MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 040b64280a31da940a0cb4e2b1bc9fdd846e3b6741793e9b92fb0f525a0bc9e3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 040b64280a31da940a0cb4e2b1bc9fdd846e3b6741793e9b92fb0f525a0bc9e3
SHA3-384 hash: 36e35e51b08130c314c070790ab3c822e0c13c8c886201c5f30902fc7c62d859cf5b40b480ae464004c7ef8ffcfa7bc6
SHA1 hash: 460b9bc6aeac281887adbe19362c62f0d3ae8148
MD5 hash: 1bc181b959c92e9e8cb8dd6587f27ded
humanhash: early-carbon-comet-freddie
File name:mpsl
Download: download sample
Signature Gafgyt
File size:28'388 bytes
First seen:2024-11-03 05:36:28 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 384:Ci2TcFENKWRXr+7UYcKdPRQexsZT1ZqqoGSPtfdExMyyc551CBJiOpgysEYF0Trv:044pR7+7DhRQ4EhZh2UVZ55+JNaFm
TLSH T1DFD2F1067D0F8E2CE567E5B5710619932FA5515B8B17FF1B28F4BB4FAA35C280248723
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf gafgyt

Intelligence


File Origin
# of uploads :
1
# of downloads :
88
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Runs as daemon
Opens a port
Connection attempt
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
mips
Packer:
custom
Botnet:
unknown
Number of open files:
7
Number of processes launched:
1
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
no suspicious findings
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Result
Verdict:
MALICIOUS
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1547823 Sample: mpsl.elf Startdate: 03/11/2024 Architecture: LINUX Score: 48 11 159.253.120.117, 1889, 53892, 53894 TKDIALOG-ASRU Russian Federation 2->11 13 Multi AV Scanner detection for submitted file 2->13 7 mpsl.elf 2->7         started        signatures3 process4 process5 9 mpsl.elf 7->9         started       
Threat name:
Linux.Trojan.Gafgyt
Status:
Malicious
First seen:
2024-09-28 01:48:35 UTC
File Type:
ELF32 Little (Exe)
AV detection:
5 of 38 (13.16%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Reads runtime system information
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

elf 040b64280a31da940a0cb4e2b1bc9fdd846e3b6741793e9b92fb0f525a0bc9e3

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh

Comments