sh4

First submission 2024-10-17 13:31:02

File details

File type: ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
Mime type: application/x-executable
File size: 46.58 KB (47696 bytes)
MD5: f6a2e4b9041523f922a15bb204228195
SHA1: 8bbe0eb6756fafa2e842d91d6b7b6dca0fe56297
SHA256: f1442fa71dd04582c8774cc450367e28c8190461ab82e6322316a924367c1878

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 31/77 VT report date: 2024-10-17 02:04:32
Malware Type 1 trojan
Threat Type 3 mirai gafgyt ddos

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://87.236.95.134/bin1/sh4 VirusTotal Report 87.236.95.134 VirusTotal Report 2024-10-17 13:31:02

Strings analysis - Possible IPs found 1

172.236.29.44

Strings analysis - Possible URLs found 2

http://schemas.xmlsoap.org/soap/encoding/
http://schemas.xmlsoap.org/soap/envelope/