Back to Malware Drops

e0dc397e99de155390f660b18a11510bbb8224ad59216ec71fa0e83288441e15

MD5885c760e1c3804d7c8eff7f78ec7021a
SSDEEP
File Typetext/x-script
Size1.4 KB
Sources2
Downloads0
First SeenDec 27, 2019
Last SeenDec 27, 2019
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

ipv4 (1)

  • 195[.]231[.]2[.]225

url (12)

  • hxxp://195[.]231[.]2[.]225/arm4;
  • hxxp://195[.]231[.]2[.]225/arm5;
  • hxxp://195[.]231[.]2[.]225/arm6;
  • hxxp://195[.]231[.]2[.]225/arm7;
  • hxxp://195[.]231[.]2[.]225/i586;
  • hxxp://195[.]231[.]2[.]225/i686;
  • hxxp://195[.]231[.]2[.]225/m68k;
  • hxxp://195[.]231[.]2[.]225/mips;
  • hxxp://195[.]231[.]2[.]225/mipsel;
  • hxxp://195[.]231[.]2[.]225/sh4;
  • hxxp://195[.]231[.]2[.]225/sparc;
  • hxxp://195[.]231[.]2[.]225/x86;