General

  • Target

    133562f29886fc8c85ce7083d4ff53fb.elf

  • Size

    57KB

  • Sample

    240703-bhsl9stdnp

  • MD5

    133562f29886fc8c85ce7083d4ff53fb

  • SHA1

    56a063ff06fbfdc55444ab9cd47b5e54a8ba50fd

  • SHA256

    3f509a48bfb5cf1a5da35c861c70b5777e61a5dbf250331e5e731a912a148672

  • SHA512

    1c5965dc03cd2ae2403aa1079d006ebdaa9e7a9daa548d5df6588a5c5c75a6e4c75c62065927bc51f5860ad394733c89d73b04017c7bc482ae35ee68f3ef9212

  • SSDEEP

    768:kbvzoZ2MvVVIXXz86kV+VT84keDpgfpZ/Lsx5JCvB53+LQOpZM5qikqs:SvzoTVIXDDkV+97pEZ/LOJUBJVe2qids

Score
7/10

Malware Config

Targets

    • Target

      133562f29886fc8c85ce7083d4ff53fb.elf

    • Size

      57KB

    • MD5

      133562f29886fc8c85ce7083d4ff53fb

    • SHA1

      56a063ff06fbfdc55444ab9cd47b5e54a8ba50fd

    • SHA256

      3f509a48bfb5cf1a5da35c861c70b5777e61a5dbf250331e5e731a912a148672

    • SHA512

      1c5965dc03cd2ae2403aa1079d006ebdaa9e7a9daa548d5df6588a5c5c75a6e4c75c62065927bc51f5860ad394733c89d73b04017c7bc482ae35ee68f3ef9212

    • SSDEEP

      768:kbvzoZ2MvVVIXXz86kV+VT84keDpgfpZ/Lsx5JCvB53+LQOpZM5qikqs:SvzoTVIXDDkV+97pEZ/LOJUBJVe2qids

    Score
    7/10
    • Modifies Watchdog functionality

      Malware like Mirai modifies the Watchdog to prevent it restarting an infected system.

    • Unexpected DNS network traffic destination

      Network traffic to other servers than the configured DNS servers was detected on the DNS port.

    • Writes file to system bin folder

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Hijack Execution Flow

1
T1574

Privilege Escalation

Hijack Execution Flow

1
T1574

Defense Evasion

Impair Defenses

1
T1562

Hijack Execution Flow

1
T1574

Discovery

System Information Discovery

1
T1082

Tasks