thinkphp

First submission 2024-10-17 02:20:02

File details

File type: Bourne-Again shell script, ASCII text executable, with very long lines
Mime type: text/x-shellscript
File size: 4.73 KB (4844 bytes)
MD5: 80299ebce287b053ec82cff873ddf3b4
SHA1: 1cf8df1f0b5e0903ac1a103e4acee85a5f0d6e00
SHA256: 220d36bded88e96516faa4ccdd36e291ad8a7639f36d51e2a3f18098f14f7a0c

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 35/77 VT report date: 2024-10-17 02:04:37
Malware Type 2 downloader trojan
Threat Type 3 medusa shell mirai

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://87.236.95.134/thinkphp VirusTotal Report 87.236.95.134 VirusTotal Report 2024-10-17 02:20:02

Strings analysis - Possible IPs found 1

87.236.95.134

Strings analysis - Possible URLs found 14

http://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.i686;
http://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.x86;
http://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.arm6;
http://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.spc;
http://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.m68k;
http://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.arm7;
http://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.mips;
http://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.ppc;
http://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.arm;
http://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.sh4;
http://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.arm5;
http://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.mpsl;
http://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.x86_64;
http://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.arc;