bot.arm6

First submission 2024-09-03 10:15:02 Last sumbission 2024-09-03 11:23:02

File details

File type: ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
Mime type: application/x-executable
File size: 144.62 KB (148092 bytes)
MD5: 8d6530a2f956ee575eeae3ae4c6ea25e
SHA1: f53aebd2b7412d24a0301be77468d832c4d2c0a9
SHA256: f3f2728743fed34d912b84f185a223281c4dbd2c0a2d6975bdc82eae48d2abda

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 44/79 VT report date: 2024-09-03 09:50:25
Malware Type 1 trojan
Threat Type 3 mirai gafgyt bashlite

URLs, FQDN and IP indicators 3

URL Host (FQDN/IP) Date Added
hXXp://185.196.9.222/bot.arm6 VirusTotal Report 185.196.9.222 VirusTotal Report 2024-09-03 11:23:03
hXXp://captcha.webredirect.org/bot.arm6 VirusTotal Report captcha.webredirect.org VirusTotal Report 2024-09-03 10:16:03
hXXp://chrome.webredirect.org/bot.arm6 VirusTotal Report chrome.webredirect.org VirusTotal Report 2024-09-03 10:15:02

Strings analysis - Possible IPs found 2

255.255.255.255
127.0.0.1