Back to Malware Drops

a6dbe9d0b774eb4ae3eac56504b145bdd13273d009c33babf88ffffae2785a41

MD5ef98cd7dd72ed4bb841b114edd8843fd
SSDEEP
File Typetext/x-script
Size1.5 KB
Sources9
Downloads0
First SeenSep 18, 2022
Last SeenSep 18, 2022
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

ipv4 (1)

  • 45[.]140[.]188[.]40

url (12)

  • hxxp://45[.]140[.]188[.]40/armv4l;
  • hxxp://45[.]140[.]188[.]40/armv5l;
  • hxxp://45[.]140[.]188[.]40/armv6l;
  • hxxp://45[.]140[.]188[.]40/i586;
  • hxxp://45[.]140[.]188[.]40/i686;
  • hxxp://45[.]140[.]188[.]40/m68k;
  • hxxp://45[.]140[.]188[.]40/mips;
  • hxxp://45[.]140[.]188[.]40/mipsel;
  • hxxp://45[.]140[.]188[.]40/powerpc;
  • hxxp://45[.]140[.]188[.]40/sh4;
  • hxxp://45[.]140[.]188[.]40/sparc;
  • hxxp://45[.]140[.]188[.]40/x86;