MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2e1b65a0332cecc8da414e544068667d570cf21aeec32d4d5147b006c227eed2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 2e1b65a0332cecc8da414e544068667d570cf21aeec32d4d5147b006c227eed2
SHA3-384 hash: d157ba27780ce7cb70a289bc46537aed7b666ba54f88f0f94049691299fea07f8826d6569c28791a851d5169a56350b3
SHA1 hash: 65cf0627f8a19cbb65bac33affb56ad8cd0a23d3
MD5 hash: bb9cd97d9ee104a47f8c39c02acbad92
humanhash: snake-potato-zebra-lima
File name:SecuriteInfo.com.Linux.Mirai.14849.22184
Download: download sample
Signature Gafgyt
File size:55'024 bytes
First seen:2020-05-20 07:56:47 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 768:/+AAMaui7foF752N4FNx5aW3VFdd7JNnpC5iTs6UbkPqgHmyJuPsB0ULnGhCaTXV:/+hMQ7gW8J/3VFdZXo4I6UYygNLyDM4j
TLSH 3133022243504995EED02D7202CE8B36B0C9FAA8274FABE663F1550F16C58FD4F1B1E9
Reporter SecuriteInfoCom
Tags:gafgyt

Intelligence


File Origin
# of uploads :
1
# of downloads :
89
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Linux.Trojan.Gafgyt
Status:
Malicious
First seen:
2020-02-11 18:35:00 UTC
File Type:
ELF32 Little (Exe)
AV detection:
8 of 28 (28.57%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

elf 2e1b65a0332cecc8da414e544068667d570cf21aeec32d4d5147b006c227eed2

(this sample)

  
Delivery method
Distributed via web download

Comments