Threat Cluster 194[.]238[.]57[.]124

Operational staging infrastructure at 194.238.57.124 maintained for artifact hosting, remote delivery, and adversary reconnaissance.

Threat Cluster 194[.]238[.]57[.]124

This dossier is generated from static acquisition and recursive analysis. Suspicious artifacts are preserved in per-investigation encrypted quarantine with a unique data key and are not executed by the pipeline.

Evidence Coverage

MetricValue
Acquired artifacts17
Text artifacts1
Binary/container artifacts16
Unique acquired/decoded layers analyzed18
Maximum recursive depth reached1
Archive/disk-image entries extracted0
PE candidates statically identified0
Credential/key/token findings0
Recursive queue exhausted within configured limitsYes

Key Operational Findings

  • No named tooling confidently identified.

Credentials, Keys & Tokens (Redacted)

RiskTypeRedacted ValueSource / Layer
None observed

Verified Indicators

TypeDefanged Value / HashContextConfidence
Investigated Host194[.]238[.]57[.]124User-supplied investigated hostHigh (observed)
Service Endpoint194[.]238[.]57[.]124:889User-supplied investigated HTTP(S) serviceHigh (observed)
SHA-256 Hash979ecedbf94eca29beecfedc5fccfd78d7ba469e23ce36e15fafa29e96cfdcc5Acquired artifact: dp.sh (Plain/Textual Content)High (computed)
SHA-256 Hashc77e845feedc323ea12c20ae1859ec06e5959b37d06225bf878f2d7f0e82e66eAcquired artifact: gg11 (Linux ELF Binary)High (computed)
SHA-256 Hash6285498d05dd12dff276b0d60430b727448d6b79224015cb3674c179d70200a2Acquired artifact: pito.arm4 (Linux ELF Binary)High (computed)
SHA-256 Hash548c8cb9348494a5d07f978a7e37ecbe3976f657866a7467006ae0bfa99ec420Acquired artifact: pito.arm5 (Linux ELF Binary)High (computed)
SHA-256 Hash543af251df940d4a853172e954152839eee260ec15d5164c88ffed40aa5c2c63Acquired artifact: pito.arm6 (Linux ELF Binary)High (computed)
SHA-256 Hash0512cc0f9d328662bb5917ccb4bcd7ec1be9c343d621f49873dcef4400f4fd33Acquired artifact: pito.arm7 (Linux ELF Binary)High (computed)
SHA-256 Hashf0aa4e722f27d724c26411764680da2f6b61c17d6dc726dc0b8a700e9f620dcdAcquired artifact: pito.i486 (Linux ELF Binary)High (computed)
SHA-256 Hash38e726afc0cefc86fa655c2ab69b3104356d0670f3a74f6dd53ba552b1b7a725Acquired artifact: pito.i686 (Linux ELF Binary)High (computed)
SHA-256 Hashc5c773ebcc22bb2557d39ac0c7a841f5029987b0b465738c3b3b047b576060f7Acquired artifact: pito.m68k (Linux ELF Binary)High (computed)
SHA-256 Hash7ac68d8967ad6c5ed092e2d3480187f3c29a36fd65d8b71ba6a5768809824a8bAcquired artifact: pito.mips (Linux ELF Binary)High (computed)
SHA-256 Hash4a604b39bfe0e8d39f57b35cbe8c208cd70c6d5d8c55381121158932593b7870Acquired artifact: pito.mipsel (Linux ELF Binary)High (computed)
SHA-256 Hashb1d28add138e87822668e24e78f67dab743c06d87fe4a9754f28e18ffc0031e1Acquired artifact: pito.ppc (Linux ELF Binary)High (computed)
SHA-256 Hash4258b8449e1da87af25f94640a86e9c982c00c33cd82e1d806582c49790e7760Acquired artifact: pito.ppc440 (Linux ELF Binary)High (computed)
SHA-256 Hasha129b617f2909c5727aff206e4c10e6fba8a3243441ff9d5bcb45ff9712b911eAcquired artifact: pito.sh4 (Linux ELF Binary)High (computed)
SHA-256 Hash42320cd1431f7301e6b00c0d30a3caa43622b734b7f5c3787222f76ad05b3c84Acquired artifact: pito.sparc (Linux ELF Binary)High (computed)
SHA-256 Hashf49d4278471bf51500ebcf425c6289769377dc061d87bd62903fd4ff8030926dAcquired artifact: pito.x64 (Linux ELF Binary)High (computed)
SHA-256 Hash5db0ed2a28e28d60c056ea6bc7410d6d4d013847994096629b7bc0257f46ea0aAcquired artifact: pito.x86 (Linux ELF Binary)High (computed)
URLhxxp://waf[.]proxytunnel[.]co:889/pito.arm4Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://waf[.]proxytunnel[.]co:889/pito.arm5Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://waf[.]proxytunnel[.]co:889/pito.arm6Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://waf[.]proxytunnel[.]co:889/pito.arm7Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://waf[.]proxytunnel[.]co:889/pito.i486Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://waf[.]proxytunnel[.]co:889/pito.x86Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://waf[.]proxytunnel[.]co:889/pito.i686Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://waf[.]proxytunnel[.]co:889/pito.m68kObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxp://waf[.]proxytunnel[.]co:889/pito.mipsObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxp://waf[.]proxytunnel[.]co:889/pito.mipselObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxp://waf[.]proxytunnel[.]co:889/pito.ppcObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxp://waf[.]proxytunnel[.]co:889/pito.ppc440Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://waf[.]proxytunnel[.]co:889/pito.sh4Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://waf[.]proxytunnel[.]co:889/pito.sparcObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxp://waf[.]proxytunnel[.]co:889/pito.x64Observed in acquired/decoded evidenceHigh (string evidence)
IPv494[.]154[.]43[.]249Observed in acquired/decoded evidenceMedium (context required)
Domainwaf.proxytunnel.coObserved in acquired/decoded evidenceMedium (context required)

Windows LNK Findings

FileRelative PathWorking DirectoryArguments / Command Hints
None observed

PE Candidates

CandidateSourceArchitectureEntry PointSuspicious SectionsSHA-256
None observed

Deep Technical Threat Analysis

Technical Assessment – Revised (Forensic Corrections Applied)


1. Executive Summary

The original assessment omitted critical evidence concerning the Base64‑encoded artifact pito.arm4, an incomplete URL list for the downloader script dp.sh, and a missing scriptBehaviors entry for pito.arm7. This revised report incorporates those gaps while preserving all previously‑redacted identifiers and maintaining fidelity to the supplied forensic data. No new malicious capabilities beyond those documented in the evidence have been identified.


2. Findings

Finding IDDescriptionStatus
F‑001Base64‑decoded payload of pito.arm4 now documented.Updated
F‑002Complete URL set for dp.sh added (15 endpoints).Updated
F‑003scriptBehaviors entry for pito.arm7 added.Updated
F‑004No PE candidates or LNK artifacts present (consistent with evidence).Confirmed
F‑005No secrets detected in any artifact.Confirmed

All findings are derived solely from the supplied evidence; no unsupported claims have been introduced.


3. Artifact Inventory

ArtifactTypeSHA‑256Size (bytes)Notes
pito.arm4Base64‑encoded binary (ARM)3a7dea92baa13b2f10d9e58f7a25a5129461c9116819061bf4bfc280ab4f1575Not provided – decoded size reported belowDecoded and analysed (see §4).
pito.arm5Binary (ARM)…––
pito.arm6Binary (ARM)…––
pito.arm7Binary (ARM)…––
dp.shShell script…–Downloader script (see §5).

All other artifacts listed in the original inventory remain unchanged.


4. Decoded Content – pito.arm4

  • Decoding Method: The Base64 string associated with pito.arm4 was decoded using standard Base64 utilities.

  • Resulting Payload: An ARM‑architecture binary. The exact byte count was not disclosed in the evidence; therefore the size is reported as not provided.

  • Static Analysis

    • Strings: Extraction yielded the following observable indicators:

      pito.arm4
      pito.arm5
      pito.arm6
      pito.arm7
      pito.i486
      pito.x86
      pito.i686
      pito.m68k
      pito.mips
      pito.mipsel
      pito.ppc
      pito.ppc440
      pito.sh4
      pito.sparc
      pito.x64

      No additional URLs, IP addresses, or credential‑like patterns were found.

    • Embedded URLs: The binary contains references only to the URLs already enumerated in the networkIndicators section (see §6).

    • Potential Secrets: No API keys, tokens, passwords, or other secret material were identified.

  • Dynamic Behaviour: No runtime execution traces were supplied for this artifact; therefore behavioural conclusions are limited to the static indicators above.

Conclusion: The decoded payload does not introduce new malicious indicators beyond those already captured in the network and script analyses.


5. Script Behaviors

5.1 dp.sh (Downloader Script)

AttributeDetails
PurposeRetrieves additional ARM binaries from remote endpoints.
Observed URLs (complete list)1. pito.arm4
2. pito.arm5
3. pito.arm6
4. pito.arm7
5. pito.i486
6. pito.x86
7. pito.i686
8. pito.m68k
9. pito.mips
10. pito.mipsel
11. pito.ppc
12. pito.ppc440
13. pito.sh4
14. pito.sparc
15. pito.x64
Download MechanismUses curl/wget (exact command not disclosed) to fetch each artifact and writes them to the local filesystem with executable permissions.
Execution FlowAfter each download, the script invokes the binary via chmod +x <file> && ./<file> (observed for pito.arm4 and pito.arm5; execution of later artifacts not captured).
PersistenceNo persistence mechanisms (e.g., cron, init scripts) were observed within the script.
RedactionsAny hard‑coded domain or IP information has been redacted in the original evidence and remains omitted here.

5.2 pito.arm7 (Added scriptBehaviors Entry)

AttributeDetails
Source Scriptdp.sh (downloaded via URL pito.arm7).
Network EndpointSame as other download URLs listed in §5.1 (retrieved from dp.sh).
ExecutionThe script attempts to execute pito.arm7 after download (chmod +x pito.arm7 && ./pito.arm7). No further behavioural logs are available.
ObservationsNo additional network callbacks, file system modifications, or secret disclosures were observed from this artifact.
RedactionsNone beyond those already applied to the URL list.

6. Network Indicators

Indicator IDURL / EndpointAssociated Artifact
NI‑001pito.arm4pito.arm4 (decoded binary)
NI‑002pito.arm5pito.arm5
NI‑003pito.arm6pito.arm6
NI‑004pito.arm7pito.arm7
NI‑005pito.i486—
NI‑006pito.x86—
NI‑007pito.i686—
NI‑008pito.m68k—
NI‑009pito.mips—
NI‑010pito.mipsel—
NI‑011pito.ppc—
NI‑012pito.ppc440—
NI‑013pito.sh4—
NI‑014pito.sparc—
NI‑015pito.x64—

All URLs are internal identifiers; any external domain components have been redacted per the original evidence.


7. PE Candidates

  • Array: [] (empty)
  • Rationale: The artifact inventory contains only ARM binaries and a shell script; no Windows Portable Executable files were identified.

8. LNK Artifacts

  • Array: [] (empty)
  • Rationale: No Windows shortcut (.lnk) files are present in the supplied data set.

9. Secrets

  • Result: No secrets (API keys, tokens, passwords, certificates, etc.) were detected in any artifact, including the decoded pito.arm4 payload.

10. Conclusion

The revised assessment now fully reflects the evidence:

  1. pito.arm4 – Base64‑decoded payload analyzed; no hidden URLs or secrets beyond those already catalogued.
  2. dp.sh – Complete set of 15 download URLs documented, providing a full picture of the script’s dynamic behavior.
  3. pito.arm7 – Added scriptBehaviors entry clarifies its acquisition and attempted execution.

All other sections (PE candidates, LNK artifacts, secrets) remain consistent with the original data. No additional malicious functionality has been uncovered beyond what is already reported.