Back to Malware Drops

bec7189998e06e6dcd2f0b7b040bdfa264bcd9832fca33cf166b42b92a01efa3

MD5a5c77902270f86b662e5177894da3dd9
SSDEEP
File Typetext/x-script
Size1.5 KB
Sources30
Downloads0
First SeenMay 3, 2021
Last SeenMay 3, 2021
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

ipv4 (1)

  • 134[.]122[.]67[.]26

url (12)

  • hxxp://134[.]122[.]67[.]26/armv4l;
  • hxxp://134[.]122[.]67[.]26/armv5l;
  • hxxp://134[.]122[.]67[.]26/armv6l;
  • hxxp://134[.]122[.]67[.]26/i586;
  • hxxp://134[.]122[.]67[.]26/i686;
  • hxxp://134[.]122[.]67[.]26/m68k;
  • hxxp://134[.]122[.]67[.]26/mips;
  • hxxp://134[.]122[.]67[.]26/mipsel;
  • hxxp://134[.]122[.]67[.]26/powerpc;
  • hxxp://134[.]122[.]67[.]26/sh4;
  • hxxp://134[.]122[.]67[.]26/sparc;
  • hxxp://134[.]122[.]67[.]26/x86;