Back to Malware Drops

ff1eac3752eafb8b38223b585797e653c109a2aff6a1012a2153ceb68fdfd9cd

MD5d8f887d1abe0adc3a528b22cabe55e8e
SSDEEP
File Typetext/x-script
Size1.5 KB
Sources9
Downloads0
First SeenNov 8, 2020
Last SeenNov 8, 2020
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

ipv4 (1)

  • 37[.]46[.]150[.]177

url (12)

  • hxxp://37[.]46[.]150[.]177/armv4l;
  • hxxp://37[.]46[.]150[.]177/armv5l;
  • hxxp://37[.]46[.]150[.]177/armv6l;
  • hxxp://37[.]46[.]150[.]177/i586;
  • hxxp://37[.]46[.]150[.]177/i686;
  • hxxp://37[.]46[.]150[.]177/m68k;
  • hxxp://37[.]46[.]150[.]177/mips;
  • hxxp://37[.]46[.]150[.]177/mipsel;
  • hxxp://37[.]46[.]150[.]177/powerpc;
  • hxxp://37[.]46[.]150[.]177/sh4;
  • hxxp://37[.]46[.]150[.]177/sparc;
  • hxxp://37[.]46[.]150[.]177/x86;