Back to Malware Drops

98f2e180640d6d1cfffd8f286e4af3fa4fe971ece6d6499aa1da2b55c3af1d2f

MD51e15bcff29481c2b106fd6de221e9892
SSDEEP
File Typetext/x-script
Size1.5 KB
Sources25
Downloads0
First SeenSep 19, 2020
Last SeenSep 19, 2020
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

ipv4 (1)

  • 45[.]14[.]224[.]110

url (12)

  • hxxp://45[.]14[.]224[.]110/ARMV4L;
  • hxxp://45[.]14[.]224[.]110/ARMV5L;
  • hxxp://45[.]14[.]224[.]110/ARMV6L;
  • hxxp://45[.]14[.]224[.]110/I586;
  • hxxp://45[.]14[.]224[.]110/I686;
  • hxxp://45[.]14[.]224[.]110/M68K;
  • hxxp://45[.]14[.]224[.]110/MIPS;
  • hxxp://45[.]14[.]224[.]110/MIPSEL;
  • hxxp://45[.]14[.]224[.]110/POWERPC;
  • hxxp://45[.]14[.]224[.]110/SH4;
  • hxxp://45[.]14[.]224[.]110/SPARC;
  • hxxp://45[.]14[.]224[.]110/X86_64;