TzkG1LAnuXzmuv3PZAC89HML7kOiU9YBsj

First submission 2024-10-12 17:12:01 Last sumbission 2024-10-17 03:31:02

File details

File type: ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, not stripped
Mime type: application/x-executable
File size: 84.62 KB (86656 bytes)
MD5: 64ece99ca4ab1c1405f5a3335d64a960
SHA1: b7395f2320a5bdadb78943b268708965cdbd1d74
SHA256: aaf14287d7a971d4541527262e85e5930bbb7f506cff4808d712843be9f05dae

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 40/77 VT report date: 2024-08-27 19:31:41
Malware Type 1 trojan
Threat Type 3 mirai gafgyt hctap

URLs, FQDN and IP indicators 3

URL Host (FQDN/IP) Date Added
hXXp://conn.masjesu.zip/bins/TzkG1LAnuXzmuv3PZAC89HML7kOiU9YBsj VirusTotal Report conn.masjesu.zip VirusTotal Report 2024-10-17 03:31:06
hXXp://87.120.126.196/bins/qJgPyUEoRB5JEOeVTrA5UMHWySH2Ba31lX VirusTotal Report 87.120.126.196 VirusTotal Report 2024-10-15 15:20:05
hXXp://87.120.84.230/bins/onWIq4fiCyw4h9cjvhWWwxbX6yXae1qY3J VirusTotal Report 87.120.84.230 VirusTotal Report 2024-10-12 17:12:01

Strings analysis - Possible IPs found 1

8.8.8.8