Back to Malware Drops

f617024af549f05dd57659483ef96ae0d40f45736c6b66365651d5101e207f26

MD5677c3ac964fc6a2be2021aa3e13ce7f0
SSDEEP
File Typetext/x-script
Size1.5 KB
Sources16
Downloads0
First SeenMar 22, 2020
Last SeenMar 22, 2020
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

ipv4 (1)

  • 93[.]114[.]82[.]176

url (12)

  • hxxp://93[.]114[.]82[.]176/armv4l;
  • hxxp://93[.]114[.]82[.]176/armv5l;
  • hxxp://93[.]114[.]82[.]176/armv6l;
  • hxxp://93[.]114[.]82[.]176/i586;
  • hxxp://93[.]114[.]82[.]176/i686;
  • hxxp://93[.]114[.]82[.]176/m68k;
  • hxxp://93[.]114[.]82[.]176/mips;
  • hxxp://93[.]114[.]82[.]176/mipsel;
  • hxxp://93[.]114[.]82[.]176/powerpc;
  • hxxp://93[.]114[.]82[.]176/sh4;
  • hxxp://93[.]114[.]82[.]176/sparc;
  • hxxp://93[.]114[.]82[.]176/x86;