.]com/download/quartz_uninstall[.]sh
- hxxp://update[.]aegis[.]aliyun[.]com/download/quartz_uninstall[.]sh||curl
- hxxp://update[.]aegis[.]aliyun[.]com/download/uninstall[.]sh
- hxxp://update[.]aegis[.]aliyun[.]com/download/uninstall[.]sh||curl