Back to Malware Drops

f438321d2ba71b9577fe5fa9cd444ce8375ccfcc52ee5886f9ced7c045a53fc4

MD5d4aa208d4ffbf6f23bac0982d4f705ce
SSDEEP
File Typetext/x-script
Size1.6 KB
Sources46
Downloads0
First SeenApr 23, 2021
Last SeenApr 23, 2021
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

ipv4 (1)

  • 109[.]104[.]151[.]10

url (9)

  • hxxp://109[.]104[.]151[.]10/mtro/mbot[.]arm4;
  • hxxp://109[.]104[.]151[.]10/mtro/mbot[.]arm5;
  • hxxp://109[.]104[.]151[.]10/mtro/mbot[.]arm6;
  • hxxp://109[.]104[.]151[.]10/mtro/mbot[.]arm7;
  • hxxp://109[.]104[.]151[.]10/mtro/mbot[.]mips;
  • hxxp://109[.]104[.]151[.]10/mtro/mbot[.]mpsl;
  • hxxp://109[.]104[.]151[.]10/mtro/mbot[.]ppc;
  • hxxp://109[.]104[.]151[.]10/mtro/mbot[.]sparc;
  • hxxp://109[.]104[.]151[.]10/mtro/mbot[.]x86;