Back to Malware Drops

d0d63e97941de785b6d124fa8b4a51aefa3e5d38fdc8aee570f467c0d17fba1c

MD52eaae50856df808a4cc4c3f5afa4685f
SSDEEP
File Typetext/x-script
Size1.5 KB
Sources10
Downloads0
First SeenAug 11, 2022
Last SeenAug 11, 2022
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

ipv4 (1)

  • 208[.]67[.]104[.]94

url (13)

  • hxxp://208[.]67[.]104[.]94/adc;
  • hxxp://208[.]67[.]104[.]94/arm6;
  • hxxp://208[.]67[.]104[.]94/cco;
  • hxxp://208[.]67[.]104[.]94/dss;
  • hxxp://208[.]67[.]104[.]94/i586;
  • hxxp://208[.]67[.]104[.]94/i686;
  • hxxp://208[.]67[.]104[.]94/m68k;
  • hxxp://208[.]67[.]104[.]94/mips;
  • hxxp://208[.]67[.]104[.]94/mpsl;
  • hxxp://208[.]67[.]104[.]94/ppc;
  • hxxp://208[.]67[.]104[.]94/scar;
  • hxxp://208[.]67[.]104[.]94/sh4;
  • hxxp://208[.]67[.]104[.]94/x86;