MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 34aa88705b24066113d5ba0f35ceeed349305c575af82ae9711bcd93ccfb32e2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: 34aa88705b24066113d5ba0f35ceeed349305c575af82ae9711bcd93ccfb32e2
SHA3-384 hash: 2db29bcc2009c5559bf8068c612dc33bd46c3424635b1ec7ddcb0a724ff215d916d8d3d5223fd06c812dc6c71fe16422
SHA1 hash: bc759ea6f042d8f20eed486f5f55e3e84eb8ea00
MD5 hash: 3ec3dd98714c4dcbf650b2555ed4ce83
humanhash: low-quebec-beer-stairway
File name:lmips
Download: download sample
Signature Gafgyt
File size:88'908 bytes
First seen:2025-09-28 19:58:30 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 1536:k0UDeb9yoAxDSfnlvL6CTincwzyyLjDoMP9y48+l+ulx8tzf6Feo+ZnMVW7k:7ieRyhyyLjDoM/l+ulytzCgZnMUk
TLSH T1F093FA0E3E268FADF76D83344BB78E31935923D626D1C685F29CD3091E6424E541FBA8
telfhash t1bb11910c493813f4e7b21d9e6becfb76e44170db46226e338d00e99eab2d9419d01c1c
Magika elf
Reporter abuse_ch
Tags:elf gafgyt

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
base64
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
mips
Packer:
not packed
Botnet:
unknown
Number of open files:
0
Number of processes launched:
1
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
no suspicious findings
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Status:
terminated
Behavior Graph:
%3 guuid=be8a944b-1900-0000-3c52-6fc2f7130000 pid=5111 /usr/bin/sudo guuid=95df234f-1900-0000-3c52-6fc2f8130000 pid=5112 /tmp/sample.bin guuid=be8a944b-1900-0000-3c52-6fc2f7130000 pid=5111->guuid=95df234f-1900-0000-3c52-6fc2f8130000 pid=5112 execve
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Linux.Backdoor.Gafgyt
Status:
Malicious
First seen:
2025-09-28 19:59:23 UTC
File Type:
ELF32 Big (Exe)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
System Network Configuration Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_AllMal_Detector
Author:DiegoAnalytics
Description:CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

elf 34aa88705b24066113d5ba0f35ceeed349305c575af82ae9711bcd93ccfb32e2

(this sample)

  
Delivery method
Distributed via web download

Comments