Back to Malware Drops

69568403ff174953b8a3128f571b755b9e01a836187f2019b50154c686d2b8a0

MD5bf305092b30814e8d65ef5edebcbf470
SSDEEP
File Typetext/x-script
Size1.6 KB
Sources5
Downloads0
First SeenAug 11, 2022
Last SeenAug 11, 2022
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

ipv4 (1)

  • 208[.]67[.]104[.]94

url (11)

  • hxxp://208[.]67[.]104[.]94/a-r[.]m-4;
  • hxxp://208[.]67[.]104[.]94/a-r[.]m-5;
  • hxxp://208[.]67[.]104[.]94/a-r[.]m-6;
  • hxxp://208[.]67[.]104[.]94/i-5[.]8-6;
  • hxxp://208[.]67[.]104[.]94/m-6[.]8-k;
  • hxxp://208[.]67[.]104[.]94/m-i[.]p-s;
  • hxxp://208[.]67[.]104[.]94/m-p[.]s-l;
  • hxxp://208[.]67[.]104[.]94/p-p[.]c-;
  • hxxp://208[.]67[.]104[.]94/s-h[.]4-;
  • hxxp://208[.]67[.]104[.]94/x-3[.]2-;
  • hxxp://208[.]67[.]104[.]94/x-8[.]6-;