Back to Malware Drops
98f2e180640d6d1cfffd8f286e4af3fa4fe971ece6d6499aa1da2b55c3af1d2f
MD51e15bcff29481c2b106fd6de221e9892
SSDEEP—
File Typetext/x-script
Size1.5 KB
Sources25
Downloads0
First SeenSep 19, 2020
Last SeenSep 19, 2020
Download sample (.zip, password: infected)
Live malware — handle only in an isolated analysis environment.
Originating Attacks
Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.
- Dropped in this session (no command captured).Sep 19, 2020, 9:32:48 PMView attack session
- Dropped in this session (no command captured).Sep 19, 2020, 9:32:48 PMView attack session
- Dropped in this session (no command captured).Sep 19, 2020, 9:32:48 PMView attack session
- Dropped in this session (no command captured).Sep 19, 2020, 9:32:48 PMView attack session
- Dropped in this session (no command captured).Sep 19, 2020, 9:32:48 PMView attack session
Indicators of Compromise
Values are defanged (e.g. hxxp://, [.]) — not live links.
ipv4 (1)
- 45[.]14[.]224[.]110
url (12)
- hxxp://45[.]14[.]224[.]110/ARMV4L;
- hxxp://45[.]14[.]224[.]110/ARMV5L;
- hxxp://45[.]14[.]224[.]110/ARMV6L;
- hxxp://45[.]14[.]224[.]110/I586;
- hxxp://45[.]14[.]224[.]110/I686;
- hxxp://45[.]14[.]224[.]110/M68K;
- hxxp://45[.]14[.]224[.]110/MIPS;
- hxxp://45[.]14[.]224[.]110/MIPSEL;
- hxxp://45[.]14[.]224[.]110/POWERPC;
- hxxp://45[.]14[.]224[.]110/SH4;
- hxxp://45[.]14[.]224[.]110/SPARC;
- hxxp://45[.]14[.]224[.]110/X86_64;