armv5l

First submission 2024-10-17 14:16:02 Last sumbission 2024-10-17 15:37:02

File details

File type: ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
Mime type: application/x-executable
File size: 73.0 KB (74756 bytes)
MD5: 21b4e9ce612f4975bb4ae4ec632090a8
SHA1: 61a85dd5a0493eef260eb86a091de3af6057a21e
SHA256: ac8a28d93c081d36f02846703599d0e9f14e361c9b10964e92f3400ee805b449

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 4/77 VT report date: 2024-10-10 05:09:00
Threat Type 1 mirai

URLs, FQDN and IP indicators 2

URL Host (FQDN/IP) Date Added
hXXp://185.121.233.82/ss/armv5l VirusTotal Report 185.121.233.82 VirusTotal Report 2024-10-17 15:37:04
hXXp://185.121.233.82/tt/armv5l VirusTotal Report 185.121.233.82 VirusTotal Report 2024-10-17 14:16:02

Strings analysis - File found

Data
!5/////./..//////./..//////./../flash/rw/store/user.dat

Strings analysis - Possible IPs found 1

127.0.0.1