bin.sh4

First submission 2024-10-17 15:52:01

File details

File type: ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
Mime type: application/x-executable
File size: 145.8 KB (149304 bytes)
MD5: 22944a5046f45415474258bbad1f1161
SHA1: 2140cd4a4eb86d51e9ea2bdd48017ab524d35cd3
SHA256: ea588df486d32e2badfc40be6d84f4fbe0e88f44fd54070d36d84fecc820d5d9

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 14/77 VT report date: 2024-10-17 14:36:37
Malware Type 1 trojan
Threat Type 2 mirai ddosagent

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://178.215.238.13/bin.sh4 VirusTotal Report 178.215.238.13 VirusTotal Report 2024-10-17 15:52:01

Strings analysis - Possible IPs found 1

85.239.34.134