arm5.nn

First submission 2024-10-14 10:57:02

File details

File type: ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
Mime type: application/x-executable
File size: 103.32 KB (105796 bytes)
MD5: 101cb1b17680e1ef45600a016588f5d7
SHA1: 8ae93f5881878f8b3c5250031a8a3e0767178969
SHA256: 54008fcba859f5b1e331aba15e8e1ac418a4b91b4e8f4506718684479d1572d5

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 23/77 VT report date: 2024-10-14 05:20:48
Malware Type 1 trojan
Threat Type 2 mirai gafgyt

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://87.120.84.247/arm5.nn VirusTotal Report 87.120.84.247 VirusTotal Report 2024-10-14 10:57:02

Strings analysis - Possible IPs found 3

127.0.0.1
255.255.255.255
87.120.84.247

Strings analysis - Possible URLs found 3

http://87.120.84.247/curl.sh
http://87.120.84.247/lol.sh
http://87.120.84.247/