Back to Malware Drops
f438321d2ba71b9577fe5fa9cd444ce8375ccfcc52ee5886f9ced7c045a53fc4
MD5d4aa208d4ffbf6f23bac0982d4f705ce
SSDEEP—
File Typetext/x-script
Size1.6 KB
Sources46
Downloads0
First SeenApr 23, 2021
Last SeenApr 23, 2021
Download sample (.zip, password: infected)
Live malware — handle only in an isolated analysis environment.
Originating Attacks
Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.
- Dropped in this session (no command captured).Apr 23, 2021, 4:08:55 AMView attack session
- Dropped in this session (no command captured).Apr 23, 2021, 4:08:55 AMView attack session
- Dropped in this session (no command captured).Apr 23, 2021, 4:08:55 AMView attack session
- Dropped in this session (no command captured).Apr 23, 2021, 4:08:55 AMView attack session
- Dropped in this session (no command captured).Apr 23, 2021, 4:08:55 AMView attack session
Indicators of Compromise
Values are defanged (e.g. hxxp://, [.]) — not live links.
ipv4 (1)
- 109[.]104[.]151[.]10
url (9)
- hxxp://109[.]104[.]151[.]10/mtro/mbot[.]arm4;
- hxxp://109[.]104[.]151[.]10/mtro/mbot[.]arm5;
- hxxp://109[.]104[.]151[.]10/mtro/mbot[.]arm6;
- hxxp://109[.]104[.]151[.]10/mtro/mbot[.]arm7;
- hxxp://109[.]104[.]151[.]10/mtro/mbot[.]mips;
- hxxp://109[.]104[.]151[.]10/mtro/mbot[.]mpsl;
- hxxp://109[.]104[.]151[.]10/mtro/mbot[.]ppc;
- hxxp://109[.]104[.]151[.]10/mtro/mbot[.]sparc;
- hxxp://109[.]104[.]151[.]10/mtro/mbot[.]x86;