MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 27a3f1fe57a508b7cf3dfde7f35725744529b7c29a38e1128682a11c04c69aad. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 27a3f1fe57a508b7cf3dfde7f35725744529b7c29a38e1128682a11c04c69aad
SHA3-384 hash: fcae83272e7bf8adf365324d0b8a8031e9df4023519ae16e83521314970614b89ed1f97223dd2cb7b5bb8145c7f07ee9
SHA1 hash: 108881c5fe5664f8d8966ac85c1d75f8fd797643
MD5 hash: df6a79f7147320373a182c0b701f36af
humanhash: single-butter-fix-four
File name:bins.sh
Download: download sample
Signature Gafgyt
File size:1'546 bytes
First seen:2025-02-07 22:51:13 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:BXOaxXPGwXVwFxUquLBXFsSX2wGGKmX4q/Xy4CZsiCvXp6OX5pJenJ+XyG1HXdpq:BXjX3XBlX7XzXDXy7qtvXPXPXHXdzktj
TLSH T123316DDF83D05500C5F9BE6EBE27FD80124CA1D2F8566FD9ACD82C39764DE4A7011A42
Magika shell
Reporter abuse_ch
Tags:gafgyt sh
URLMalware sample (SHA256 hash)SignatureTags
http://bins.freesite.host/bins/jackmymipsc5a252c6c7613e4a50ced47a624ed4ce3787b115518114a0555b31d9a63ea4e5 Gafgytelf gafgyt mirai
http://bins.freesite.host/bins/jackmymipselb56c148fa30ed9a70689592f126ccee72d0d557fc2f1837e29acbc23f4834ce2 Gafgytelf gafgyt
http://bins.freesite.host/bins/jackmysh4942b941595845f743dc56f8500d583e5279d947d1da1fce85ba6da2d68184b32 Gafgytelf gafgyt mirai
http://bins.freesite.host/bins/jackmyx866b64c98adacb31fa5f66578ac0160c9298cdc15ea9426e503f5f57663350abb9 Gafgytelf gafgyt mirai
http://bins.freesite.host/bins/jackmyarmv65de8cc1d8e0a6111d9df026906abf69b394a453c9a9e1928713532ccad07347a Gafgytelf gafgyt
http://bins.freesite.host/bins/jackmyi686864efd17093cf1fbe758e71b904737032162e1d2072fea0ac8e9a1ec3c9dd7aa Gafgytelf gafgyt
http://bins.freesite.host/bins/jackmypowerpc6227ee3d6de82a192485c5759e577a45e47d4680b4e1e0b3b103c9d0e9a2523a Gafgytelf gafgyt
http://bins.freesite.host/bins/jackmyi586d8ddcd876e8428facde0a83d30ca573ad821d32de42006a2262b500f877ea807 Gafgytelf gafgyt
http://bins.freesite.host/bins/jackmym86k2733ecac081356843673c91d29e0fb6e97da3d0d5853484e39466f1c2610618c Gafgytelf gafgyt
http://bins.freesite.host/bins/jackmysparc40c8fe7b6cce8e6a4f5bbeabaf4610eabf71dbd016a154674592a1293a190c5e Gafgytelf gafgyt
http://bins.freesite.host/bins/jackmyarmv4a9aca166b0102d703eaf6272ffac6e4d94f5bddd39db43d6115713152b257d54 Gafgytelf gafgyt
http://bins.freesite.host/bins/jackmyarmv58b39b83968fd19714c2f895c6eaed9c7a9b90ab538657653df6f3f65af0445ba Gafgytelf gafgyt
http://bins.freesite.host/bins/jackmypowerpc4408b39b83968fd19714c2f895c6eaed9c7a9b90ab538657653df6f3f65af0445ba Gafgytelf

Intelligence


File Origin
# of uploads :
1
# of downloads :
145
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
Win32.Trojan.Gafgyt
Status:
Malicious
First seen:
2025-02-07 21:40:13 UTC
File Type:
Text (Shell)
AV detection:
15 of 38 (39.47%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt botnet defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
File and Directory Permissions Modification
Executes dropped EXE
Detected Gafgyt variant
Gafgyt family
Gafgyt/Bashlite
Malware Config
C2 Extraction:
165.154.224.116:443
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 27a3f1fe57a508b7cf3dfde7f35725744529b7c29a38e1128682a11c04c69aad

(this sample)

  
Delivery method
Distributed via web download

Comments