Back to Malware Drops

ba01104165da2c3ac7bee2fc2efa65de834d45f99b9d934ed521d38a7d90cf34

MD521257fdc8cb71aae61eeaa01f29fe004
SSDEEP192:aNE6TPkhznR6fEp0QHCdd60QHCeAKGdH7Md4SrdH7Md4S8z2kiJFq:aDcn4cULOc8C6
File Typetext/x-script
Size8.7 KB
Sources118
Downloads0
First SeenJan 15, 2020
Last SeenJan 15, 2020
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

ipv4 (4)

  • 104[.]244[.]74[.]248
  • 104[.]244[.]75[.]25
  • 107[.]189[.]11[.]170
  • 23[.]94[.]24[.]12

url (8)

  • hxxp://104[.]244[.]74[.]248/go
  • hxxp://104[.]244[.]75[.]25/i686
  • hxxp://107[.]189[.]11[.]170/11
  • hxxp://107[.]189[.]11[.]170/2start[.]jpg
  • hxxp://107[.]189[.]11[.]170/2start[.]jpg||wget
  • hxxp://107[.]189[.]11[.]170/hxx
  • hxxp://107[.]189[.]11[.]170/p
  • hxxp://107[.]189[.]11[.]170/x86_64