Back to Malware Drops

8c600c925ea8f6e171caa504e66e653c25e733f21e7bebd5c0613e6eed4785cb

MD5b807011ef07985dea3a2166ae7c33500
SSDEEP
File Typetext/x-script
Size2.0 KB
Sources30
Downloads0
First SeenAug 14, 2022
Last SeenAug 14, 2022
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

ipv4 (1)

  • 109[.]206[.]241[.]219

url (20)

  • hxxp://109[.]206[.]241[.]219/bins/phantom[.]arm4;
  • hxxp://109[.]206[.]241[.]219/bins/phantom[.]arm4;cat
  • hxxp://109[.]206[.]241[.]219/bins/phantom[.]arm5;
  • hxxp://109[.]206[.]241[.]219/bins/phantom[.]arm5;cat
  • hxxp://109[.]206[.]241[.]219/bins/phantom[.]arm6;
  • hxxp://109[.]206[.]241[.]219/bins/phantom[.]arm6;cat
  • hxxp://109[.]206[.]241[.]219/bins/phantom[.]arm7;
  • hxxp://109[.]206[.]241[.]219/bins/phantom[.]arm7;cat
  • hxxp://109[.]206[.]241[.]219/bins/phantom[.]m68k;
  • hxxp://109[.]206[.]241[.]219/bins/phantom[.]m68k;cat
  • hxxp://109[.]206[.]241[.]219/bins/phantom[.]mips;
  • hxxp://109[.]206[.]241[.]219/bins/phantom[.]mips;cat
  • hxxp://109[.]206[.]241[.]219/bins/phantom[.]mpsl;
  • hxxp://109[.]206[.]241[.]219/bins/phantom[.]mpsl;cat
  • hxxp://109[.]206[.]241[.]219/bins/phantom[.]ppc;
  • hxxp://109[.]206[.]241[.]219/bins/phantom[.]ppc;cat
  • hxxp://109[.]206[.]241[.]219/bins/phantom[.]sh4;
  • hxxp://109[.]206[.]241[.]219/bins/phantom[.]sh4;cat
  • hxxp://109[.]206[.]241[.]219/bins/phantom[.]x86;
  • hxxp://109[.]206[.]241[.]219/bins/phantom[.]x86;cat