db0fa4b8db0333367e9bda3ab68b8042.spc

First submission 2024-10-17 13:12:02

File details

File type: ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, stripped
Mime type: application/x-executable
File size: 83.75 KB (85760 bytes)
MD5: 6d07b38655f1d3f7d5ede931c3dcbfd8
SHA1: 92e4e28336efa8b205a159ae902336f7bffb609e
SHA256: 495d59285906fe0c06807773d13148b4bbf2d059b577fdef3ed6dbfb846adcc7

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 42/77 VT report date: 2024-10-17 02:06:20
Malware Type 1 trojan
Threat Type 3 mirai gafgyt smmr1

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.spc VirusTotal Report 87.236.95.134 VirusTotal Report 2024-10-17 13:12:02

Strings analysis - Possible IPs found 2

172.236.29.44
127.0.0.1

Strings analysis - Possible URLs found 3

http://schemas.xmlsoap.org/soap/encoding/
http://172.236.29.44/bin+-O+/tmp/gaf;sh+/tmp/gaf
http://schemas.xmlsoap.org/soap/envelope/