bot.ppc

First submission 2024-09-02 15:37:01 Last sumbission 2024-09-03 11:21:01

File details

File type: ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, stripped
Mime type: application/x-executable
File size: 133.74 KB (136952 bytes)
MD5: 65d9edd84ce842664f1863d2ec6cd70a
SHA1: d14eb787806999f5c8c90a0d65dae48c73b1bd24
SHA256: 652a397ec3bcca44b14062c02bbed93c2c1a1d010231cca6ddc3b4e63d98cd20

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 28/79 VT report date: 2024-09-02 14:53:29
Malware Type 1 trojan
Threat Type 3 mirai froz gafgyt

URLs, FQDN and IP indicators 2

URL Host (FQDN/IP) Date Added
hXXp://185.196.9.222/bot.ppc VirusTotal Report 185.196.9.222 VirusTotal Report 2024-09-03 11:21:03
hXXp://captcha.webredirect.org/bot.ppc VirusTotal Report captcha.webredirect.org VirusTotal Report 2024-09-02 15:37:01

Strings analysis - Possible IPs found 2

255.255.255.255
127.0.0.1