i

First submission 2023-03-05 08:26:04 Last sumbission 2024-10-14 00:47:13

File details

File type: ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, no section header
File size: 300.74 KB (307960 bytes)
MD5: 7b61d204b1a02968237b9e817e79aead
SHA1: 403f0e100a9bc9cf520c045008cf03ca552cceef
SHA256: 3ba495d4fe7fbed339ae6852cddd60c878f6545bfec31254d536526a64b9bf56

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

URLs, FQDN and IP indicators 4

URL Host (FQDN/IP) Date Added
hXXp://59.88.226.83:36401/i VirusTotal Report 59.88.226.83 VirusTotal Report 2024-10-14 00:47:15
hXXp://59.88.226.83:36401/bin.sh VirusTotal Report 59.88.226.83 VirusTotal Report 2024-10-14 00:27:08
hXXp://117.253.108.235:36401/i VirusTotal Report 117.253.108.235 VirusTotal Report 2024-10-13 04:07:06
hXXp://117.253.108.235:36401/bin.sh VirusTotal Report 117.253.108.235 VirusTotal Report 2024-10-13 03:45:07

Strings analysis - File found

XML
M7c.xml

Strings analysis - Possible IPs found 5

192.168.0.100
192.168.1.1
239.255.255.250
192.168.3.1
127.0.0.1

Strings analysis - Possible URLs found 17

http://schemas.xmlsoap.org/soap/envelope/
http://purenetworks.com/HNAP1/
http://%s:%d/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1
http://%s:%d/Mozi.m+-O+-
http://%s:%d
http://schemas.xmlsoap.org/soap/encoding/
http://www.w3.org/2001/XMLSchema-instance
http://www.w3.org/2001/XMLSchema
http://upx.sf.net
http://%s:%d/Mozi.m;
http://schemas.xmlsoap.org/soap/envelope//
http://%s:%d/Mozi.m;/tmp/Mozi.m
http://%s:%d/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+varcron
http://%s:%d/Mozi.m
http://%s:%d/Mozi.a;sh$
http://%s:%d/Mozi.m;$
http://%s:%d/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws