MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 31c9e46df74fa306564967c80cf057bc28b282436ff68a5516c1652619081644. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 31c9e46df74fa306564967c80cf057bc28b282436ff68a5516c1652619081644
SHA3-384 hash: f0528302523bdda6e7726bb6d5ee16944d2b06d126147b364293480ab3f1e0881dba6867ae3ab0578a4d8ce69cec5df1
SHA1 hash: e0f664a6f06a271ef16eefd78d80d7a34fa3b1ad
MD5 hash: d84280cdba7dcd1f4e8162d94cb74f7c
humanhash: juliet-oregon-butter-sweet
File name:rondo.aqu.sh
Download: download sample
Signature Gafgyt
File size:10'876 bytes
First seen:2026-01-04 07:04:11 UTC
Last seen:2026-01-05 00:15:26 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 96:hiOfWVc1dZd4cjzlZ16EMvyK6tTVRei0E3abaOfORMnS5gf2NUeeCEcg2Ro+4z:hs9W7I1vVYTSPDCnO
TLSH T16F2229C433C202F726E56B4661B3837C5E4482E36163EFBBE57864B29BB0D4860DDB95
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://41.231.37.153/rondo.loln/an/aua-wget
http://41.231.37.153/rondo.x86_64a5f035343b91205375751e0fb4d828aef261532508ef80129ffe7a9ba8a30ed0 Gafgytgafgyt RondoDox ua-wget
http://41.231.37.153/rondo.i686293a3a492aef65a88cf5434ee66ad55875deb66885871c9199296e707fb17926 Miraimirai ua-wget
http://41.231.37.153/rondo.i58638b3192b7e792073bde272b917f53336ad35d17482d5140b362f697861bd2c55 Miraimirai ua-wget
http://41.231.37.153/rondo.i486f1beda333a121d1fc43ca60075f62a6e9848b5d9e41ef177d934ebc7138a696f Miraimirai ua-wget
http://41.231.37.153/rondo.armv6l29ed805642950a7709d058067ec1882d877beb02e67b56b673b5e2d2b17272d2 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.armv5l635916119ab6903aa6f8672e8c59d9c658c279b6fee9b7490abfff1b58395402 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.armv4l92a92f68af94dfc82046ebe54a51a639d972608d2516255250cd222ad2b8fddd Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.armv7lec6125b2e7dba1419d5cb0d0ffbcd40de93826062968999d29a933f1485249dc Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.powerpc852713af646fc9ebe10d87b98556f42763cd8490bcb855847a46e6db0fced634 Miraimirai ua-wget
http://41.231.37.153/rondo.powerpc-440fp2311ce1f03fd7a7c7b2130ebcd7cf84c346e22cec9e00749835746cfd2f2efa5 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.mips5075648683ceb6822b87509f97f7d15436d510feb0a019053084cb63eb44520d Gafgytgafgyt ua-wget
http://41.231.37.153/rondo.mipseld4d72de0e0335c9a3f3eec7cdfd93f7fcc5ee85fc1b8692b8fdab77355db7190 Gafgytgafgyt ua-wget
http://41.231.37.153/rondo.arc700a448a233d175276ab77aa4cf9fd63dd02f9e6fd5f4ee160ce99f177df7d27d11 Miraimirai ua-wget
http://41.231.37.153/rondo.sh487b5360fc1a9b326ab7cdece074614eb30e23bd0ff7b179cb121e29aac0edb31 Miraimirai ua-wget
http://41.231.37.153/rondo.sparc8ccaa9a601ec1a1750338b8074d60609b53cde76135f1761fd705428dd195bb7 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.m68k9aedf0f1ae99ae01eed2d8edec1dd9f2a2257435a91c6a57d4b368946b0f1d18 Miraimirai ua-wget
http://41.231.37.153/rondo.armebb335b5eeaf8ea4f275a66c22322e2f35a36707979aa430ea3dadc29564f3ba09 MiraiRondoDox ua-wget
http://41.231.37.153/rondo.armebhf4e7384185cdff726ae05bad052983c0b3854bd5a3a69897d980cacef2f9a06fc RondoDoxua-wget

Intelligence


File Origin
# of uploads :
3
# of downloads :
42
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive masquerade
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-04T05:15:00Z UTC
Last seen:
2026-01-04T22:36:00Z UTC
Hits:
~10
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-01-04 07:05:18 UTC
File Type:
Text (Shell)
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:xmrig antivm credential_access defense_evasion discovery execution linux miner persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to shm directory
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads CPU attributes
Reads process memory
Abuse Elevation Control Mechanism: Sudo and Sudo Caching
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Deletes log files
Enumerates running processes
Modifies init.d
Modifies rc script
Reads hardware information
Reads list of loaded kernel modules
Write file to user bin folder
Writes file to system bin folder
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Renames itself
XMRig Miner payload
Xmrig family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 31c9e46df74fa306564967c80cf057bc28b282436ff68a5516c1652619081644

(this sample)

  
Delivery method
Distributed via web download

Comments