General

  • Target

    2be087e54204a6c395e05516c53fd579.elf

  • Size

    5.1MB

  • Sample

    240702-s7l98atepp

  • MD5

    2be087e54204a6c395e05516c53fd579

  • SHA1

    3bdad143cd168a2015aba2053e53f99a24d52ace

  • SHA256

    b60ad90687871ae94e2b33cf2320f523ee614893215335dc5958a6a705488330

  • SHA512

    2ab629a5f9637c7026069e5cc7b473968290b8eb42158dc93c46613d2b4b0ef39149f158b71dda8b2c8bbbebd58ba28cf5437fc0d083fca37deb84423a769db8

  • SSDEEP

    49152:YB9Em2vjYVfh5jw9aF8k4yHwXrD3LwJKiCb85E6l9HblTLEGdvIRKnuI:QDVf/Y4jMrDr8E+rvuK1

Score
7/10

Malware Config

Targets

    • Target

      2be087e54204a6c395e05516c53fd579.elf

    • Size

      5.1MB

    • MD5

      2be087e54204a6c395e05516c53fd579

    • SHA1

      3bdad143cd168a2015aba2053e53f99a24d52ace

    • SHA256

      b60ad90687871ae94e2b33cf2320f523ee614893215335dc5958a6a705488330

    • SHA512

      2ab629a5f9637c7026069e5cc7b473968290b8eb42158dc93c46613d2b4b0ef39149f158b71dda8b2c8bbbebd58ba28cf5437fc0d083fca37deb84423a769db8

    • SSDEEP

      49152:YB9Em2vjYVfh5jw9aF8k4yHwXrD3LwJKiCb85E6l9HblTLEGdvIRKnuI:QDVf/Y4jMrDr8E+rvuK1

    Score
    7/10
    • Modifies Watchdog functionality

      Malware like Mirai modifies the Watchdog to prevent it restarting an infected system.

    • Creates/modifies environment variables

      Creating/modifying environment variables is a common persistence mechanism.

    • Modifies init.d

      Adds/modifies system service, likely for persistence.

    • Modifies Bash startup script

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Hijack Execution Flow

1
T1574

Boot or Logon Autostart Execution

2
T1547

Privilege Escalation

Hijack Execution Flow

1
T1574

Boot or Logon Autostart Execution

2
T1547

Defense Evasion

Impair Defenses

1
T1562

Hijack Execution Flow

1
T1574

Discovery

System Information Discovery

1
T1082

Tasks