MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1c86a16eeb7fe7cd72f14541896aa4f959129578156d9dd2f448b9111df33593. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 1c86a16eeb7fe7cd72f14541896aa4f959129578156d9dd2f448b9111df33593
SHA3-384 hash: 1cba7ed20bea5f2a3feddfbaa8ea215925987d52faafbbb00b2532486f0dc7284174750c6cd5834241e08b6bbd14ee5a
SHA1 hash: d20ef1dd5d1217a3da9bd3310a3d44ca87496272
MD5 hash: e0224a8dc4047a637632945fcec4d73c
humanhash: venus-echo-monkey-helium
File name:o
Download: download sample
Signature Gafgyt
File size:92 bytes
First seen:2026-01-28 16:30:11 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 3:L6FT7KDQNUCz6MRgFjpMPFGBzSEyLTUWOevn:L6FTODW6MmRpVI5v
TLSH T15AB012F730203404C408FD0498B20FAC105346C134840F0812F70624EC5810438B090C
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://109.104.155.24/mipse21b7bea60a9530514cc047e69acc0a4f8fcd4aa0b0b740b44420536df8db05d Gafgyt32-bit elf gafgyt Mozi

Intelligence


File Origin
# of uploads :
1
# of downloads :
55
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
base64 bash evasive lolbin
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=a14c7826-1800-0000-5e2a-e261880c0000 pid=3208 /usr/bin/sudo guuid=6bb8d829-1800-0000-5e2a-e2618a0c0000 pid=3210 /tmp/sample.bin guuid=a14c7826-1800-0000-5e2a-e261880c0000 pid=3208->guuid=6bb8d829-1800-0000-5e2a-e2618a0c0000 pid=3210 execve guuid=b76f222a-1800-0000-5e2a-e2618b0c0000 pid=3211 /usr/bin/rm guuid=6bb8d829-1800-0000-5e2a-e2618a0c0000 pid=3210->guuid=b76f222a-1800-0000-5e2a-e2618b0c0000 pid=3211 execve guuid=b8ff762a-1800-0000-5e2a-e2618c0c0000 pid=3212 /usr/bin/dash guuid=6bb8d829-1800-0000-5e2a-e2618a0c0000 pid=3210->guuid=b8ff762a-1800-0000-5e2a-e2618c0c0000 pid=3212 clone guuid=44f4912a-1800-0000-5e2a-e2618d0c0000 pid=3213 /usr/bin/chmod guuid=6bb8d829-1800-0000-5e2a-e2618a0c0000 pid=3210->guuid=44f4912a-1800-0000-5e2a-e2618d0c0000 pid=3213 execve guuid=c466a62b-1800-0000-5e2a-e2618e0c0000 pid=3214 /usr/bin/dash guuid=6bb8d829-1800-0000-5e2a-e2618a0c0000 pid=3210->guuid=c466a62b-1800-0000-5e2a-e2618e0c0000 pid=3214 clone
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 1c86a16eeb7fe7cd72f14541896aa4f959129578156d9dd2f448b9111df33593

(this sample)

Comments