bot.mipsle

First submission 2024-10-13 22:14:02 Last sumbission 2024-10-13 23:17:09

File details

File type: ELF 32-bit LSB executable, MIPS, MIPS32 version 1 (SYSV), statically linked, Go BuildID=cum__uZdpvlPNeU9fODl/CrHDcovmSNnWixeoRk5l/UAJ1IHxzeNa8eHAZWMNc/mQQlpPIKAQReivURz7s0, with debug_info, not stripped
Mime type: application/x-executable
File size: 8023.92 KB (8216498 bytes)
MD5: 23176b0103ad402ba24d667f41200fd9
SHA1: 1358b3303b046985b9f5619500b59e29181fb009
SHA256: e1ad3945be78ff830a8e740dde64df37ee114d7a21d5fc9bed1fc3ff1a964f1c

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

URLs, FQDN and IP indicators 2

URL Host (FQDN/IP) Date Added
hXXp://billing.rpnodes.host/bot.mipsle VirusTotal Report billing.rpnodes.host VirusTotal Report 2024-10-13 23:17:11
hXXp://100.42.189.107/bot.mipsle VirusTotal Report 100.42.189.107 VirusTotal Report 2024-10-13 22:14:02

Strings analysis - File found

Log
math.Log

Strings analysis - Possible IPs found 13

87.120.84.114
1.1.2.1
2.5.4.102
72.5.4.82
1.1.3.1
5.4.32.5
1.2.1.1
127.0.0.1
2.5.4.62
5.4.112.5
1.2.2.1
4.52.5.4
1.1.1.1

Strings analysis - Possible URLs found 2

http://api.ipify.orgjson:
http://OPTIONSCreatedIM