.Smips

First submission 2024-10-17 16:10:03

File details

File type: ELF 32-bit MSB executable, MIPS, MIPS32 rel2 version 1 (SYSV), statically linked, BuildID[sha1]=c4b1698a317a9e60a215228abd402e61aa331eb4, for GNU/Linux 3.2.0, not stripped
Mime type: application/x-executable
File size: 730.19 KB (747712 bytes)
MD5: 6fca7592590fdf896ca4d371483ff4c3
SHA1: af264edd278bd793ad3f40c597eb1ff8f637fb6b
SHA256: f0549031d7ad521b609729b0c9458faa88edc78e191abf59a7578e94f13c3b5f

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 15/77 VT report date: 2024-10-17 14:38:37
Malware Type 1 trojan
Threat Type 2 mirai expl

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://87.120.112.50/.Smips VirusTotal Report 87.120.112.50 VirusTotal Report 2024-10-17 16:10:03

Strings analysis - Possible IPs found 2

87.120.112.50
239.255.255.250

Strings analysis - Possible URLs found 4

http://87.120.112.50/.Sarm7$
http://www.debian.org/Bugs/
http://schemas.xmlsoap.org/soap/encoding/
http://schemas.xmlsoap.org/soap/envelope/