sora.sh4

First submission 2024-08-30 09:11:02

File details

File type: ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
Mime type: application/x-executable
File size: 62.0 KB (63484 bytes)
MD5: 6ea1297900f0f707d6961c2857a5b26b
SHA1: 33d72a4c6be31d40054a9014e9dbefacf0934977
SHA256: 8cf6d1fe9752c3469b8ebf0232659bb90fb8e15faa353992ae5c2c2af8cb294e

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 42/78 VT report date: 2024-08-30 06:19:14
Malware Type 1 trojan
Threat Type 3 mirai gafgyt bootnet

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://5.59.248.234/bins/sora.sh4 VirusTotal Report 5.59.248.234 VirusTotal Report 2024-08-30 09:11:02

Strings analysis - Possible IPs found 1

5.59.248.234