Back to Malware Drops

e41bf64be83c14cbc2fd9f5238cb96bfa38c87790290edc007ac28f5a9679eaf

MD59ef85b8bb06b0325b38fe62a388ebd82
SSDEEP
File Typetext/x-script
Size1.5 KB
Sources153
Downloads0
First SeenNov 27, 2020
Last SeenNov 28, 2020
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

ipv4 (1)

  • 45[.]14[.]224[.]42

url (12)

  • hxxp://45[.]14[.]224[.]42/armv4l;
  • hxxp://45[.]14[.]224[.]42/armv5l;
  • hxxp://45[.]14[.]224[.]42/armv6l;
  • hxxp://45[.]14[.]224[.]42/i586;
  • hxxp://45[.]14[.]224[.]42/i686;
  • hxxp://45[.]14[.]224[.]42/m68k;
  • hxxp://45[.]14[.]224[.]42/mips;
  • hxxp://45[.]14[.]224[.]42/mipsel;
  • hxxp://45[.]14[.]224[.]42/powerpc;
  • hxxp://45[.]14[.]224[.]42/sh4;
  • hxxp://45[.]14[.]224[.]42/sparc;
  • hxxp://45[.]14[.]224[.]42/x86;