Back to Malware Drops

edb3175bca6d281e688080c2c033de4afd1c7753e72de693dd1135aeb8fc4bde

MD5ab340414495f0d982b64093222249592
SSDEEP
File Typeunknown
Size899 B
Sources10
Downloads0
First SeenJun 17, 2022
Last SeenJun 18, 2022
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

ipv4 (1)

  • 2[.]58[.]149[.]116

url (7)

  • hxxp://2[.]58[.]149[.]116/arm7
  • hxxp://2[.]58[.]149[.]116/mips
  • hxxp://2[.]58[.]149[.]116/mips64
  • hxxp://2[.]58[.]149[.]116/mipsel
  • hxxp://2[.]58[.]149[.]116/spc
  • hxxp://2[.]58[.]149[.]116/spc?ARCH=$(uname
  • hxxp://2[.]58[.]149[.]116/x86