MalwareBazaar Database
This page shows some basic information the YARA rule gafgyt_langflow_sbox_cipher including corresponding malware samples.
Database Entry
| YARA Rule: | gafgyt_langflow_sbox_cipher |
|---|---|
| Author: | Nokia Deepfield ERT |
| Description: | Customized Gafgyt/BASHLITE DDoS bot delivered via Langflow CVE-2025-3248; identifies the actor's embedded affine S-box, 16-byte magic key, and LCG-driven stream cipher used for the encrypted C2 protocol |
| Firstseen: | 2026-08-18 08:36:55 UTC |
| Lastseen: | 2026-09-23 23:36:28 UTC |
| Sightings: | 21 |
Malware Samples
The table below shows all malware samples that matching this particular YARA rule (max 1000).
| Firstseen (UTC) | SHA256 hash | Tags | Signature | Reporter |
|---|