Back to Malware Drops

fb771b83734e19786a6ae0df67bfc0bf5d6c8b61e28023d586b16d451f7fe38b

MD55b31b9b8e5619f16a6ae813494f58717
SSDEEP
File Typeunknown
Size1.6 KB
Sources92
Downloads0
First SeenMar 18, 2022
Last SeenJun 4, 2022
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

ipv4 (1)

  • 61[.]177[.]137[.]133

url (11)

  • hxxp://61[.]177[.]137[.]133/x/irq0
  • hxxp://61[.]177[.]137[.]133/x/irq1
  • hxxp://61[.]177[.]137[.]133/x/irq2
  • hxxp://61[.]177[.]137[.]133/x/pty
  • hxxp://61[.]177[.]137[.]133/x/tty0
  • hxxp://61[.]177[.]137[.]133/x/tty1
  • hxxp://61[.]177[.]137[.]133/x/tty2
  • hxxp://61[.]177[.]137[.]133/x/tty3
  • hxxp://61[.]177[.]137[.]133/x/tty4
  • hxxp://61[.]177[.]137[.]133/x/tty5
  • hxxp://61[.]177[.]137[.]133/x/tty6