192 bytes small Linux/ARM Raspberry Pi tcp port 4444 /bin/sh binding shellcode.
1a24f9b9ad167466d2026dc0a966677a2fe4340c7c09bec582671fcb93061fa5
160 bytes small Linux/ARM Raspberry Pi reverse TCP /bin/sh shellcode that connects to 192.168.0.12 port 4444.
d39c6fb0779cbfe35e7e33db8b14d9e3fa7865730dbe954dd0421c6645c5a5af
GRR Rapid Response is an incident response framework focused on remote live forensics. The goal of GRR is to support forensics and investigations in a fast, scalable manner to allow analysts to quickly triage attacks and perform analysis remotely. GRR consists of 2 parts: client and server. GRR client is deployed on systems that one might want to investigate. On every such system, once deployed, GRR client periodically polls GRR frontend servers for work. "Work" means running a specific action: downloading file, listing a directory, etc. GRR server infrastructure consists of several components (frontends, workers, UI servers) and provides web-based graphical user interface and an API endpoint that allows analysts to schedule actions on clients and view and process collected data.
79e926fc1ad932016c3c26ac50f8a1b9d55b8ad11060832bb0937cc4328720c5