General

  • Target

    e7f994410e4ac997ea931e2f513806781d8d59d5d071189cc26edc345782c4e1.elf

  • Size

    106KB

  • Sample

    240702-cl26jswdmq

  • MD5

    c33d141a8ee2aee1ddbab334c6cc6319

  • SHA1

    09568a84c28cfb4a0bba45c71706e9162fb8a878

  • SHA256

    e7f994410e4ac997ea931e2f513806781d8d59d5d071189cc26edc345782c4e1

  • SHA512

    a237af19f979fff046ed0b90778b06606cbc494a5c068fbb4b38ee0f257a62e01a80e61fec767d6a3a86b2b9baad87f47377acb682164d5b25d472f217def131

  • SSDEEP

    3072:j6dye4BmJQephaZw/1vc4+AzkSXmdRWaLHgb4:dephaZchrmdRWaDgb4

Score
10/10

Malware Config

Extracted

Family

gafgyt

C2

37.156.29.141:4258

Targets

    • Target

      e7f994410e4ac997ea931e2f513806781d8d59d5d071189cc26edc345782c4e1.elf

    • Size

      106KB

    • MD5

      c33d141a8ee2aee1ddbab334c6cc6319

    • SHA1

      09568a84c28cfb4a0bba45c71706e9162fb8a878

    • SHA256

      e7f994410e4ac997ea931e2f513806781d8d59d5d071189cc26edc345782c4e1

    • SHA512

      a237af19f979fff046ed0b90778b06606cbc494a5c068fbb4b38ee0f257a62e01a80e61fec767d6a3a86b2b9baad87f47377acb682164d5b25d472f217def131

    • SSDEEP

      3072:j6dye4BmJQephaZw/1vc4+AzkSXmdRWaLHgb4:dephaZchrmdRWaDgb4

    Score
    6/10
    • Reads system routing table

      Gets active network interfaces from /proc virtual filesystem.

MITRE ATT&CK Matrix ATT&CK v13

Tasks