bot.sh4

First submission 2024-09-30 14:10:02

File details

File type: ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
Mime type: application/x-executable
File size: 114.81 KB (117568 bytes)
MD5: b7ddfbd42b6906bea2013df063cbe8b8
SHA1: 54e0ded02922c63e7b7b5b9bf6ec3ce5a3fcde2e
SHA256: 004b09c20d40d2e60aca9a3dd7257e8c6a309fdb924054091edbbd60c8231ec2

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 40/77 VT report date: 2024-09-30 13:29:34
Malware Type 1 trojan
Threat Type 3 mirai gafgyt genericrxua

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://45.85.146.39/bot.sh4 VirusTotal Report 45.85.146.39 VirusTotal Report 2024-09-30 14:10:02

Strings analysis - Possible IPs found 2

255.255.255.255
127.0.0.1