ohshit.sh

First submission 2023-09-17 23:15:02

File details

File type: Bourne-Again shell script, ASCII text executable
Mime type: text/x-shellscript
File size: 2.9 KB (2970 bytes)
MD5: 16aa2ee73b8d09491f07d99240e7b208
SHA1: e3637de58803316422f8e95c844a5b28ed8e3c45
SHA256: 47bad7f3cb2eeca6d95e12e1e9196e3aa5c3e7f5ef89fad65553dbda581d00a6
Virus Total: 37/59 VT report date: 2023-09-17 20:10:01

File features detected

Is DLL

Packers

Anti Debug

Anti VM

Signed

XOR

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://141.11.159.192/ohshit.sh VirusTotal Report 141.11.159.192 VirusTotal Report 2023-09-17 23:15:02

Strings analysis - Possible IPs found 1

141.11.159.192

Strings analysis - Possible URLs found 30

http://141.11.159.192/hiddenbin/boatnet.arc;
http://141.11.159.192/hiddenbin/boatnet.x86_64;
http://141.11.159.192/hiddenbin/boatnet.arm6;cat
http://141.11.159.192/hiddenbin/boatnet.i468;
http://141.11.159.192/hiddenbin/boatnet.sh4;
http://141.11.159.192/hiddenbin/boatnet.i686;cat
http://141.11.159.192/hiddenbin/boatnet.arm5;cat
http://141.11.159.192/hiddenbin/boatnet.mips;
http://141.11.159.192/hiddenbin/boatnet.sh4;cat
http://141.11.159.192/hiddenbin/boatnet.ppc;
http://141.11.159.192/hiddenbin/boatnet.spc;
http://141.11.159.192/hiddenbin/boatnet.arm;cat
http://141.11.159.192/hiddenbin/boatnet.spc;cat
http://141.11.159.192/hiddenbin/boatnet.arm7;cat
http://141.11.159.192/hiddenbin/boatnet.arm6;
http://141.11.159.192/hiddenbin/boatnet.mpsl;
http://141.11.159.192/hiddenbin/boatnet.i686;
http://141.11.159.192/hiddenbin/boatnet.i468;cat
http://141.11.159.192/hiddenbin/boatnet.x86_64;cat
http://141.11.159.192/hiddenbin/boatnet.mpsl;cat
http://141.11.159.192/hiddenbin/boatnet.x86;
http://141.11.159.192/hiddenbin/boatnet.mips;cat
http://141.11.159.192/hiddenbin/boatnet.ppc;cat
http://141.11.159.192/hiddenbin/boatnet.x86;cat
http://141.11.159.192/hiddenbin/boatnet.arc;cat
http://141.11.159.192/hiddenbin/boatnet.m68k;cat
http://141.11.159.192/hiddenbin/boatnet.m68k;
http://141.11.159.192/hiddenbin/boatnet.arm;
http://141.11.159.192/hiddenbin/boatnet.arm5;
http://141.11.159.192/hiddenbin/boatnet.arm7;