MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 05686c56837324d1bbb9b98c331bd689af81de4a27c52a4d84ace7e25302e111. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 7


Intelligence 7 IOCs YARA 16 File information Comments

SHA256 hash: 05686c56837324d1bbb9b98c331bd689af81de4a27c52a4d84ace7e25302e111
SHA3-384 hash: 7882bb37db6b74eb5db808aefabc267b401350f3ef0dd31cae4bef0db320d52f2f5a81ab71692d6b021deef044a0fa2a
SHA1 hash: d2f5dbec007fc5ab00891651aaf56e1feefd9b63
MD5 hash: 54f0648f2e7cee0cb382eec995843eb2
humanhash: gee-equal-enemy-mirror
File name:kworkerd
Download: download sample
Signature Gafgyt
File size:278'072 bytes
First seen:2026-07-08 01:28:08 UTC
Last seen:2026-07-08 13:02:11 UTC
File type: elf
MIME type:application/x-executable
ssdeep 6144:+Oq94BgLBMx0E/bJghAzZ6DvFc9NqHH9JLOf9E5:VyEgFMx0E/bJghAYvFc98HH9y9E5
TLSH T1AE445B036580D5BAC487D0B5CBDFA2274961783D5C7A724B27A07FA23F4AEB05B19B13
telfhash t195a1ad301895305172d3c5467607ea3dbd350864d7ed76f9bad3b8f8ac9ba804da2c3a
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf gafgyt

Intelligence


File Origin
# of uploads :
2
# of downloads :
79
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Verdict:
Malware
Maliciousness:

Behaviour
Runs as daemon
Sends data to a server
Manages services
Sets a written file as executable
Creating a file in the %temp% directory
Receives data from a server
Connection attempt
Launching a process
Deleting a recently created file
Creating a file
Collects information on the CPU
Changes the time when the file was created, accessed, or modified
Opens a port
Kills processes
Changes access rights for a written file
Substitutes an application name
Creates or modifies files in /cron to set up autorun
Deleting of the original file
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
base64 gcc
Verdict:
Malicious
File Type:
elf.64.le
First seen:
2026-07-07T17:08:00Z UTC
Last seen:
2026-07-09T12:58:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=00d01240-1f00-0000-2ff8-953b45140000 pid=5189 /usr/bin/sudo guuid=bb90f847-1f00-0000-2ff8-953b46140000 pid=5190 /tmp/sample.bin guuid=00d01240-1f00-0000-2ff8-953b45140000 pid=5189->guuid=bb90f847-1f00-0000-2ff8-953b46140000 pid=5190 execve guuid=88a6da49-1f00-0000-2ff8-953b47140000 pid=5191 /tmp/sample.bin zombie guuid=bb90f847-1f00-0000-2ff8-953b46140000 pid=5190->guuid=88a6da49-1f00-0000-2ff8-953b47140000 pid=5191 clone guuid=7acf0d4a-1f00-0000-2ff8-953b48140000 pid=5192 /tmp/sample.bin delete-file net send-data write-config write-file zombie guuid=88a6da49-1f00-0000-2ff8-953b47140000 pid=5191->guuid=7acf0d4a-1f00-0000-2ff8-953b48140000 pid=5192 clone ffee5cfb-bb94-52c2-8935-ae3a87e774db 127.0.0.1:42780 guuid=7acf0d4a-1f00-0000-2ff8-953b48140000 pid=5192->ffee5cfb-bb94-52c2-8935-ae3a87e774db con 82b03cd2-8196-5a85-bbf6-6eae5f31c4aa 91.92.40.118:443 guuid=7acf0d4a-1f00-0000-2ff8-953b48140000 pid=5192->82b03cd2-8196-5a85-bbf6-6eae5f31c4aa send: 272B guuid=2d370c4b-1f00-0000-2ff8-953b49140000 pid=5193 /tmp/sample.bin guuid=7acf0d4a-1f00-0000-2ff8-953b48140000 pid=5192->guuid=2d370c4b-1f00-0000-2ff8-953b49140000 pid=5193 clone guuid=782e804b-1f00-0000-2ff8-953b4b140000 pid=5195 /usr/bin/dash guuid=7acf0d4a-1f00-0000-2ff8-953b48140000 pid=5192->guuid=782e804b-1f00-0000-2ff8-953b4b140000 pid=5195 execve guuid=20532bb0-1f00-0000-2ff8-953b61140000 pid=5217 /usr/bin/dash guuid=7acf0d4a-1f00-0000-2ff8-953b48140000 pid=5192->guuid=20532bb0-1f00-0000-2ff8-953b61140000 pid=5217 execve guuid=0c4999f9-1f00-0000-2ff8-953b80140000 pid=5248 /usr/bin/dash guuid=7acf0d4a-1f00-0000-2ff8-953b48140000 pid=5192->guuid=0c4999f9-1f00-0000-2ff8-953b80140000 pid=5248 execve guuid=eacfe2f9-1f00-0000-2ff8-953b82140000 pid=5250 /usr/bin/dash guuid=7acf0d4a-1f00-0000-2ff8-953b48140000 pid=5192->guuid=eacfe2f9-1f00-0000-2ff8-953b82140000 pid=5250 execve guuid=9cc1274b-1f00-0000-2ff8-953b4a140000 pid=5194 /tmp/sample.bin guuid=2d370c4b-1f00-0000-2ff8-953b49140000 pid=5193->guuid=9cc1274b-1f00-0000-2ff8-953b4a140000 pid=5194 clone guuid=a9ab3efa-1f00-0000-2ff8-953b84140000 pid=5252 /tmp/sample.bin guuid=2d370c4b-1f00-0000-2ff8-953b49140000 pid=5193->guuid=a9ab3efa-1f00-0000-2ff8-953b84140000 pid=5252 clone guuid=e22a784c-1f00-0000-2ff8-953b4c140000 pid=5196 /usr/bin/systemctl guuid=782e804b-1f00-0000-2ff8-953b4b140000 pid=5195->guuid=e22a784c-1f00-0000-2ff8-953b4c140000 pid=5196 execve guuid=f6d461b0-1f00-0000-2ff8-953b62140000 pid=5218 /usr/bin/systemctl guuid=20532bb0-1f00-0000-2ff8-953b61140000 pid=5217->guuid=f6d461b0-1f00-0000-2ff8-953b62140000 pid=5218 execve guuid=7a0ce1ec-1f00-0000-2ff8-953b79140000 pid=5241 /usr/bin/dash guuid=64aac0f6-1f00-0000-2ff8-953b7c140000 pid=5244 /tmp/.k guuid=7a0ce1ec-1f00-0000-2ff8-953b79140000 pid=5241->guuid=64aac0f6-1f00-0000-2ff8-953b7c140000 pid=5244 execve guuid=7c2650f7-1f00-0000-2ff8-953b7d140000 pid=5245 /tmp/.k zombie guuid=64aac0f6-1f00-0000-2ff8-953b7c140000 pid=5244->guuid=7c2650f7-1f00-0000-2ff8-953b7d140000 pid=5245 clone guuid=577262f7-1f00-0000-2ff8-953b7f140000 pid=5247 /tmp/.k net send-data write-file zombie guuid=7c2650f7-1f00-0000-2ff8-953b7d140000 pid=5245->guuid=577262f7-1f00-0000-2ff8-953b7f140000 pid=5247 clone guuid=577262f7-1f00-0000-2ff8-953b7f140000 pid=5247->ffee5cfb-bb94-52c2-8935-ae3a87e774db send: 15B guuid=4447c3f9-1f00-0000-2ff8-953b81140000 pid=5249 /usr/bin/dash guuid=0c4999f9-1f00-0000-2ff8-953b80140000 pid=5248->guuid=4447c3f9-1f00-0000-2ff8-953b81140000 pid=5249 clone guuid=ac6e26fa-1f00-0000-2ff8-953b83140000 pid=5251 /usr/bin/dash guuid=eacfe2f9-1f00-0000-2ff8-953b82140000 pid=5250->guuid=ac6e26fa-1f00-0000-2ff8-953b83140000 pid=5251 clone
Result
Threat name:
Mirai, Xmrig
Detection:
malicious
Classification:
troj.spyw.evad.mine
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Drops invisible ELF files
Executes itself again with its parent PID as an argument (indicative of hampering debugging)
Executes the "crontab" command typically for achieving persistence
Found strings related to Crypto-Mining
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Opens /sys/class/net/* files useful for querying network interface information
Sample deletes itself
Sample tries to persist itself using cron
Yara detected Mirai
Yara detected Xmrig cryptocurrency miner
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1938985 Sample: kworkerd.elf Startdate: 08/07/2026 Architecture: LINUX Score: 100 71 91.92.40.118, 443, 45634, 53202 TODYL-CLOUD-TodylIncUS Bulgaria 2->71 77 Malicious sample detected (through community Yara rule) 2->77 79 Antivirus detection for dropped file 2->79 81 Antivirus / Scanner detection for submitted sample 2->81 83 3 other signatures 2->83 10 kworkerd.elf 2->10         started        13 systemd sh 2->13         started        15 systemd snapd-env-generator 2->15         started        17 systemd snapd-env-generator 2->17         started        signatures3 process4 signatures5 87 Found strings related to Crypto-Mining 10->87 19 kworkerd.elf 10->19         started        21 sh sh 13->21         started        23 sh wget 13->23         started        26 sh rm 13->26         started        process6 file7 28 kworkerd.elf 19->28         started        31 sh wget 21->31         started        34 sh .k 21->34         started        36 sh chmod 21->36         started        67 /tmp/..redis-sentinel, POSIX 23->67 dropped process8 file9 89 Opens /sys/class/net/* files useful for querying network interface information 28->89 91 Sample deletes itself 28->91 38 kworkerd.elf sh 28->38         started        41 kworkerd.elf sh 28->41         started        43 kworkerd.elf sh 28->43         started        47 2 other processes 28->47 69 /tmp/.k, ELF 31->69 dropped 93 Drops invisible ELF files 31->93 45 .k 34->45         started        signatures10 process11 signatures12 85 Executes itself again with its parent PID as an argument (indicative of hampering debugging) 38->85 49 sh crontab 38->49         started        53 sh crontab 41->53         started        55 sh systemctl 43->55         started        57 .k 45->57         started        59 sh systemctl 47->59         started        61 kworkerd.elf 47->61         started        63 kworkerd.elf 47->63         started        process13 file14 65 /var/spool/cron/crontabs/tmp.BcS9Zj, ASCII 49->65 dropped 73 Sample tries to persist itself using cron 49->73 75 Executes the "crontab" command typically for achieving persistence 49->75 signatures15
Threat name:
Linux.Backdoor.Gafgyt
Status:
Malicious
First seen:
2026-07-07 20:07:02 UTC
File Type:
ELF64 Little (Exe)
AV detection:
16 of 24 (66.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Creates/modifies Cron job
Enumerates active TCP sockets
Enumerates running processes
Modifies systemd
Reads MAC address of network interface
Deletes itself
Modifies Watchdog functionality
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ELF_Toriilike_persist
Author:4r4
Description:Detects Torii IoT Botnet (stealthier Mirai alternative)
Reference:Identified via researched data
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:Linux_Trojan_Gafgyt_0cd591cd
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_33b4111a
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_620087b9
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_807911a2
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_9e9530a7
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_a33a8363
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_d0c57a2e
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_d4227dbf
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_d996d335
Author:Elastic Security
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

elf 05686c56837324d1bbb9b98c331bd689af81de4a27c52a4d84ace7e25302e111

(this sample)

Comments