Back to Malware Drops

ac8ea0234436d78b950f53a97d99836fa000fc126fbf7815cf92d8a8d137099d

MD564004c00ee8b57caa36f8cbd733ff306
SSDEEP
File Typetext/x-script
Size2.2 KB
Sources8
Downloads0
First SeenJan 12, 2021
Last SeenJan 12, 2021
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

ipv4 (1)

  • 208[.]123[.]209[.]58

url (24)

  • hxxp://208[.]123[.]209[.]58/SBIDIOT/arm;
  • hxxp://208[.]123[.]209[.]58/SBIDIOT/arm6;
  • hxxp://208[.]123[.]209[.]58/SBIDIOT/arm6;cat
  • hxxp://208[.]123[.]209[.]58/SBIDIOT/arm7;
  • hxxp://208[.]123[.]209[.]58/SBIDIOT/arm7;cat
  • hxxp://208[.]123[.]209[.]58/SBIDIOT/arm;cat
  • hxxp://208[.]123[.]209[.]58/SBIDIOT/m68k;
  • hxxp://208[.]123[.]209[.]58/SBIDIOT/m68k;cat
  • hxxp://208[.]123[.]209[.]58/SBIDIOT/mips;
  • hxxp://208[.]123[.]209[.]58/SBIDIOT/mips;cat
  • hxxp://208[.]123[.]209[.]58/SBIDIOT/mpsl;
  • hxxp://208[.]123[.]209[.]58/SBIDIOT/mpsl;cat
  • hxxp://208[.]123[.]209[.]58/SBIDIOT/ppc;
  • hxxp://208[.]123[.]209[.]58/SBIDIOT/ppc;cat
  • hxxp://208[.]123[.]209[.]58/SBIDIOT/root;
  • hxxp://208[.]123[.]209[.]58/SBIDIOT/root;cat
  • hxxp://208[.]123[.]209[.]58/SBIDIOT/rtk;
  • hxxp://208[.]123[.]209[.]58/SBIDIOT/rtk;cat
  • hxxp://208[.]123[.]209[.]58/SBIDIOT/sh4;
  • hxxp://208[.]123[.]209[.]58/SBIDIOT/sh4;cat
  • hxxp://208[.]123[.]209[.]58/SBIDIOT/x86;
  • hxxp://208[.]123[.]209[.]58/SBIDIOT/x86;cat
  • hxxp://208[.]123[.]209[.]58/SBIDIOT/zte;
  • hxxp://208[.]123[.]209[.]58/SBIDIOT/zte;cat