General

  • Target

    hidakibest.mpsl.elf

  • Size

    141KB

  • Sample

    240702-e5d9yazclm

  • MD5

    961cb57075598839f35e7dfedb23260a

  • SHA1

    56e722af334cc2c4b605c2b4290149af83a4a718

  • SHA256

    391504a2dcc1bf82b23e97bc6f3d1c906e25a9d2090b5c38dc2388ccff96be36

  • SHA512

    65b3f84e4f84fd1eeb3699341842177defd30da48e9897971ae16ce095b3c0d814529ddc0df2f76d736f0d1babcf13e6545b4be6baef5d46e3467ea3de0d1413

  • SSDEEP

    3072:lBXpqf9VHGn7vst5htpRvHpVFm0/5ApYADn:llp4Wvst5htvp7m0/5ASADn

Score
10/10

Malware Config

Extracted

Family

gafgyt

C2

45.93.200.174:4258

Targets

    • Target

      hidakibest.mpsl.elf

    • Size

      141KB

    • MD5

      961cb57075598839f35e7dfedb23260a

    • SHA1

      56e722af334cc2c4b605c2b4290149af83a4a718

    • SHA256

      391504a2dcc1bf82b23e97bc6f3d1c906e25a9d2090b5c38dc2388ccff96be36

    • SHA512

      65b3f84e4f84fd1eeb3699341842177defd30da48e9897971ae16ce095b3c0d814529ddc0df2f76d736f0d1babcf13e6545b4be6baef5d46e3467ea3de0d1413

    • SSDEEP

      3072:lBXpqf9VHGn7vst5htpRvHpVFm0/5ApYADn:llp4Wvst5htvp7m0/5ASADn

    Score
    6/10
    • Reads system routing table

      Gets active network interfaces from /proc virtual filesystem.

MITRE ATT&CK Matrix ATT&CK v13

Tasks