MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 353a0834304c317795ced72984aa94138923405cf9873c1908d2dafe4e68b079. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments 1

SHA256 hash: 353a0834304c317795ced72984aa94138923405cf9873c1908d2dafe4e68b079
SHA3-384 hash: af8d0092c70368b2d1e6904eed8545d5e1b6d8c92b9be92a22e39544af5aaf9bd400f2edbf03169398b0eb62ccece20e
SHA1 hash: 77a37f4bc95b728c58800929f7ce42f7fa00c999
MD5 hash: bf315b74685804072b8f6321435deffa
humanhash: arkansas-aspen-victor-bakerloo
File name:bf315b74685804072b8f6321435deffa
Download: download sample
Signature Gafgyt
File size:45'748 bytes
First seen:2021-10-18 21:26:24 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 768:ruxA0wZJBmeWc3epNUaexXab40awS/D1yS3IobhX0WILLFnCx4uVcqgw02NWXrat:rueJBAG0U2P2/hyS371MLJG4u+qgw06N
TLSH T12823F111E2F11D31D66F2DF5C681E36323A93ECB36A140BA178DFE612D79B209540EE5
Reporter zbetcheckin
Tags:32 elf gafgyt powerpc

Intelligence


File Origin
# of uploads :
1
# of downloads :
105
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Linux.Trojan.Gafgyt
Status:
Malicious
First seen:
2021-10-18 21:27:08 UTC
AV detection:
10 of 45 (22.22%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

elf 353a0834304c317795ced72984aa94138923405cf9873c1908d2dafe4e68b079

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
zbet commented on 2021-10-18 21:26:25 UTC

url : hxxp://45.95.169.115/StableBins/ppc