General

  • Target

    Okami.arm5.elf

  • Size

    95KB

  • Sample

    240705-gtqvpswemf

  • MD5

    367c4e5d6a27362aaa00fa81ec64c1d0

  • SHA1

    f4ed1a09f6d5e22c28149d6b8bd04c91f92f9f3d

  • SHA256

    c9517d36ef7d5db4299dca574bfeb5701f005081ad3ba3f54876f1a256f2a595

  • SHA512

    0b75c0ecf5b001778325177f0b1e245bc3e5ff9a98f41e5fbc4413f485852e762423dcb9d7a6cc33dfc83ea6184805fc0fef0b096c78722768e326296debfffb

  • SSDEEP

    1536:QOs8fUOsBA+WuS2BJ1wAR13VKYmJjO/E5hYIXUeRVdAxpPdIufWHeoB/DQUDaLd2:QhOMA+Wu0AbwYmR5hYIEeR3+pPdoB/Dn

Score
10/10

Malware Config

Extracted

Family

gafgyt

C2

93.123.85.246:6963

Targets

    • Target

      Okami.arm5.elf

    • Size

      95KB

    • MD5

      367c4e5d6a27362aaa00fa81ec64c1d0

    • SHA1

      f4ed1a09f6d5e22c28149d6b8bd04c91f92f9f3d

    • SHA256

      c9517d36ef7d5db4299dca574bfeb5701f005081ad3ba3f54876f1a256f2a595

    • SHA512

      0b75c0ecf5b001778325177f0b1e245bc3e5ff9a98f41e5fbc4413f485852e762423dcb9d7a6cc33dfc83ea6184805fc0fef0b096c78722768e326296debfffb

    • SSDEEP

      1536:QOs8fUOsBA+WuS2BJ1wAR13VKYmJjO/E5hYIXUeRVdAxpPdIufWHeoB/DQUDaLd2:QhOMA+Wu0AbwYmR5hYIEeR3+pPdoB/Dn

    Score
    7/10
    • Writes DNS configuration

      Writes data to DNS resolver config file.

MITRE ATT&CK Matrix ATT&CK v13

Tasks