boatnet.sh4

First submission 2024-08-31 23:40:02

File details

File type: ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
Mime type: application/x-executable
File size: 80.85 KB (82792 bytes)
MD5: 829fedd9e66cc609278b2c47363466b5
SHA1: a4862d2ccd2e85952439b525b84e118a6a3f2fa7
SHA256: 1ee87e6228d79a9f20baab112db361edfd910a0fe12a53ff48bb0940455dd858

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 39/78 VT report date: 2024-08-31 23:08:59
Malware Type 1 trojan
Threat Type 3 mirai gafgyt froz

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://94.156.71.225/hiddenbin/boatnet.sh4 VirusTotal Report 94.156.71.225 VirusTotal Report 2024-08-31 23:40:02

Strings analysis - Possible IPs found 3

255.255.255.255
127.0.0.1
94.156.71.225