MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1845fb1ac4245dd108d6abb39181134371695e425fd56d31f4f5cc61fd773f31. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 1845fb1ac4245dd108d6abb39181134371695e425fd56d31f4f5cc61fd773f31
SHA3-384 hash: 6eb2dbb2aff4fc0eee1f1aab82ab40b6c6a63187dbf1d5de9b5260b21a9fae17b74c5df36e26742e4b2959472fc28bd9
SHA1 hash: 4c7683ba69d6bda77c69df20f8892b407a6641a9
MD5 hash: 8cdddfbd2d5ba92eb387840efa1b7536
humanhash: spaghetti-massachusetts-spring-cola
File name:bins.sh
Download: download sample
Signature Gafgyt
File size:1'518 bytes
First seen:2025-02-01 18:41:53 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:7fWaLfnGafNwFxUquL7fdsDgfuwGGKvgfAq8gfq4CZsiCRfx63gfBpJenJgfKG1S:7OaLPGaVwFxUquL7Fsc2wGGKY4qBy4CN
TLSH T1F13178EF83909150C169BE5EBF21FD80221DE1C2F9472FCA6CD80C39764EE0AB012A42
Magika shell
Reporter abuse_ch
Tags:gafgyt sh
URLMalware sample (SHA256 hash)SignatureTags
http://bins.freesite.host/bins/jackmymipsc5a252c6c7613e4a50ced47a624ed4ce3787b115518114a0555b31d9a63ea4e5 Gafgytelf gafgyt mirai
http://bins.freesite.host/bins/jackmymipselb56c148fa30ed9a70689592f126ccee72d0d557fc2f1837e29acbc23f4834ce2 Gafgytelf gafgyt
http://bins.freesite.host/bins/jackmysh4942b941595845f743dc56f8500d583e5279d947d1da1fce85ba6da2d68184b32 Gafgytelf gafgyt mirai
http://bins.freesite.host/bins/jackmyx866b64c98adacb31fa5f66578ac0160c9298cdc15ea9426e503f5f57663350abb9 Gafgytelf gafgyt mirai
http://bins.freesite.host/bins/jackmyarmv65de8cc1d8e0a6111d9df026906abf69b394a453c9a9e1928713532ccad07347a Gafgytelf gafgyt
http://bins.freesite.host/bins/jackmyi686864efd17093cf1fbe758e71b904737032162e1d2072fea0ac8e9a1ec3c9dd7aa Gafgytelf gafgyt
http://bins.freesite.host/bins/jackmypowerpc6227ee3d6de82a192485c5759e577a45e47d4680b4e1e0b3b103c9d0e9a2523a Gafgytelf gafgyt
http://bins.freesite.host/bins/jackmyi586d8ddcd876e8428facde0a83d30ca573ad821d32de42006a2262b500f877ea807 Gafgytelf gafgyt
http://bins.freesite.host/bins/jackmym86k2733ecac081356843673c91d29e0fb6e97da3d0d5853484e39466f1c2610618c Gafgytelf gafgyt
http://bins.freesite.host/bins/jackmysparc40c8fe7b6cce8e6a4f5bbeabaf4610eabf71dbd016a154674592a1293a190c5e Gafgytelf gafgyt
http://bins.freesite.host/bins/jackmyarmv4a9aca166b0102d703eaf6272ffac6e4d94f5bddd39db43d6115713152b257d54 Gafgytelf gafgyt
http://bins.freesite.host/bins/jackmyarmv58b39b83968fd19714c2f895c6eaed9c7a9b90ab538657653df6f3f65af0445ba Gafgytelf gafgyt
http://bins.freesite.host/bins/jackmypowerpc4408b39b83968fd19714c2f895c6eaed9c7a9b90ab538657653df6f3f65af0445ba Gafgytelf

Intelligence


File Origin
# of uploads :
1
# of downloads :
96
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive lolbin remote
Result
Verdict:
MALICIOUS
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-02-01 18:42:20 UTC
File Type:
Text (Shell)
AV detection:
16 of 38 (42.11%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt botnet defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Reads system network configuration
Reads system routing table
File and Directory Permissions Modification
Executes dropped EXE
Detected Gafgyt variant
Gafgyt family
Gafgyt/Bashlite
Malware Config
C2 Extraction:
194.37.80.234:666
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 1845fb1ac4245dd108d6abb39181134371695e425fd56d31f4f5cc61fd773f31

(this sample)

  
Delivery method
Distributed via web download

Comments