goahead

First submission 2024-10-17 02:13:02

File details

File type: Bourne-Again shell script, ASCII text executable, with very long lines
Mime type: text/x-shellscript
File size: 4.72 KB (4830 bytes)
MD5: ab9ca96b70ab2766af19b4f66ca51983
SHA1: 408dd59c1315ef7a8e4f24a1ba88f37e4a81afb4
SHA256: 92db80ff0a69312f362597f8b92ce9e6259384338e67d246f87549dbbae8597e

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 34/77 VT report date: 2024-10-17 02:03:16
Malware Type 2 downloader trojan
Threat Type 3 medusa shell mirai

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://87.236.95.134/goahead VirusTotal Report 87.236.95.134 VirusTotal Report 2024-10-17 02:13:02

Strings analysis - Possible IPs found 1

87.236.95.134

Strings analysis - Possible URLs found 14

http://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.i686;
http://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.x86;
http://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.arm6;
http://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.spc;
http://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.m68k;
http://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.arm7;
http://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.mips;
http://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.ppc;
http://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.arm;
http://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.sh4;
http://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.arm5;
http://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.mpsl;
http://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.x86_64;
http://87.236.95.134/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.arc;