Back to Malware Drops
ba96704c49166e038c8984f9d2804c3d54dd85f3c5eb246c91e92924945b4b9c
MD52303fe7a08ee57757955969055fb0f76
SSDEEP—
File Typetext/x-script
Size1.5 KB
Sources56
Downloads0
First SeenFeb 25, 2021
Last SeenFeb 25, 2021
Download sample (.zip, password: infected)
Live malware — handle only in an isolated analysis environment.
Originating Attacks
Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.
- Dropped in this session (no command captured).Feb 25, 2021, 2:58:15 AMView attack session
- Dropped in this session (no command captured).Feb 25, 2021, 2:58:15 AMView attack session
- Dropped in this session (no command captured).Feb 25, 2021, 2:58:15 AMView attack session
- Dropped in this session (no command captured).Feb 25, 2021, 2:58:15 AMView attack session
- Dropped in this session (no command captured).Feb 25, 2021, 2:58:15 AMView attack session
Indicators of Compromise
Values are defanged (e.g. hxxp://, [.]) — not live links.
ipv4 (1)
- 194[.]15[.]36[.]227
url (12)
- hxxp://194[.]15[.]36[.]227/armv4l;
- hxxp://194[.]15[.]36[.]227/armv5l;
- hxxp://194[.]15[.]36[.]227/armv6l;
- hxxp://194[.]15[.]36[.]227/i586;
- hxxp://194[.]15[.]36[.]227/i686;
- hxxp://194[.]15[.]36[.]227/m68k;
- hxxp://194[.]15[.]36[.]227/mips;
- hxxp://194[.]15[.]36[.]227/mipsel;
- hxxp://194[.]15[.]36[.]227/powerpc;
- hxxp://194[.]15[.]36[.]227/sh4;
- hxxp://194[.]15[.]36[.]227/sparc;
- hxxp://194[.]15[.]36[.]227/x86;