VirusTotal - File - c8d7d90dc47cccdd43a5fc98b8708ede05fc8517cf2c73a9c7416c3f7f499c96 files.dog
VirusTotal

MediCat.USB.v21.12.7z
https://www.virustotal.com/gui/file/e72589d08acbf7938b731e9d35983775ea6e4628251d069c6a282d51d6547080 CommandLine|contains:
- '[System.Net.WebRequest]::create'
- 'curl '
- 'Invoke-RestMethod'
- 'Invoke-WebRequest'
- 'iwr '
- 'Net.WebClient'
- 'Resume-BitsTransfer'
- 'Start-BitsTransfer'
- 'wget '
- 'WinHttp.WinHttpRequest'the reason im looking is the following ports are open on 51.222.40.149 prometheus edward
30000 30439 30544 30564 30991 31314 31333 31383 31403 31550 31556 31871 32000 32072 32205 32217 32563 32567 32754