MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 39b3a360c62dab5c94ee9774cc4d50aac3d0db8abd329f222f75312cb2c1700d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 39b3a360c62dab5c94ee9774cc4d50aac3d0db8abd329f222f75312cb2c1700d
SHA3-384 hash: c82cf3881394b994c2be771397f6e2fd3f3867cfe64ff6c6e8537414669e9872c477956af6cfe3eff543a6e9678b11a6
SHA1 hash: 912ecf5bed2d49b82f9f8c6d8679680a7e6a1897
MD5 hash: 2f6c603f3b8443f8acf4d8381ca18b84
humanhash: golf-twelve-kentucky-floor
File name:tplink
Download: download sample
Signature Gafgyt
File size:7'028 bytes
First seen:2025-05-15 02:21:56 UTC
Last seen:2025-05-16 02:30:21 UTC
File type: sh
MIME type:text/plain
ssdeep 96:NNJeC9F99P5Fhy3QaNpeKNlF93jTNTryHL27ywt4ouJ:4+c3QDA3kHLYywt4ouJ
TLSH T1CEE134CC3D914BBA0E1ADFE9E621C85AA44ED4C364908F192ABE20F8E9FDF047D14557
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://185.142.53.233/mips63e5d4c2ac320aa49bfc1c23e1a253c00ec5e51b4b64f0fb304c34f4d0a6fa56 Gafgytddos elf gafgyt mirai
http://185.142.53.233/mpsl1f20bd51306a7cd754a0d6864311ca2a4fc8def258607ba35285216eb39e6891 Gafgytddos elf gafgyt mirai
http://185.142.53.233/x8605e5afb5cf3997973ad7701749efddcc5876dcf7069d398c95c3e8dda1b2d088 Miraiddos elf mirai
http://185.142.53.233/i68618649e80c64bc1b3c27f82fb5b86424ac7d8b2c910dc10d888cdc1d4bd4db2bc Miraiddos elf mirai
http://185.142.53.233/sh4b2aae96dfe77848425790b7370da4c15fa7de04d3cb2c6469470c751bce0eb09 Gafgytgafgyt mirai ua-wget
http://185.142.53.233/ppc17277a6d4918a77790c1492d4595367a53249ad3e646589083488bba619b6fd3 Miraimirai ua-wget
http://185.142.53.233/arcn/an/amirai ua-wget
http://185.142.53.233/arm4e630d71a3ebf5faede6525d46ec1ce4880c2276b941e71f03fea47189efcbe4 Miraiddos elf mirai
http://185.142.53.233/arm571922b4599572f865e6446137409eddcca93ef567eeded9c2684c5adf9d33c72 Miraiddos elf mirai
http://185.142.53.233/arm6b1d10651ccda9afdfb1876f967df8b4f2971283e928dfcbc6f867abc58581dcb Miraiddos elf mirai
http://185.142.53.233/arm7b530d6edb5659f75331fac721a888aaae428a06d6b3f658b1b0c9d23c4b75ba0 Miraimirai ua-wget
ftp://5.142.53.233:8021/mipsn/an/an/a
ftp://5.142.53.233:8021/mpsln/an/an/a
ftp://5.142.53.233:8021/x86n/an/an/a
ftp://5.142.53.233:8021/i686n/an/an/a
ftp://5.142.53.233:8021/sh4n/an/an/a
ftp://5.142.53.233:8021/ppcn/an/an/a
ftp://5.142.53.233:8021/arcn/an/an/a
ftp://5.142.53.233:8021/armn/an/an/a
ftp://5.142.53.233:8021/arm5n/an/an/a
ftp://5.142.53.233:8021/arm6n/an/an/a
ftp://5.142.53.233:8021/arm7n/an/an/a

Intelligence


File Origin
# of uploads :
11
# of downloads :
102
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2025-05-15 05:26:47 UTC
File Type:
Text (Shell)
AV detection:
12 of 37 (32.43%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:UNK_install_script
Author:evilcel3ri
Description:Detects a suspicious behaviour in an bash installation script

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 39b3a360c62dab5c94ee9774cc4d50aac3d0db8abd329f222f75312cb2c1700d

(this sample)

  
Delivery method
Distributed via web download

Comments