sh4

First submission 2024-10-13 12:56:02 Last sumbission 2024-10-13 14:16:02

File details

File type: ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
Mime type: application/x-executable
File size: 57.36 KB (58740 bytes)
MD5: 11b9ecf90ccb37290e1418e393c5e768
SHA1: 63b8e1391aa93612cdd44b3f385074ff09420a16
SHA256: 296437c2814f539980df6a6155b96b1b2e20059c233426181bdff75c4db409b5

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 33/77 VT report date: 2024-10-13 12:30:19
Malware Type 1 trojan
Threat Type 3 mirai ddos gafgyt

URLs, FQDN and IP indicators 2

URL Host (FQDN/IP) Date Added
hXXp://net.tiktoka.cc/sh4 VirusTotal Report net.tiktoka.cc VirusTotal Report 2024-10-13 14:16:04
hXXp://81.161.238.2/sh4 VirusTotal Report 81.161.238.2 VirusTotal Report 2024-10-13 12:56:02

Strings analysis - Possible IPs found 3

81.161.238.2
255.255.255.255
127.0.0.1

Strings analysis - Possible URLs found 2

http://schemas.xmlsoap.org/soap/encoding/
http://schemas.xmlsoap.org/soap/envelope/