MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2cd72b85842a488f943cc099bacd2e8031d8b9c7c6011832fed6a7dbe9d2d60e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: 2cd72b85842a488f943cc099bacd2e8031d8b9c7c6011832fed6a7dbe9d2d60e
SHA3-384 hash: 190dbc4a7b7cf1f80986acb9a8c51d69645c73e19c4c17b1cdfd5f4ab5076591214b37f97a7eba949903b34330a8e3d7
SHA1 hash: acbf8745d446500d01bdbb920333ede919c5341c
MD5 hash: 885274b64ff300558e5ab2af040b006f
humanhash: eighteen-cola-lion-quiet
File name:skid.sh
Download: download sample
Signature Gafgyt
File size:1'171 bytes
First seen:2026-05-16 19:31:59 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:1zymchFzymohuezyuwzytntgUzybFbWq3zyuSzyDfzyfNIlT:1zhchFzhohuez7wzcntgUzobJ3z1SzoD
TLSH T12121E4C61172CAB8ACB2BF573674860878C1E1E670EB6F98F9DC35D6008CD157840EA3
Magika csv
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://94.26.106.137/skid.mipsa9db89581bbb13c07b93651ec1b129186e08384c3d93345b3fa8698e7fe8cf0f Gafgytgafgyt mirai opendir
http://94.26.106.137/skid.mpsl6266b0cb629d43b6b239e8e1a585e241cd59f28ced04d713bcbdc16f4dc82834 Gafgytgafgyt mirai opendir
http://94.26.106.137/skid.x861e42c3e553e95581d4be5f117024504ba1b87b79fd02b66648c431fc53b181a7 Miraimirai opendir
http://94.26.106.137/skid.ppcn/an/aelf ua-wget
http://94.26.106.137/skid.sparc57f8ef018a2bd1d5a69e59d03e061017152bb2515533d82308c23edaa0733648 Gafgytgafgyt mirai opendir
http://94.26.106.137/skid.arm49e9ce1bfe7cfe72c461e628fd87b487c33a59f4abf3f2b70f5f0548bdf233598 Gafgytgafgyt mirai opendir
http://94.26.106.137/skid.arm529ee40176680f7e702dd4a657c1468f610d50069e4ae193f7f12f42e02c05b21 Miraimirai opendir
http://94.26.106.137/skid.arm6495236a92ab2ff78cb92cecf472c523a3d8afb8a4d52aadcc4ae9ec627be32f2 Gafgytgafgyt mirai opendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
30
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
text
First seen:
2026-05-16T16:48:00Z UTC
Last seen:
2026-05-17T02:57:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=460e95ce-1a00-0000-774d-a1823e0b0000 pid=2878 /usr/bin/sudo guuid=70b359d1-1a00-0000-774d-a182480b0000 pid=2888 /tmp/sample.bin guuid=460e95ce-1a00-0000-774d-a1823e0b0000 pid=2878->guuid=70b359d1-1a00-0000-774d-a182480b0000 pid=2888 execve guuid=301fabd1-1a00-0000-774d-a182490b0000 pid=2889 /usr/bin/wget guuid=70b359d1-1a00-0000-774d-a182480b0000 pid=2888->guuid=301fabd1-1a00-0000-774d-a182490b0000 pid=2889 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-05-16 19:34:52 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  3/5
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 2cd72b85842a488f943cc099bacd2e8031d8b9c7c6011832fed6a7dbe9d2d60e

(this sample)

  
Delivery method
Distributed via web download

Comments