MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 206ed1f6b61827f4c3ad3eba9ff59579f1b4d71f838ba532a8f222a913a5d1f5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 4


Intelligence 4 IOCs YARA 3 File information Comments

SHA256 hash: 206ed1f6b61827f4c3ad3eba9ff59579f1b4d71f838ba532a8f222a913a5d1f5
SHA3-384 hash: 40407d7aaf20bec77b26c7087ce14081885f30b4d1e615f30c5928927285e56454ade23366905f9cc51afba5b624bcad
SHA1 hash: 378b8a6de9d24f9d8e00c2adbc4c2af3d4119ba8
MD5 hash: 3361a0e475502afa8b87d1a542306a3e
humanhash: berlin-juliet-batman-fifteen
File name:skid.sh
Download: download sample
Signature Gafgyt
File size:1'152 bytes
First seen:2026-02-06 13:59:37 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:v0Bchf0BohuYJ0bSms08nL0aFbWCJ0V20I5L0wNIlT:vychfyohuKyS3hnLtb1JS2H5LMT
TLSH T1342145DA11B6C5B42CA2EF5771B9874530C0A2A630E79F14ECEC38ED408CD187061EA3
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://216.239.104.59/skid.mips567efc0e2ca0ffcdc15952c3f7f8af8029d2e42626c09345dab933974364cbf8 Miraielf mirai ua-wget
http://216.239.104.59/skid.mpsl4f8dfac7243376ab1e024d88ec75205101d0348f4a69160d34ef733bc54a04ac Gafgytelf gafgyt ua-wget
http://216.239.104.59/skid.x864cb93f270b727d4968bcfeaf803f4ead48a43cedfe52c90b0141139381a55f64 Gafgytcensys elf gafgyt ua-wget
http://216.239.104.59/skid.ppc757e8a38ec8a9a619903b22a193b8077a6d2f2af71e28648d7640c35a990da84 Gafgytelf gafgyt ua-wget
http://216.239.104.59/skid.sparcde7008eee0827cb292fd9b11bc0fac34eeac5cca90abd577f0f3a2f0f03240a8 Gafgytelf gafgyt ua-wget
http://216.239.104.59/skid.arm46a4b22342dddff57c33c173e61a8494bcbc069b8d436f02093f310ca64f91537 Gafgytelf gafgyt ua-wget
http://216.239.104.59/skid.arm5e649ebf65eb37615639c2e100842864952f412fef172c60f332bafb4e3d5a102 Gafgytelf gafgyt ua-wget
http://216.239.104.59/skid.arm62b04ce9a9dbbd083bfbfd62d282eb9b8563854f1492d29b23b6ed5d4e2bef654 Gafgytcensys elf gafgyt ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
29
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Gathering data
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
Reads system network configuration
Reads system routing table
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 206ed1f6b61827f4c3ad3eba9ff59579f1b4d71f838ba532a8f222a913a5d1f5

(this sample)

  
Delivery method
Distributed via web download

Comments