bot.sh4

First submission 2024-10-17 14:55:02

File details

File type: ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
Mime type: application/x-executable
File size: 114.81 KB (117568 bytes)
MD5: 2d71bb5d47d7c0ad3ee8471bcad6fc0d
SHA1: 4d2e0729c6bf568e8b0c73e35194b989c942ccbc
SHA256: eca8cf0c6e0cadbbadd8ea384198477a9cbbacfd0ad62e075218d02c13699dc9

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 36/77 VT report date: 2024-10-17 14:37:03
Malware Type 1 trojan
Threat Type 3 mirai gafgyt genericrxua

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://91.218.67.59/bot.sh4 VirusTotal Report 91.218.67.59 VirusTotal Report 2024-10-17 14:55:02

Strings analysis - Possible IPs found 2

255.255.255.255
127.0.0.1