General

  • Target

    1ad856811354d0bf4c0e552e064eeeef0a3d601c6f738ad675f642dd1aa6b511.elf

  • Size

    155KB

  • Sample

    240703-bgr94syhnf

  • MD5

    34dbec1fdbd5eb161788b3ddab78d914

  • SHA1

    7feb2449c924af715466344914cdc04c48268bfe

  • SHA256

    1ad856811354d0bf4c0e552e064eeeef0a3d601c6f738ad675f642dd1aa6b511

  • SHA512

    506fe6278790e90104c9f7a6ef449ae79e1b3326dd9b6338ad0958d61b96e4c090ef72fe565742a888c500e61a1e7b568ebd6f9bed75260f2232350078e59e04

  • SSDEEP

    3072:xUL2FlZkJoC2gQXalWvRbffphahpCn38nuVAlZl3nmBT38dAY4:xDvhfphabkBwXmBT38dAY4

Score
10/10

Malware Config

Extracted

Family

gafgyt

C2

62.72.191.203:777

Targets

    • Target

      1ad856811354d0bf4c0e552e064eeeef0a3d601c6f738ad675f642dd1aa6b511.elf

    • Size

      155KB

    • MD5

      34dbec1fdbd5eb161788b3ddab78d914

    • SHA1

      7feb2449c924af715466344914cdc04c48268bfe

    • SHA256

      1ad856811354d0bf4c0e552e064eeeef0a3d601c6f738ad675f642dd1aa6b511

    • SHA512

      506fe6278790e90104c9f7a6ef449ae79e1b3326dd9b6338ad0958d61b96e4c090ef72fe565742a888c500e61a1e7b568ebd6f9bed75260f2232350078e59e04

    • SSDEEP

      3072:xUL2FlZkJoC2gQXalWvRbffphahpCn38nuVAlZl3nmBT38dAY4:xDvhfphabkBwXmBT38dAY4

    Score
    6/10
    • Reads system routing table

      Gets active network interfaces from /proc virtual filesystem.

MITRE ATT&CK Matrix ATT&CK v13

Tasks