General

  • Target

    hidakibest.x86.elf

  • Size

    90KB

  • Sample

    240703-njt8pszfme

  • MD5

    e2a89847bc9db68ba9663b3069dd59b5

  • SHA1

    3cc1d26fd7159549b382929533025f497203e9cd

  • SHA256

    822dd18327967a869c8f3c722e64e22f08f069effdb651b0a779db6da3a21836

  • SHA512

    726667dd94bf0ebe642875a5781aa5dcb7d4d05f2fe84fad1a8524444d0d7e8cefdd53d2f1619ff2962b3e219f2d743bff255f125769815bf8d60f8bff07d6f7

  • SSDEEP

    1536:N7R3dgFgpm+U3owTmlfX8xbUHPN+83Xwpha3N5iAoxg6I5um2Xj5YZA0e:t0FghURKlfs+vN+IXwpha3zoxg95um2h

Score
10/10

Malware Config

Extracted

Family

gafgyt

C2

194.233.78.47:4258

Targets

    • Target

      hidakibest.x86.elf

    • Size

      90KB

    • MD5

      e2a89847bc9db68ba9663b3069dd59b5

    • SHA1

      3cc1d26fd7159549b382929533025f497203e9cd

    • SHA256

      822dd18327967a869c8f3c722e64e22f08f069effdb651b0a779db6da3a21836

    • SHA512

      726667dd94bf0ebe642875a5781aa5dcb7d4d05f2fe84fad1a8524444d0d7e8cefdd53d2f1619ff2962b3e219f2d743bff255f125769815bf8d60f8bff07d6f7

    • SSDEEP

      1536:N7R3dgFgpm+U3owTmlfX8xbUHPN+83Xwpha3N5iAoxg6I5um2Xj5YZA0e:t0FghURKlfs+vN+IXwpha3zoxg95um2h

    Score
    6/10
    • Reads system routing table

      Gets active network interfaces from /proc virtual filesystem.

MITRE ATT&CK Matrix ATT&CK v13

Tasks