x86_64

First submission 2024-10-13 13:00:01 Last sumbission 2024-10-13 13:39:01

File details

File type: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped
Mime type: application/x-executable
File size: 61.81 KB (63296 bytes)
MD5: 9792db7688d11a5082b7af80862368ce
SHA1: 3b8b444c5256bed8eba39578bf03833d647f25ed
SHA256: 7f88ab1eff058326f0df0520f49b946c41dc134cca08f011440a72b35bdba7bb

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 40/77 VT report date: 2024-10-13 12:26:58
Malware Type 1 trojan
Threat Type 3 mirai expl gafgyt

URLs, FQDN and IP indicators 2

URL Host (FQDN/IP) Date Added
hXXp://net.tiktoka.cc/x86_64 VirusTotal Report net.tiktoka.cc VirusTotal Report 2024-10-13 13:39:02
hXXp://81.161.238.2/x86_64 VirusTotal Report 81.161.238.2 VirusTotal Report 2024-10-13 13:00:02

Strings analysis - Possible IPs found 3

81.161.238.2
255.255.255.255
127.0.0.1

Strings analysis - Possible URLs found 2

http://schemas.xmlsoap.org/soap/encoding/
http://schemas.xmlsoap.org/soap/envelope/