MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 26418d383bfa8595b9d8ea45dc3b383442bca55451ceea3622b7da108b48d50d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 7


Intelligence 7 IOCs YARA 4 File information Comments

SHA256 hash: 26418d383bfa8595b9d8ea45dc3b383442bca55451ceea3622b7da108b48d50d
SHA3-384 hash: 3357d12d3632251e39561ef1a3041d2ebebaff609a22ff32d1a335c61ed9dca3a37d3143d7e1a5fbe38d1bed8b214c65
SHA1 hash: 1e5177a894c2c0c1462bb6f53afd057159905b6f
MD5 hash: f98cbe0fb007f5a822ec2c40b24b7179
humanhash: alaska-charlie-four-fillet
File name:xnxnxnxnxnxnxnxnx86_64xnxn
Download: download sample
Signature Gafgyt
File size:63'928 bytes
First seen:2026-08-06 20:42:23 UTC
Last seen:2026-08-07 00:53:52 UTC
File type: elf
MIME type:application/x-executable
ssdeep 1536:Mdcqm5iERozq3p7o8FwOA4zCKOFGUfKbeH6UhV/VukAQ9:MaHJgMo8FwOA4zUFGUO3UhbkQ9
TLSH T14D5302512ABCF83ACEE2D9390B6841E645DC9DB494C7600E43CD7CF84A0696CBE9C6D7
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter BlinkzSec
Tags:gafgyt UPX
File size (compressed) :63'928 bytes
File size (de-compressed) :136'064 bytes
Format:linux/amd64
Unpacked file: df9fc12451968b58a2c3eae0344b761963bdc8b70c6adfcec222193ee7d4634f

Intelligence


File Origin
# of uploads :
2
# of downloads :
52
Origin country :
CH CH
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file
Sends data to a server
Connection attempt
Locks files
Receives data from a server
Creating a file in the %temp% directory
Kills processes
Runs as daemon
DNS request
Substitutes an application name
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
packed upx
Status:
terminated
Behavior Graph:
%3 guuid=9ebd3884-1900-0000-234e-53bb42070000 pid=1858 /usr/bin/sudo guuid=05276587-1900-0000-234e-53bb49070000 pid=1865 /tmp/sample.bin write-file guuid=9ebd3884-1900-0000-234e-53bb42070000 pid=1858->guuid=05276587-1900-0000-234e-53bb49070000 pid=1865 execve guuid=c0dc0189-1900-0000-234e-53bb4f070000 pid=1871 /tmp/sample.bin zombie guuid=05276587-1900-0000-234e-53bb49070000 pid=1865->guuid=c0dc0189-1900-0000-234e-53bb4f070000 pid=1871 clone guuid=78a04289-1900-0000-234e-53bb50070000 pid=1872 /tmp/sample.bin net send-data zombie guuid=c0dc0189-1900-0000-234e-53bb4f070000 pid=1871->guuid=78a04289-1900-0000-234e-53bb50070000 pid=1872 clone dcdb0ae2-691b-5c5d-856c-315716177236 45.135.194.47:54128 guuid=78a04289-1900-0000-234e-53bb50070000 pid=1872->dcdb0ae2-691b-5c5d-856c-315716177236 send: 153B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=78a04289-1900-0000-234e-53bb50070000 pid=1872->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 38B guuid=78a04289-1900-0000-234e-53bb50070000 pid=1873 /tmp/sample.bin guuid=78a04289-1900-0000-234e-53bb50070000 pid=1872->guuid=78a04289-1900-0000-234e-53bb50070000 pid=1873 clone guuid=78a04289-1900-0000-234e-53bb50070000 pid=1874 /tmp/sample.bin zombie guuid=78a04289-1900-0000-234e-53bb50070000 pid=1872->guuid=78a04289-1900-0000-234e-53bb50070000 pid=1874 clone
Threat name:
Linux.Trojan.Gafgyt
Status:
Malicious
First seen:
2026-08-06 20:43:11 UTC
File Type:
ELF64 Little (Exe)
AV detection:
8 of 36 (22.22%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
antivm discovery linux upx
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Reads system network configuration
Checks hardware identifiers (DMI)
Enumerates active TCP sockets
Enumerates running processes
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:SUSP_ELF_LNX_UPX_Compressed_File
Author:Florian Roth (Nextron Systems)
Description:Detects a suspicious ELF binary with UPX compression
Reference:Internal Research
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:upx_packed_elf_v1
Author:RandomMalware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

elf 26418d383bfa8595b9d8ea45dc3b383442bca55451ceea3622b7da108b48d50d

(this sample)

  
Delivery method
Distributed via web download

Comments