Back to Malware Drops
e0dc397e99de155390f660b18a11510bbb8224ad59216ec71fa0e83288441e15
MD5885c760e1c3804d7c8eff7f78ec7021a
SSDEEP—
File Typetext/x-script
Size1.4 KB
Sources2
Downloads0
First SeenDec 27, 2019
Last SeenDec 27, 2019
Download sample (.zip, password: infected)
Live malware — handle only in an isolated analysis environment.
Originating Attacks
Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.
- Dropped in this session (no command captured).Dec 27, 2019, 8:21:57 AMView attack session
- Dropped in this session (no command captured).Dec 27, 2019, 8:21:57 AMView attack session
Indicators of Compromise
Values are defanged (e.g. hxxp://, [.]) — not live links.
ipv4 (1)
- 195[.]231[.]2[.]225
url (12)
- hxxp://195[.]231[.]2[.]225/arm4;
- hxxp://195[.]231[.]2[.]225/arm5;
- hxxp://195[.]231[.]2[.]225/arm6;
- hxxp://195[.]231[.]2[.]225/arm7;
- hxxp://195[.]231[.]2[.]225/i586;
- hxxp://195[.]231[.]2[.]225/i686;
- hxxp://195[.]231[.]2[.]225/m68k;
- hxxp://195[.]231[.]2[.]225/mips;
- hxxp://195[.]231[.]2[.]225/mipsel;
- hxxp://195[.]231[.]2[.]225/sh4;
- hxxp://195[.]231[.]2[.]225/sparc;
- hxxp://195[.]231[.]2[.]225/x86;