General

  • Target

    3458aa0a053b2d6ece5c81d7b0ab08f4eb8931932df9cc36e08aa0bf82a2690f.elf

  • Size

    209KB

  • Sample

    240703-bk6a5stepn

  • MD5

    b3d9eab3c7dfe6b12d2b11f082c26a0f

  • SHA1

    6a9ffe8db2cb31000af5d6c39cb8e917cbb9492f

  • SHA256

    3458aa0a053b2d6ece5c81d7b0ab08f4eb8931932df9cc36e08aa0bf82a2690f

  • SHA512

    890f8b5e4b4ef6ece46044be428b2d070ae7121555c98eb30a9188dda4d97ed5731d69bab3525998605b519a7b6a4f49295eeaf25e837b46c1a7d63280d30142

  • SSDEEP

    3072:T4mSFGv/kuidcX1qRdck5hfH3TwpCMtmrpy6n9Nn:pn/ZmbRCk5hfXJMtmrpy6n9Nn

Score
10/10

Malware Config

Extracted

Family

gafgyt

C2

62.72.191.203:777

Targets

    • Target

      3458aa0a053b2d6ece5c81d7b0ab08f4eb8931932df9cc36e08aa0bf82a2690f.elf

    • Size

      209KB

    • MD5

      b3d9eab3c7dfe6b12d2b11f082c26a0f

    • SHA1

      6a9ffe8db2cb31000af5d6c39cb8e917cbb9492f

    • SHA256

      3458aa0a053b2d6ece5c81d7b0ab08f4eb8931932df9cc36e08aa0bf82a2690f

    • SHA512

      890f8b5e4b4ef6ece46044be428b2d070ae7121555c98eb30a9188dda4d97ed5731d69bab3525998605b519a7b6a4f49295eeaf25e837b46c1a7d63280d30142

    • SSDEEP

      3072:T4mSFGv/kuidcX1qRdck5hfH3TwpCMtmrpy6n9Nn:pn/ZmbRCk5hfXJMtmrpy6n9Nn

    Score
    6/10
    • Reads system routing table

      Gets active network interfaces from /proc virtual filesystem.

MITRE ATT&CK Matrix ATT&CK v13

Tasks