Back to Malware Drops

a669190e08218a41daaf26481feb5b320325b3c190afed5ca0078ccc49f6d2a3

MD5ca96afba1267bcac642a4514f12751c3
SSDEEP
File Typetext/x-script
Size1.5 KB
Sources51
Downloads0
First SeenNov 23, 2020
Last SeenNov 23, 2020
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

ipv4 (1)

  • 45[.]14[.]224[.]77

url (12)

  • hxxp://45[.]14[.]224[.]77/ARMV4L;
  • hxxp://45[.]14[.]224[.]77/ARMV5L;
  • hxxp://45[.]14[.]224[.]77/ARMV6L;
  • hxxp://45[.]14[.]224[.]77/I586;
  • hxxp://45[.]14[.]224[.]77/I686;
  • hxxp://45[.]14[.]224[.]77/M68K;
  • hxxp://45[.]14[.]224[.]77/MIPS;
  • hxxp://45[.]14[.]224[.]77/MIPSEL;
  • hxxp://45[.]14[.]224[.]77/POWERPC;
  • hxxp://45[.]14[.]224[.]77/SH4;
  • hxxp://45[.]14[.]224[.]77/SPARC;
  • hxxp://45[.]14[.]224[.]77/X86_64;