Back to Malware Drops

a0f1701dd59a4eb0cffa24e742ab77089ed60804fdf7ac2f07ef3f342752dee2

MD5af6dace6c3b91554ca32f40ece3a1fb6
SSDEEP
File Typetext/x-script
Size1.1 KB
Sources5
Downloads0
First SeenSep 1, 2022
Last SeenSep 5, 2022
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

ipv4 (1)

  • 208[.]67[.]104[.]31

url (22)

  • hxxp://208[.]67[.]104[.]31/bins/arm4;
  • hxxp://208[.]67[.]104[.]31/bins/arm4;chmod
  • hxxp://208[.]67[.]104[.]31/bins/arm5;
  • hxxp://208[.]67[.]104[.]31/bins/arm5;chmod
  • hxxp://208[.]67[.]104[.]31/bins/arm6;
  • hxxp://208[.]67[.]104[.]31/bins/arm6;chmod
  • hxxp://208[.]67[.]104[.]31/bins/arm7;
  • hxxp://208[.]67[.]104[.]31/bins/arm7;chmod
  • hxxp://208[.]67[.]104[.]31/bins/i686;
  • hxxp://208[.]67[.]104[.]31/bins/i686;chmod
  • hxxp://208[.]67[.]104[.]31/bins/m68k;
  • hxxp://208[.]67[.]104[.]31/bins/m68k;chmod
  • hxxp://208[.]67[.]104[.]31/bins/mips;
  • hxxp://208[.]67[.]104[.]31/bins/mips;chmod
  • hxxp://208[.]67[.]104[.]31/bins/mipsel;
  • hxxp://208[.]67[.]104[.]31/bins/mipsel;chmod
  • hxxp://208[.]67[.]104[.]31/bins/sh4;
  • hxxp://208[.]67[.]104[.]31/bins/sh4;chmod
  • hxxp://208[.]67[.]104[.]31/bins/x86;
  • hxxp://208[.]67[.]104[.]31/bins/x86_64;
  • hxxp://208[.]67[.]104[.]31/bins/x86_64;chmod
  • hxxp://208[.]67[.]104[.]31/bins/x86;chmod