Back to Malware Drops

f3ceec7636faa46a90bbf5d58e890c51494272891a4e5b7a5375167591c53414

MD561cf56777ba6be0fb738f8ae7e105a1c
SSDEEP
File Typetext/x-script
Size1.5 KB
Sources60
Downloads0
First SeenDec 9, 2020
Last SeenDec 29, 2020
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

ipv4 (1)

  • 104[.]168[.]245[.]85

url (12)

  • hxxp://104[.]168[.]245[.]85/armv4l;
  • hxxp://104[.]168[.]245[.]85/armv5l;
  • hxxp://104[.]168[.]245[.]85/armv6l;
  • hxxp://104[.]168[.]245[.]85/i586;
  • hxxp://104[.]168[.]245[.]85/i686;
  • hxxp://104[.]168[.]245[.]85/m68k;
  • hxxp://104[.]168[.]245[.]85/mips;
  • hxxp://104[.]168[.]245[.]85/mipsel;
  • hxxp://104[.]168[.]245[.]85/powerpc;
  • hxxp://104[.]168[.]245[.]85/sh4;
  • hxxp://104[.]168[.]245[.]85/sparc;
  • hxxp://104[.]168[.]245[.]85/x86;