MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 09e4f7821407b5ab5129ddda4fc15462bb9ccf8353c03dafd206fb464ec0cb91. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 09e4f7821407b5ab5129ddda4fc15462bb9ccf8353c03dafd206fb464ec0cb91
SHA3-384 hash: f0fb0076b323d5ae0adc3b62cb03370e738cfaef1ba1a4f103064230bd3679c7f078490528ecc0fe7a968c30b42e1137
SHA1 hash: f45f205db20cec4864bfb3af293d7899d965ad91
MD5 hash: 6dc274394bdc5a3c1cbe89ef03ca4e79
humanhash: muppet-sink-jig-rugby
File name:bb.sh
Download: download sample
Signature Gafgyt
File size:1'140 bytes
First seen:2025-06-20 23:18:27 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:2GxnGDkV7IG7RGwEGVNI1FIGEUGFG+uGJS8GAIGFGc6GXKWGcaoaTao5v:2iyJqRKxIquWmrRImf605iZ2ox
TLSH T1EC214ADAA0E846034411CE1AB2A9D8D874F4E7FF527F5F6D7CEC04E9529AA48701CEE4
Magika shell
Reporter abuse_ch
Tags:gafgyt sh
URLMalware sample (SHA256 hash)SignatureTags
http://31.56.39.249/D.mips134d4d68baa03e4c7f3a32f5c02e728c1e2d05d6fe654efdce0c3eca60f3b0a9 Miraimirai opendir
http://31.56.39.249/D.mpsl8dd53502cdd743c4070b92920edfc5690a2fded42100d6d49a2a5ef201b3ab88 Miraimirai opendir
http://31.56.39.249/D.sh4d85eaea3a5dd3160878d5c270cc9b3615cb12239d1928f6598230d7c326e0bf7 Miraimirai opendir
http://31.56.39.249/D.x862e3eb8ae3aa8d76aa7c83f84f3ac81f30992a3de4019223c1f0c6931c9c1c279 Miraimirai opendir
http://31.56.39.249/D.arm68e3dc5ac028d168e5945e4b476393e3ba7d16eef6eb94c80ad6424a5fe7da8d0 Miraimirai opendir
http://31.56.39.249/D.i686e8f77574c12c1a6da6b2e82b64bf173f3631a12b8757d61d8e4be62a5a9298aa Miraimirai opendir
http://31.56.39.249/D.ppccefb739ab85e4fb068ab093f0a234c67df4a4e8aaab3eb4da3877e39377c8eb3 Miraimirai opendir
http://31.56.39.249/D.i586d43271f4ab46dc29f86386e0cc8804279ad96c7ba05232e8822a263d90390da4 Miraimirai opendir
http://31.56.39.249/D.m68kbb213cbe556628ed7cf44c93e8146e84102c6e5ba97cab4051ebcd4aad6061dd Miraimirai opendir
http://31.56.39.249/D.sparcd0e4e37094d31751b41d3330af4e7323120aee83cc48753491a26ab0c4e2593f Miraimirai opendir
http://31.56.39.249/D.arm42b052507f5b20d839b8f14b4fa906b205c38a90b7e4f02c01011c6a02064a3ec Gafgytgafgyt opendir
http://31.56.39.249/D.arm5db905b9f8900c31136c9c975cbd347574f8d5adfc227766f3e2bb2d1b7adb0b1 Gafgytgafgyt opendir
http://31.56.39.249/D.arm78da89673b756bad9c10f9e4058aa732247d9c2f6d39bdd703f5621aa2bf3c758 Miraimirai opendir
http://31.56.39.249/D.ppc440fpn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
96
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
94.9%
Tags:
downloader trojan agent
Status:
terminated
Behavior Graph:
%3 guuid=e8d6d9a9-1900-0000-107f-c1a786090000 pid=2438 /usr/bin/sudo guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442 /tmp/sample.bin guuid=e8d6d9a9-1900-0000-107f-c1a786090000 pid=2438->guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442 execve guuid=713050b3-1900-0000-107f-c1a78c090000 pid=2444 /usr/bin/wget net send-data write-file guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=713050b3-1900-0000-107f-c1a78c090000 pid=2444 execve guuid=b1e717bc-1900-0000-107f-c1a799090000 pid=2457 /usr/bin/chmod guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=b1e717bc-1900-0000-107f-c1a799090000 pid=2457 execve guuid=112d59bc-1900-0000-107f-c1a79b090000 pid=2459 /usr/bin/bash guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=112d59bc-1900-0000-107f-c1a79b090000 pid=2459 clone guuid=7f8942bd-1900-0000-107f-c1a79f090000 pid=2463 /usr/bin/rm delete-file guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=7f8942bd-1900-0000-107f-c1a79f090000 pid=2463 execve guuid=9cb59ebd-1900-0000-107f-c1a7a2090000 pid=2466 /usr/bin/wget net send-data write-file guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=9cb59ebd-1900-0000-107f-c1a7a2090000 pid=2466 execve guuid=8a5e87c3-1900-0000-107f-c1a7b0090000 pid=2480 /usr/bin/chmod guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=8a5e87c3-1900-0000-107f-c1a7b0090000 pid=2480 execve guuid=e8aecdc3-1900-0000-107f-c1a7b2090000 pid=2482 /usr/bin/bash guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=e8aecdc3-1900-0000-107f-c1a7b2090000 pid=2482 clone guuid=47e575c4-1900-0000-107f-c1a7b5090000 pid=2485 /usr/bin/rm delete-file guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=47e575c4-1900-0000-107f-c1a7b5090000 pid=2485 execve guuid=599fdcc4-1900-0000-107f-c1a7b7090000 pid=2487 /usr/bin/wget net send-data write-file guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=599fdcc4-1900-0000-107f-c1a7b7090000 pid=2487 execve guuid=6a9aecc9-1900-0000-107f-c1a7be090000 pid=2494 /usr/bin/chmod guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=6a9aecc9-1900-0000-107f-c1a7be090000 pid=2494 execve guuid=27c731ca-1900-0000-107f-c1a7c0090000 pid=2496 /usr/bin/bash guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=27c731ca-1900-0000-107f-c1a7c0090000 pid=2496 clone guuid=73e2bbca-1900-0000-107f-c1a7c4090000 pid=2500 /usr/bin/rm delete-file guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=73e2bbca-1900-0000-107f-c1a7c4090000 pid=2500 execve guuid=4d611ccb-1900-0000-107f-c1a7c6090000 pid=2502 /usr/bin/wget net send-data write-file guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=4d611ccb-1900-0000-107f-c1a7c6090000 pid=2502 execve guuid=6d3383d0-1900-0000-107f-c1a7d2090000 pid=2514 /usr/bin/chmod guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=6d3383d0-1900-0000-107f-c1a7d2090000 pid=2514 execve guuid=107ecfd0-1900-0000-107f-c1a7d4090000 pid=2516 /D.x86 net guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=107ecfd0-1900-0000-107f-c1a7d4090000 pid=2516 execve guuid=265619d1-1900-0000-107f-c1a7d7090000 pid=2519 /usr/bin/rm delete-file guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=265619d1-1900-0000-107f-c1a7d7090000 pid=2519 execve guuid=239570d1-1900-0000-107f-c1a7da090000 pid=2522 /usr/bin/wget net send-data write-file guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=239570d1-1900-0000-107f-c1a7da090000 pid=2522 execve guuid=9eb84dd7-1900-0000-107f-c1a7e7090000 pid=2535 /usr/bin/chmod guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=9eb84dd7-1900-0000-107f-c1a7e7090000 pid=2535 execve guuid=ad76bbd7-1900-0000-107f-c1a7e8090000 pid=2536 /usr/bin/bash guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=ad76bbd7-1900-0000-107f-c1a7e8090000 pid=2536 clone guuid=557fa6d8-1900-0000-107f-c1a7eb090000 pid=2539 /usr/bin/rm delete-file guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=557fa6d8-1900-0000-107f-c1a7eb090000 pid=2539 execve guuid=35310fd9-1900-0000-107f-c1a7ec090000 pid=2540 /usr/bin/wget net send-data write-file guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=35310fd9-1900-0000-107f-c1a7ec090000 pid=2540 execve guuid=75c4f1dd-1900-0000-107f-c1a7f9090000 pid=2553 /usr/bin/chmod guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=75c4f1dd-1900-0000-107f-c1a7f9090000 pid=2553 execve guuid=a7304ede-1900-0000-107f-c1a7fb090000 pid=2555 /D.i686 net guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=a7304ede-1900-0000-107f-c1a7fb090000 pid=2555 execve guuid=2c7972df-1900-0000-107f-c1a7010a0000 pid=2561 /usr/bin/rm delete-file guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=2c7972df-1900-0000-107f-c1a7010a0000 pid=2561 execve guuid=61aae0df-1900-0000-107f-c1a7040a0000 pid=2564 /usr/bin/wget net send-data write-file guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=61aae0df-1900-0000-107f-c1a7040a0000 pid=2564 execve guuid=eb7006e7-1900-0000-107f-c1a7160a0000 pid=2582 /usr/bin/chmod guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=eb7006e7-1900-0000-107f-c1a7160a0000 pid=2582 execve guuid=26fa5ee7-1900-0000-107f-c1a7180a0000 pid=2584 /usr/bin/bash guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=26fa5ee7-1900-0000-107f-c1a7180a0000 pid=2584 clone guuid=33cc10e9-1900-0000-107f-c1a71c0a0000 pid=2588 /usr/bin/rm delete-file guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=33cc10e9-1900-0000-107f-c1a71c0a0000 pid=2588 execve guuid=307e6ee9-1900-0000-107f-c1a71e0a0000 pid=2590 /usr/bin/wget net send-data write-file guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=307e6ee9-1900-0000-107f-c1a71e0a0000 pid=2590 execve guuid=8ff7efee-1900-0000-107f-c1a7300a0000 pid=2608 /usr/bin/chmod guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=8ff7efee-1900-0000-107f-c1a7300a0000 pid=2608 execve guuid=64843aef-1900-0000-107f-c1a7320a0000 pid=2610 /D.i586 net guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=64843aef-1900-0000-107f-c1a7320a0000 pid=2610 execve guuid=a8ee77f0-1900-0000-107f-c1a73a0a0000 pid=2618 /usr/bin/rm delete-file guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=a8ee77f0-1900-0000-107f-c1a73a0a0000 pid=2618 execve guuid=0452bff0-1900-0000-107f-c1a73c0a0000 pid=2620 /usr/bin/wget net send-data write-file guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=0452bff0-1900-0000-107f-c1a73c0a0000 pid=2620 execve guuid=ab9343f6-1900-0000-107f-c1a74e0a0000 pid=2638 /usr/bin/chmod guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=ab9343f6-1900-0000-107f-c1a74e0a0000 pid=2638 execve guuid=d70daff6-1900-0000-107f-c1a7510a0000 pid=2641 /usr/bin/bash guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=d70daff6-1900-0000-107f-c1a7510a0000 pid=2641 clone guuid=1a0369f7-1900-0000-107f-c1a7550a0000 pid=2645 /usr/bin/rm delete-file guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=1a0369f7-1900-0000-107f-c1a7550a0000 pid=2645 execve guuid=626300f8-1900-0000-107f-c1a7580a0000 pid=2648 /usr/bin/wget net send-data write-file guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=626300f8-1900-0000-107f-c1a7580a0000 pid=2648 execve guuid=b73309fe-1900-0000-107f-c1a76d0a0000 pid=2669 /usr/bin/chmod guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=b73309fe-1900-0000-107f-c1a76d0a0000 pid=2669 execve guuid=dd4755fe-1900-0000-107f-c1a76f0a0000 pid=2671 /usr/bin/bash guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=dd4755fe-1900-0000-107f-c1a76f0a0000 pid=2671 clone guuid=96eb14ff-1900-0000-107f-c1a7730a0000 pid=2675 /usr/bin/rm delete-file guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=96eb14ff-1900-0000-107f-c1a7730a0000 pid=2675 execve guuid=b24162ff-1900-0000-107f-c1a7750a0000 pid=2677 /usr/bin/wget net send-data write-file guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=b24162ff-1900-0000-107f-c1a7750a0000 pid=2677 execve guuid=19b2e105-1a00-0000-107f-c1a7860a0000 pid=2694 /usr/bin/chmod guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=19b2e105-1a00-0000-107f-c1a7860a0000 pid=2694 execve guuid=0d8c3c06-1a00-0000-107f-c1a7870a0000 pid=2695 /usr/bin/bash guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=0d8c3c06-1a00-0000-107f-c1a7870a0000 pid=2695 clone guuid=91521507-1a00-0000-107f-c1a78c0a0000 pid=2700 /usr/bin/rm delete-file guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=91521507-1a00-0000-107f-c1a78c0a0000 pid=2700 execve guuid=fe605d07-1a00-0000-107f-c1a78e0a0000 pid=2702 /usr/bin/wget net send-data write-file guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=fe605d07-1a00-0000-107f-c1a78e0a0000 pid=2702 execve guuid=b5abff0c-1a00-0000-107f-c1a7a00a0000 pid=2720 /usr/bin/chmod guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=b5abff0c-1a00-0000-107f-c1a7a00a0000 pid=2720 execve guuid=c55d600d-1a00-0000-107f-c1a7a20a0000 pid=2722 /usr/bin/bash guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=c55d600d-1a00-0000-107f-c1a7a20a0000 pid=2722 clone guuid=ab21f30e-1a00-0000-107f-c1a7a80a0000 pid=2728 /usr/bin/rm delete-file guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=ab21f30e-1a00-0000-107f-c1a7a80a0000 pid=2728 execve guuid=731c570f-1a00-0000-107f-c1a7aa0a0000 pid=2730 /usr/bin/wget net send-data write-file guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=731c570f-1a00-0000-107f-c1a7aa0a0000 pid=2730 execve guuid=166d3415-1a00-0000-107f-c1a7ba0a0000 pid=2746 /usr/bin/chmod guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=166d3415-1a00-0000-107f-c1a7ba0a0000 pid=2746 execve guuid=ef027215-1a00-0000-107f-c1a7bc0a0000 pid=2748 /usr/bin/bash guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=ef027215-1a00-0000-107f-c1a7bc0a0000 pid=2748 clone guuid=9a3c1016-1a00-0000-107f-c1a7c00a0000 pid=2752 /usr/bin/rm delete-file guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=9a3c1016-1a00-0000-107f-c1a7c00a0000 pid=2752 execve guuid=defc7a16-1a00-0000-107f-c1a7c20a0000 pid=2754 /usr/bin/wget net send-data guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=defc7a16-1a00-0000-107f-c1a7c20a0000 pid=2754 execve guuid=525a8719-1a00-0000-107f-c1a7cc0a0000 pid=2764 /usr/bin/chmod guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=525a8719-1a00-0000-107f-c1a7cc0a0000 pid=2764 execve guuid=3d8af219-1a00-0000-107f-c1a7ce0a0000 pid=2766 /usr/bin/bash guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=3d8af219-1a00-0000-107f-c1a7ce0a0000 pid=2766 clone guuid=5d900e1a-1a00-0000-107f-c1a7cf0a0000 pid=2767 /usr/bin/rm guuid=9f7000ac-1900-0000-107f-c1a78a090000 pid=2442->guuid=5d900e1a-1a00-0000-107f-c1a7cf0a0000 pid=2767 execve ec4192e8-5288-5372-a2de-e40b6fa61ae6 31.56.39.249:80 guuid=713050b3-1900-0000-107f-c1a78c090000 pid=2444->ec4192e8-5288-5372-a2de-e40b6fa61ae6 send: 133B guuid=9cb59ebd-1900-0000-107f-c1a7a2090000 pid=2466->ec4192e8-5288-5372-a2de-e40b6fa61ae6 send: 133B guuid=599fdcc4-1900-0000-107f-c1a7b7090000 pid=2487->ec4192e8-5288-5372-a2de-e40b6fa61ae6 send: 132B guuid=4d611ccb-1900-0000-107f-c1a7c6090000 pid=2502->ec4192e8-5288-5372-a2de-e40b6fa61ae6 send: 132B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=107ecfd0-1900-0000-107f-c1a7d4090000 pid=2516->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4eb0f6d0-1900-0000-107f-c1a7d5090000 pid=2517 /D.x86 guuid=107ecfd0-1900-0000-107f-c1a7d4090000 pid=2516->guuid=4eb0f6d0-1900-0000-107f-c1a7d5090000 pid=2517 clone guuid=e81dfdd0-1900-0000-107f-c1a7d6090000 pid=2518 /D.x86 dns net send-data zombie guuid=4eb0f6d0-1900-0000-107f-c1a7d5090000 pid=2517->guuid=e81dfdd0-1900-0000-107f-c1a7d6090000 pid=2518 clone 40e180cd-ab99-5b38-9e4e-2558f124d4ce 31.56.39.249:455 guuid=e81dfdd0-1900-0000-107f-c1a7d6090000 pid=2518->40e180cd-ab99-5b38-9e4e-2558f124d4ce send: 109B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=e81dfdd0-1900-0000-107f-c1a7d6090000 pid=2518->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 38B guuid=239570d1-1900-0000-107f-c1a7da090000 pid=2522->ec4192e8-5288-5372-a2de-e40b6fa61ae6 send: 133B guuid=35310fd9-1900-0000-107f-c1a7ec090000 pid=2540->ec4192e8-5288-5372-a2de-e40b6fa61ae6 send: 133B guuid=a7304ede-1900-0000-107f-c1a7fb090000 pid=2555->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=386857df-1900-0000-107f-c1a7ff090000 pid=2559 /D.i686 guuid=a7304ede-1900-0000-107f-c1a7fb090000 pid=2555->guuid=386857df-1900-0000-107f-c1a7ff090000 pid=2559 clone guuid=9e245fdf-1900-0000-107f-c1a7000a0000 pid=2560 /D.i686 dns net send-data zombie guuid=386857df-1900-0000-107f-c1a7ff090000 pid=2559->guuid=9e245fdf-1900-0000-107f-c1a7000a0000 pid=2560 clone guuid=9e245fdf-1900-0000-107f-c1a7000a0000 pid=2560->40e180cd-ab99-5b38-9e4e-2558f124d4ce send: 99B guuid=9e245fdf-1900-0000-107f-c1a7000a0000 pid=2560->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 38B guuid=61aae0df-1900-0000-107f-c1a7040a0000 pid=2564->ec4192e8-5288-5372-a2de-e40b6fa61ae6 send: 132B guuid=307e6ee9-1900-0000-107f-c1a71e0a0000 pid=2590->ec4192e8-5288-5372-a2de-e40b6fa61ae6 send: 133B guuid=64843aef-1900-0000-107f-c1a7320a0000 pid=2610->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=22e555f0-1900-0000-107f-c1a7370a0000 pid=2615 /D.i586 guuid=64843aef-1900-0000-107f-c1a7320a0000 pid=2610->guuid=22e555f0-1900-0000-107f-c1a7370a0000 pid=2615 clone guuid=426f5ef0-1900-0000-107f-c1a7380a0000 pid=2616 /D.i586 dns net send-data zombie guuid=22e555f0-1900-0000-107f-c1a7370a0000 pid=2615->guuid=426f5ef0-1900-0000-107f-c1a7380a0000 pid=2616 clone guuid=426f5ef0-1900-0000-107f-c1a7380a0000 pid=2616->40e180cd-ab99-5b38-9e4e-2558f124d4ce send: 99B guuid=426f5ef0-1900-0000-107f-c1a7380a0000 pid=2616->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 38B guuid=0452bff0-1900-0000-107f-c1a73c0a0000 pid=2620->ec4192e8-5288-5372-a2de-e40b6fa61ae6 send: 133B guuid=626300f8-1900-0000-107f-c1a7580a0000 pid=2648->ec4192e8-5288-5372-a2de-e40b6fa61ae6 send: 134B guuid=b24162ff-1900-0000-107f-c1a7750a0000 pid=2677->ec4192e8-5288-5372-a2de-e40b6fa61ae6 send: 133B guuid=fe605d07-1a00-0000-107f-c1a78e0a0000 pid=2702->ec4192e8-5288-5372-a2de-e40b6fa61ae6 send: 133B guuid=731c570f-1a00-0000-107f-c1a7aa0a0000 pid=2730->ec4192e8-5288-5372-a2de-e40b6fa61ae6 send: 133B guuid=defc7a16-1a00-0000-107f-c1a7c20a0000 pid=2754->ec4192e8-5288-5372-a2de-e40b6fa61ae6 send: 137B
Threat name:
Script-Shell.Trojan.ShellLoader
Status:
Malicious
First seen:
2025-06-20 23:19:35 UTC
File Type:
Text (Shell)
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt botnet defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Reads system network configuration
Reads system routing table
File and Directory Permissions Modification
Executes dropped EXE
Detected Gafgyt variant
Gafgyt family
Gafgyt/Bashlite
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 09e4f7821407b5ab5129ddda4fc15462bb9ccf8353c03dafd206fb464ec0cb91

(this sample)

  
Delivery method
Distributed via web download

Comments