MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1150d27a2f9e1bc4bd7e100fe6436a1318357963b6b1b25b381816e7f13e3904. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 1150d27a2f9e1bc4bd7e100fe6436a1318357963b6b1b25b381816e7f13e3904
SHA3-384 hash: 5037c18048ce286276e5b3511401d86fefc04a32e0ac3c8df73eaa3b0e1d78a1f3af7529e81931a3e732180772abc7aa
SHA1 hash: 8f54c9d8882545b2d80c553ede7227e6866a9ebd
MD5 hash: 7b7abe4aef23dffe334e229e5c025deb
humanhash: may-ack-tango-cat
File name:rondo.mips
Download: download sample
Signature Gafgyt
File size:159'148 bytes
First seen:2025-12-24 23:52:04 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 1536:FXekiaveCIoOC0r5waikF8hYZs/g3ideelbB014wzmCPl5B8TbDAtgIR5boIlgqM:F3vedCPmRkYsigIR5boapR7VjTcrAGu+
TLSH T134F3D80D6E224F7DF2B8873847B74F34A69D63DA12E1C685E1BCE1052E6024D257FB68
telfhash t1aa21a1284d7817e4b2296c5d195ceb76d2a335df3e166c238911d81eeb69b838d21c0c
Magika elf
Reporter abuse_ch
Tags:elf gafgyt

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
masquerade
Verdict:
Unknown
File Type:
elf.32.be
First seen:
2025-12-24T21:42:00Z UTC
Last seen:
2025-12-24T21:48:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=7f8b34c3-1600-0000-c111-d2712f0c0000 pid=3119 /usr/bin/sudo guuid=239536c5-1600-0000-c111-d271360c0000 pid=3126 /tmp/sample.bin guuid=7f8b34c3-1600-0000-c111-d2712f0c0000 pid=3119->guuid=239536c5-1600-0000-c111-d271360c0000 pid=3126 execve
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Linux.Backdoor.Gafgyt
Status:
Malicious
First seen:
2025-12-24 23:52:16 UTC
File Type:
ELF32 Big (Exe)
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
System Network Configuration Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

elf 1150d27a2f9e1bc4bd7e100fe6436a1318357963b6b1b25b381816e7f13e3904

(this sample)

  
Delivery method
Distributed via web download

Comments