sh4

First submission 2024-10-17 15:38:03

File details

File type: ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, not stripped
Mime type: application/x-executable
File size: 123.68 KB (126647 bytes)
MD5: 00cdaa734bacda6c01b975e6d30e8597
SHA1: 6d1db7ceb17b7dba68c16bf686f951cd7f8ac573
SHA256: bc221763caaabd9e8e3d1e185de732ab130a4f192692180c70be3c9b5dcd6b19

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 40/77 VT report date: 2024-10-17 14:35:00
Malware Type 1 trojan
Threat Type 3 gafgyt mirai bashlite

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://205.185.122.67/sh4 VirusTotal Report 205.185.122.67 VirusTotal Report 2024-10-17 15:38:03

Strings analysis - Possible IPs found 7

1.9.2.6
1.9.2.4
1.8.1.11
1.9.0.8
1.9.0.6
8.8.8.8
205.185.122.67