🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 13ccc7aef514e8fc26eb656e3ff5cffaddb1e544f048af99ddef613c97ddbf18. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 13ccc7aef514e8fc26eb656e3ff5cffaddb1e544f048af99ddef613c97ddbf18
SHA3-384 hash: 0093179db6b2f943f5ac4873d57611592f460c1b5cf7adf3bb820b5df468b152292069c07cdef075154d368e24872b99
SHA1 hash: 9387b7ef33c278cd069c8dd8a585be16e72d850d
MD5 hash: 6bbf3b5eabf62b9c6eed0ebfa93a3e3d
humanhash: fifteen-echo-fifteen-mango
File name:Sakura.sh
Download: download sample
Signature Gafgyt
File size:2'111 bytes
First seen:2025-12-04 06:50:42 UTC
Last seen:2025-12-04 21:47:07 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vRqd8jRtttQdMR0YRLRRJ7RiT6RgCRMIRXL1Rl5NRMIRXxRWT:vRqd8jRtttQdMR0YRLRRJ7RiT6RgCRM5
TLSH T1AE41AED720960BF36D91D83732698894B9D4A08AA4C19F466CDD3EE488BEDECA404682
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://151.244.72.224/m-i.p-s.Sakura485600a97866207f946d6552fc71bdd876d7466ebe3f7c832c52399f538bcd2a Gafgytelf gafgyt ua-wget
http://151.244.72.224/m-p.s-l.Sakurad45961a0b0e771b04c578cd9068f56e694ec41062d85c88651e80b5823572ca7 Gafgytelf gafgyt ua-wget
http://151.244.72.224/s-h.4-.Sakuraa74908ea9a46e8676d4763c1c24d514fe75a24b8b815a78af2fb0766e279821a Gafgytelf gafgyt ua-wget
http://151.244.72.224/x-8.6-.Sakura4543f33125d0623caf587df3b1d70eeea9ba8b14fcc81cd75ebf3d803c560d86 Miraielf mirai ua-wget
http://151.244.72.224/a-r.m-6.Sakura2a32bd0d89f79561c3dfbc4d42cbb8e00a6aa5691b9edb604dd607a7389510fa Gafgytelf gafgyt ua-wget
http://151.244.72.224/x-3.2-.Sakuraa9b9301e75806ebf5e2e007b1ac6196d993a3cf0630394597f02f9e2be2eb461 Gafgytelf gafgyt ua-wget
http://151.244.72.224/a-r.m-7.Sakura4b192e426d8db3a1202638e0dc9055be97dab7a2d02fa2895b44e69fdc1d388d Gafgytelf gafgyt ua-wget
http://151.244.72.224/p-p.c-.Sakura0658c9f92e23f5b8914d511b3a29ce28b170d194343b8c3d6e22baf21aac6c90 Gafgytelf gafgyt ua-wget
http://151.244.72.224/i-5.8-6.Sakurae39ae8606f7fde8f7c4f6d05820c01c0d88761828c94de707c5fd8dac60f5434 Gafgytelf gafgyt ua-wget
http://151.244.72.224/m-6.8-k.Sakura367c3e32682736981ce62433391c3c526b9ba174bf26cc3958d981f97dcc50ba Gafgytelf gafgyt ua-wget
http://151.244.72.224/a-r.m-4.Sakura0658c9f92e23f5b8914d511b3a29ce28b170d194343b8c3d6e22baf21aac6c90 Gafgytelf gafgyt ua-wget
http://151.244.72.224/a-r.m-5.Sakuraa00db9f639ca5beb42be7f2e4b8ba48996d823c187492b8661408c0796c798cf Gafgytelf gafgyt ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
40
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive medusa mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-04T04:21:00Z UTC
Last seen:
2025-12-04T06:16:00Z UTC
Hits:
~10
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-12-04 06:26:36 UTC
File Type:
Text (Shell)
AV detection:
17 of 24 (70.83%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt botnet defense_evasion discovery linux
Behaviour
Writes file to tmp directory
Reads system network configuration
Reads system routing table
File and Directory Permissions Modification
Executes dropped EXE
Detected Gafgyt variant
Gafgyt family
Gafgyt/Bashlite
Malware Config
C2 Extraction:
151.244.72.224:606
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 13ccc7aef514e8fc26eb656e3ff5cffaddb1e544f048af99ddef613c97ddbf18

(this sample)

  
Delivery method
Distributed via web download

Comments