k.arm6
First submission 2024-10-18 00:28:02
File details
File type: | ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, with debug_info, not stripped |
Mime type: | application/x-executable |
File size: | 153.13 KB (156806 bytes) |
MD5: | 87ea0ae5594d7e59242de7216ad0f4c9 |
SHA1: | f15156a22dd54aa601490f1169b38bb3b7ee73ed |
SHA256: | cc87cb17f0663028e9db55a37c749a51e8349c2b8f06d6b59a756c4782f9e85f |
File features detected
Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR
URLs, FQDN and IP indicators 1
Strings analysis - Possible IPs found 7
1.9.2.6 |
1.9.2.4 |
1.8.1.11 |
1.9.0.8 |
64.235.37.148 |
8.8.8.8 |
1.9.0.6 |
Strings analysis - Possible URLs found 6
http://64.235.37.148/gpon+-O+/tmp/gaf;sh+/tmp/gaf |
http://64.235.37.148/t%20-O%20-%3E%20/tmp/t;sh%20/tmp/t%27$ |
http://64.235.37.148/real.sh |
http://schemas.xmlsoap.org/soap/envelope/ |
http://schemas.xmlsoap.org/soap/encoding/ |
http://64.235.37.148/Kirin.sh;chmod |