MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 28dedd67eaeeb24ec4663e310d64bcac20becae4bf07b6425b49b245565b0fd6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 28dedd67eaeeb24ec4663e310d64bcac20becae4bf07b6425b49b245565b0fd6
SHA3-384 hash: 3bee5930a4a51b1162c0830b478f7ccc3936fdc9e3f0679de765b84b90f56443fb4a1854e2b37c57dbd7d72bfbed3ef1
SHA1 hash: 78d41b67743dbd39204d48ba03490faf3ef4bf62
MD5 hash: ebad383c140d6183f14b7035d03f6c6c
humanhash: purple-steak-yankee-delaware
File name:ipc
Download: download sample
Signature Gafgyt
File size:811 bytes
First seen:2025-01-03 06:51:22 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:v0FF5p0FDMp0FhTNaMp0FBWp0FLhp0FVNIh5sMp0FGKLKQ:UF5aDMaPFakaLhaVNIfsMaZKQ
TLSH T1290100DA317706B52CA2AD67B16E8420B1E5B28A54D4EF1E68DC34F5508DD24E000FD3
Magika shell
Reporter abuse_ch
Tags:gafgyt sh
URLMalware sample (SHA256 hash)SignatureTags
http://212.64.215.71/mipsafe1cc80e06d92bbe16070b220541a5edad0a767c9cf8aa566dc914a6ab66d60 Gafgytelf gafgyt
http://212.64.215.71/mpsl915dccaa387bdf81c0f3d87d150b7f626208ddbaf09316f06cf16574bbfd5f94 Gafgytelf gafgyt
http://212.64.215.71/x86_64n/an/an/a
http://212.64.215.71/arm45cd25892f0b330577ff4b00c2dd75a0787ddc7b7b97999c648f95c806a6d2fcf Miraielf mirai
http://212.64.215.71/arm569b3cda867879e6e8fa8ab62402473bfb1e1fba08b9ebf93225c71e7050abb4e Gafgytelf gafgyt
http://212.64.215.71/arm638868d291357511a937be546a172986f7625ff5f309cfec32f76e9897a76347c Gafgytelf gafgyt
http://212.64.215.71/arm7fc6fbc9d13e3b343ddb18350039e36cfaaf8aeda58d36bdedd1d1ce3402b40e1 Miraielf gafgyt mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
93
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug expand lolbin remote
Result
Verdict:
MALICIOUS
Threat name:
Win32.Trojan.Generic
Status:
Malicious
First seen:
2025-01-03 06:55:04 UTC
File Type:
Text (Shell)
AV detection:
10 of 23 (43.48%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 28dedd67eaeeb24ec4663e310d64bcac20becae4bf07b6425b49b245565b0fd6

(this sample)

  
Delivery method
Distributed via web download

Comments