Analysis

  • max time kernel
    148s
  • max time network
    3s
  • platform
    debian-9_armhf
  • resource
    debian9-armhf-20240611-en
  • resource tags

    arch:armhfimage:debian9-armhf-20240611-enkernel:4.9.0-13-armmp-lpaelocale:en-usos:debian-9-armhfsystem
  • submitted
    29-06-2024 17:13

General

  • Target

    Burpy-main/Linux_setup.sh

  • Size

    3KB

  • MD5

    73bc4d7b9e9239df7de056f438557029

  • SHA1

    b2a065229bb6f875fcddea7d3de55e6edca5202b

  • SHA256

    702246e93915471ef2fa6b35f5335a299329b929f0f90de2838a97550c64606e

  • SHA512

    5ebe8d54d87928c689607019f28451b3a4edf7cf8705aee86657eab798b586bb7f7c02d0225f99079255482b756571398568ae3c46525a905ce170e66c2b9cd1

Score
4/10

Malware Config

Signatures

  • Checks CPU configuration 1 TTPs 1 IoCs

    Checks CPU information which indicate if the system is a virtual machine.

  • Reads runtime system information 4 IoCs

    Reads data from /proc virtual filesystem.

Processes

  • /tmp/Burpy-main/Linux_setup.sh
    /tmp/Burpy-main/Linux_setup.sh
    1⤵
      PID:653
      • /bin/mkdir
        mkdir -p /usr/local/java
        2⤵
        • Reads runtime system information
        PID:659
      • /bin/mkdir
        mkdir -p /usr/local/java/jdk19
        2⤵
        • Reads runtime system information
        PID:662
      • /usr/bin/curl
        curl -L https://download.oracle.com/java/19/latest/jdk-19_linux-x64_bin.tar.gz -o jdk19.tar.gz
        2⤵
        • Checks CPU configuration
        • Reads runtime system information
        PID:664

    Network

    MITRE ATT&CK Matrix ATT&CK v13

    Defense Evasion

    Virtualization/Sandbox Evasion

    1
    T1497

    Discovery

    Virtualization/Sandbox Evasion

    1
    T1497

    Replay Monitor

    Loading Replay Monitor...

    Downloads