ohshit.sh
First submission 2024-10-12 08:50:02
File details
File type: | Bourne-Again shell script, ASCII text executable |
Mime type: | text/x-shellscript |
File size: | 2.9 KB (2970 bytes) |
MD5: | 4b8885cf53734502d543862cb1a89f00 |
SHA1: | 6a16f879228ca04c48854bd370b3f1d8142c8dad |
SHA256: | 7dafaee4c6dc91a023a6882f75d3b4c4404261d21e769043d9d19db88172b91a |
File features detected
Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR
OSINT Enrichments
Virus Total: | 37/77 VT report date: 2024-10-12 08:26:53 |
Malware Type 2 | downloader trojan |
Threat Type 3 | medusa shell bash |
URLs, FQDN and IP indicators 1
Strings analysis - Possible IPs found 1
93.123.109.160 |
Strings analysis - Possible URLs found 30
http://93.123.109.160/hiddenbin/boatnet.x86;cat |
http://93.123.109.160/hiddenbin/boatnet.sh4; |
http://93.123.109.160/hiddenbin/boatnet.arm; |
http://93.123.109.160/hiddenbin/boatnet.spc;cat |
http://93.123.109.160/hiddenbin/boatnet.sh4;cat |
http://93.123.109.160/hiddenbin/boatnet.ppc;cat |
http://93.123.109.160/hiddenbin/boatnet.arm7;cat |
http://93.123.109.160/hiddenbin/boatnet.mpsl;cat |
http://93.123.109.160/hiddenbin/boatnet.i686;cat |
http://93.123.109.160/hiddenbin/boatnet.arc; |
http://93.123.109.160/hiddenbin/boatnet.mips; |
http://93.123.109.160/hiddenbin/boatnet.ppc; |
http://93.123.109.160/hiddenbin/boatnet.arm6; |
http://93.123.109.160/hiddenbin/boatnet.i468;cat |
http://93.123.109.160/hiddenbin/boatnet.m68k; |
http://93.123.109.160/hiddenbin/boatnet.mips;cat |
http://93.123.109.160/hiddenbin/boatnet.arc;cat |
http://93.123.109.160/hiddenbin/boatnet.mpsl; |
http://93.123.109.160/hiddenbin/boatnet.arm6;cat |
http://93.123.109.160/hiddenbin/boatnet.m68k;cat |
http://93.123.109.160/hiddenbin/boatnet.x86; |
http://93.123.109.160/hiddenbin/boatnet.arm5; |
http://93.123.109.160/hiddenbin/boatnet.arm5;cat |
http://93.123.109.160/hiddenbin/boatnet.arm7; |
http://93.123.109.160/hiddenbin/boatnet.x86_64;cat |
http://93.123.109.160/hiddenbin/boatnet.x86_64; |
http://93.123.109.160/hiddenbin/boatnet.i686; |
http://93.123.109.160/hiddenbin/boatnet.i468; |
http://93.123.109.160/hiddenbin/boatnet.spc; |
http://93.123.109.160/hiddenbin/boatnet.arm;cat |