roze.armv6
First submission 2024-10-13 20:49:02
File details
File type: | ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, with debug_info, not stripped |
Mime type: | application/x-executable |
File size: | 204.69 KB (209606 bytes) |
MD5: | a1f1f29d081acb7dc39c8368e4c5e57f |
SHA1: | 2a6e2a5ef793ded2dfef30ba8feedae6f364458e |
SHA256: | 895f51d9af7134ed1b29ba7e9b2a2a96df54f0f140fa1533733e8c673f1a42f9 |
File features detected
Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR
OSINT Enrichments
Virus Total: | 40/77 VT report date: 2024-10-09 06:01:05 |
Malware Type 1 | trojan |
Threat Type 3 | gafgyt mirai bashlite |
URLs, FQDN and IP indicators 1
Strings analysis - Possible IPs found 11
1.9.2.8 |
3.0.4.2 |
8.8.8.8 |
93.123.85.167 |
1.9.2.6 |
1.9.2.4 |
1.8.1.11 |
1.9.0.8 |
1.9.0.6 |
1.9.1.1 |
1.9.1.3 |
Strings analysis - Possible URLs found 5
http://www.baidu.com/search/spider.html) |
http://www.baidu.com/search/spider.htm) |
http://fast.no/support/crawler.asp) |
http://feedback.redkolibri.com/ |
http://www.billybobbot.com/crawler/) |