General

  • Target

    74eccd852eab34eaf4d1f7497a76d816cc2c3dd41d3812b7da6e4560a43d5349.elf

  • Size

    120KB

  • Sample

    240706-bvrwhathpg

  • MD5

    6a55e7205729dbc6b4d324dabf284f41

  • SHA1

    c3fbe653cd334002bcdc4f877ff88a22a48d9d8d

  • SHA256

    74eccd852eab34eaf4d1f7497a76d816cc2c3dd41d3812b7da6e4560a43d5349

  • SHA512

    f92fbe82ddf8de1890af00828f9b8e45914926a76a55c6baa34d31c656353ce295aa4fe503c8ad6f3989603f08eca9e14ecf1229c9d2f01c7b04d56b7996f060

  • SSDEEP

    3072:yvINYCagg4pAF4mbUAQTbFjnme0DU8nTl9:yYYwg6AymbUDTbpnme0DUkTl9

Score
10/10

Malware Config

Extracted

Family

gafgyt

C2

5.59.248.211:6982

Targets

    • Target

      74eccd852eab34eaf4d1f7497a76d816cc2c3dd41d3812b7da6e4560a43d5349.elf

    • Size

      120KB

    • MD5

      6a55e7205729dbc6b4d324dabf284f41

    • SHA1

      c3fbe653cd334002bcdc4f877ff88a22a48d9d8d

    • SHA256

      74eccd852eab34eaf4d1f7497a76d816cc2c3dd41d3812b7da6e4560a43d5349

    • SHA512

      f92fbe82ddf8de1890af00828f9b8e45914926a76a55c6baa34d31c656353ce295aa4fe503c8ad6f3989603f08eca9e14ecf1229c9d2f01c7b04d56b7996f060

    • SSDEEP

      3072:yvINYCagg4pAF4mbUAQTbFjnme0DU8nTl9:yYYwg6AymbUDTbpnme0DUkTl9

    Score
    6/10
    • Reads system routing table

      Gets active network interfaces from /proc virtual filesystem.

MITRE ATT&CK Matrix ATT&CK v13

Tasks