General

  • Target

    b8d4bf9e194f61703d597682997bcf702756e83948f359128e22babe9d08a952.elf

  • Size

    204KB

  • Sample

    240703-cyr64sxbpq

  • MD5

    aa6216495cf81557da544e6500636d3f

  • SHA1

    887456d81b352e7d9ae4d368ef533e61485f38cc

  • SHA256

    b8d4bf9e194f61703d597682997bcf702756e83948f359128e22babe9d08a952

  • SHA512

    9072be414a9825d5a5e2f4f191ba7fe09bd16f7131dcf0b05cd1fb8ebe3daac586a341d1132f1badbbe19b616a79308bd08c96af8982a36096b083ed7e36891e

  • SSDEEP

    6144:FZzyacCwXJ4DbpW0vV5hbL6K2axVOcgym0wfB5RyAn:FZzyacCwXJ4gC5hbMylgym0mB5RyAn

Score
10/10

Malware Config

Extracted

Family

gafgyt

C2

195.85.205.47:777

Targets

    • Target

      b8d4bf9e194f61703d597682997bcf702756e83948f359128e22babe9d08a952.elf

    • Size

      204KB

    • MD5

      aa6216495cf81557da544e6500636d3f

    • SHA1

      887456d81b352e7d9ae4d368ef533e61485f38cc

    • SHA256

      b8d4bf9e194f61703d597682997bcf702756e83948f359128e22babe9d08a952

    • SHA512

      9072be414a9825d5a5e2f4f191ba7fe09bd16f7131dcf0b05cd1fb8ebe3daac586a341d1132f1badbbe19b616a79308bd08c96af8982a36096b083ed7e36891e

    • SSDEEP

      6144:FZzyacCwXJ4DbpW0vV5hbL6K2axVOcgym0wfB5RyAn:FZzyacCwXJ4gC5hbMylgym0mB5RyAn

    Score
    6/10
    • Reads system routing table

      Gets active network interfaces from /proc virtual filesystem.

MITRE ATT&CK Matrix ATT&CK v13

Tasks