firmware.sh4

First submission 2024-09-01 17:01:03 Last sumbission 2024-09-01 18:19:02

File details

File type: ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
Mime type: application/x-executable
File size: 93.42 KB (95664 bytes)
MD5: 866ab94cdba8c1e145fcfc5e8a587251
SHA1: 3eda27ca9939320a3fdd89e794d3c1207cca7902
SHA256: b8aba5f4f1a0f074f60982b0f030fd84af36556d747e0642a8fb575f9899de6c

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 37/78 VT report date: 2024-09-01 08:44:55
Malware Type 1 trojan
Threat Type 3 mirai gafgyt bonb

URLs, FQDN and IP indicators 3

URL Host (FQDN/IP) Date Added
hXXp://shayan.90.ydns.eu/firmware/firmware.sh4 VirusTotal Report shayan.90.ydns.eu VirusTotal Report 2024-09-01 18:19:03
hXXp://ckea.ru/firmware/firmware.sh4 VirusTotal Report ckea.ru VirusTotal Report 2024-09-01 17:22:04
hXXp://45.159.211.121/firmware/firmware.sh4 VirusTotal Report 45.159.211.121 VirusTotal Report 2024-09-01 17:01:03

Strings analysis - Possible IPs found 1

8.8.8.8