MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3ac38c1708e7221ee617c9f80273d1d6dac3c2591f59b72bb9c1e9df1a87eff6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: 3ac38c1708e7221ee617c9f80273d1d6dac3c2591f59b72bb9c1e9df1a87eff6
SHA3-384 hash: f4e2ea2f0c59a89a7af487353ab2c0ae12be36c62487f9031f89f7d8de1a9154d265d6c44a2148307b91d6139acf59f3
SHA1 hash: 8b1b5ede0cd12983082e4afe78e3059da3f5f796
MD5 hash: ad9c3d380bb9d2a0380db85b572ebd8b
humanhash: pluto-queen-hamper-skylark
File name:bb.sh
Download: download sample
Signature Gafgyt
File size:2'050 bytes
First seen:2025-06-17 18:44:25 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:vGwKjeGWt3JGgFGZsGwNImksG5sGeGtsGxUGcJGeGYLGNKNGjaPaoaoGv:v5Kjeb/JFHlJfbLoUFJDjL+4lyZo4
TLSH T1A34114CA71E209727C60D917726F648435F0A69650F99F1AFCDD3CE941DED887008E93
Magika shell
Reporter abuse_ch
Tags:gafgyt sh
URLMalware sample (SHA256 hash)SignatureTags
http://31.56.39.249/Demon.mips823509b26a440736f00f76a3c627f6e472d183ecbf25cc5641dc1f22aef6f2be Miraimirai opendir
http://31.56.39.249/Demon.mpsl923ed9145bd6766f389229d43e3c195ed9df67de696ead3aa51f0df44e3429d8 Miraimirai opendir
http://31.56.39.249/Demon.sh44e02226f33804c4ad4ebbc2eaae1dff4c7efe8fb42f30e5ecd6a3380890a4308 Miraimirai opendir
http://31.56.39.249/Demon.x86507134ffeb79bcf993258948e08ed276cf25d5aa81896371c0bae3a4e884dfc5 Miraimirai opendir
http://31.56.39.249/Demon.arm6n/an/amirai opendir
http://31.56.39.249/Demon.i686103799224b5959e025e3c1adc674e29c6945848161bdb086bfb67e786ea0b136 Miraimirai opendir
http://31.56.39.249/Demon.ppce3140efa0122523ea82d0dc0be5a8eacc92a8e5a2972400d0095dc7fddbfb193 Miraimirai opendir
http://31.56.39.249/Demon.i586bd792b6302ec18d1dda59e5554bb719f2bc0de653bb02591922e19f30ab4f374 Miraimirai opendir
http://31.56.39.249/Demon.m68kd7f2b5605991a843979f97f585e5cd78659a07847acf10926a48bbfc8b14b7d4 Miraimirai opendir
http://31.56.39.249/Demon.sparc1a19b52722d1422f2e501a40b97f1bf9f73afd4d3261ec329c36e37a83b8af42 Miraimirai opendir
http://31.56.39.249/Demon.arm4c688bc41fdea54b2bc80ac803fc74949f4ac27304fb29d364b57d177afbed417 Gafgytgafgyt opendir
http://31.56.39.249/Demon.arm59169794a0fe58f80f6045d8773201538815956952c001a9abb22ad980e5e3987 Gafgytgafgyt opendir
http://31.56.39.249/Demon.arm7836a2bd687f6820e26017b30f011864f4b7274a53166e78d52c116757e37b998 Miraimirai opendir
http://31.56.39.249/Demon.ppc440fpn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
132
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.1%
Tags:
downloader trojan agent
Status:
terminated
Behavior Graph:
%3 guuid=1c77d1d5-1700-0000-5888-aa962a0c0000 pid=3114 /usr/bin/sudo guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121 /tmp/sample.bin guuid=1c77d1d5-1700-0000-5888-aa962a0c0000 pid=3114->guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121 execve guuid=049cfdd7-1700-0000-5888-aa96340c0000 pid=3124 /usr/bin/wget net send-data write-file guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=049cfdd7-1700-0000-5888-aa96340c0000 pid=3124 execve guuid=c95490e3-1700-0000-5888-aa96530c0000 pid=3155 /usr/bin/chmod guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=c95490e3-1700-0000-5888-aa96530c0000 pid=3155 execve guuid=973dfde3-1700-0000-5888-aa96540c0000 pid=3156 /usr/bin/bash guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=973dfde3-1700-0000-5888-aa96540c0000 pid=3156 clone guuid=41efbee4-1700-0000-5888-aa96560c0000 pid=3158 /usr/bin/rm delete-file guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=41efbee4-1700-0000-5888-aa96560c0000 pid=3158 execve guuid=fabd20e5-1700-0000-5888-aa96570c0000 pid=3159 /usr/bin/wget net send-data write-file guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=fabd20e5-1700-0000-5888-aa96570c0000 pid=3159 execve guuid=a9e09cef-1700-0000-5888-aa966c0c0000 pid=3180 /usr/bin/chmod guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=a9e09cef-1700-0000-5888-aa966c0c0000 pid=3180 execve guuid=196302f0-1700-0000-5888-aa966d0c0000 pid=3181 /usr/bin/bash guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=196302f0-1700-0000-5888-aa966d0c0000 pid=3181 clone guuid=f59cd2f0-1700-0000-5888-aa966f0c0000 pid=3183 /usr/bin/rm delete-file guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=f59cd2f0-1700-0000-5888-aa966f0c0000 pid=3183 execve guuid=7ffb4ef1-1700-0000-5888-aa96700c0000 pid=3184 /usr/bin/wget net send-data write-file guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=7ffb4ef1-1700-0000-5888-aa96700c0000 pid=3184 execve guuid=2ba34efb-1700-0000-5888-aa96710c0000 pid=3185 /usr/bin/chmod guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=2ba34efb-1700-0000-5888-aa96710c0000 pid=3185 execve guuid=b316aafb-1700-0000-5888-aa96720c0000 pid=3186 /usr/bin/bash guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=b316aafb-1700-0000-5888-aa96720c0000 pid=3186 clone guuid=2e996ffc-1700-0000-5888-aa96740c0000 pid=3188 /usr/bin/rm delete-file guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=2e996ffc-1700-0000-5888-aa96740c0000 pid=3188 execve guuid=523acefc-1700-0000-5888-aa96750c0000 pid=3189 /usr/bin/wget net send-data write-file guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=523acefc-1700-0000-5888-aa96750c0000 pid=3189 execve guuid=7f983807-1800-0000-5888-aa96840c0000 pid=3204 /usr/bin/chmod guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=7f983807-1800-0000-5888-aa96840c0000 pid=3204 execve guuid=a1fda407-1800-0000-5888-aa96850c0000 pid=3205 /tmp/Demon.x86 net guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=a1fda407-1800-0000-5888-aa96850c0000 pid=3205 execve guuid=c763f907-1800-0000-5888-aa968a0c0000 pid=3210 /usr/bin/rm delete-file guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=c763f907-1800-0000-5888-aa968a0c0000 pid=3210 execve guuid=05ff5c08-1800-0000-5888-aa968b0c0000 pid=3211 /usr/bin/wget net send-data write-file guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=05ff5c08-1800-0000-5888-aa968b0c0000 pid=3211 execve guuid=a5086014-1800-0000-5888-aa969a0c0000 pid=3226 /usr/bin/chmod guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=a5086014-1800-0000-5888-aa969a0c0000 pid=3226 execve guuid=6f54a614-1800-0000-5888-aa969c0c0000 pid=3228 /usr/bin/bash guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=6f54a614-1800-0000-5888-aa969c0c0000 pid=3228 clone guuid=1763b415-1800-0000-5888-aa96a00c0000 pid=3232 /usr/bin/rm delete-file guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=1763b415-1800-0000-5888-aa96a00c0000 pid=3232 execve guuid=b8d2b716-1800-0000-5888-aa96a20c0000 pid=3234 /usr/bin/wget net send-data write-file guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=b8d2b716-1800-0000-5888-aa96a20c0000 pid=3234 execve guuid=83d20e22-1800-0000-5888-aa96a50c0000 pid=3237 /usr/bin/chmod guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=83d20e22-1800-0000-5888-aa96a50c0000 pid=3237 execve guuid=34b00823-1800-0000-5888-aa96a60c0000 pid=3238 /tmp/Demon.i686 net guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=34b00823-1800-0000-5888-aa96a60c0000 pid=3238 execve guuid=f3206f25-1800-0000-5888-aa96a90c0000 pid=3241 /usr/bin/rm delete-file guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=f3206f25-1800-0000-5888-aa96a90c0000 pid=3241 execve guuid=4bc53526-1800-0000-5888-aa96aa0c0000 pid=3242 /usr/bin/wget net send-data write-file guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=4bc53526-1800-0000-5888-aa96aa0c0000 pid=3242 execve guuid=e46f9034-1800-0000-5888-aa96b90c0000 pid=3257 /usr/bin/chmod guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=e46f9034-1800-0000-5888-aa96b90c0000 pid=3257 execve guuid=fc67e034-1800-0000-5888-aa96ba0c0000 pid=3258 /usr/bin/bash guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=fc67e034-1800-0000-5888-aa96ba0c0000 pid=3258 clone guuid=b17a5236-1800-0000-5888-aa96bc0c0000 pid=3260 /usr/bin/rm delete-file guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=b17a5236-1800-0000-5888-aa96bc0c0000 pid=3260 execve guuid=3997bc36-1800-0000-5888-aa96bd0c0000 pid=3261 /usr/bin/wget net send-data write-file guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=3997bc36-1800-0000-5888-aa96bd0c0000 pid=3261 execve guuid=44a95441-1800-0000-5888-aa96c50c0000 pid=3269 /usr/bin/chmod guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=44a95441-1800-0000-5888-aa96c50c0000 pid=3269 execve guuid=69e4b041-1800-0000-5888-aa96c60c0000 pid=3270 /tmp/Demon.i586 net guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=69e4b041-1800-0000-5888-aa96c60c0000 pid=3270 execve guuid=b167c442-1800-0000-5888-aa96c90c0000 pid=3273 /usr/bin/rm delete-file guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=b167c442-1800-0000-5888-aa96c90c0000 pid=3273 execve guuid=924a1643-1800-0000-5888-aa96cb0c0000 pid=3275 /usr/bin/wget net send-data write-file guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=924a1643-1800-0000-5888-aa96cb0c0000 pid=3275 execve guuid=8d9c314d-1800-0000-5888-aa96dc0c0000 pid=3292 /usr/bin/chmod guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=8d9c314d-1800-0000-5888-aa96dc0c0000 pid=3292 execve guuid=12bd7c4d-1800-0000-5888-aa96de0c0000 pid=3294 /usr/bin/bash guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=12bd7c4d-1800-0000-5888-aa96de0c0000 pid=3294 clone guuid=e43e1b4e-1800-0000-5888-aa96e20c0000 pid=3298 /usr/bin/rm delete-file guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=e43e1b4e-1800-0000-5888-aa96e20c0000 pid=3298 execve guuid=c428704e-1800-0000-5888-aa96e40c0000 pid=3300 /usr/bin/wget net send-data write-file guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=c428704e-1800-0000-5888-aa96e40c0000 pid=3300 execve guuid=a9801159-1800-0000-5888-aa96f00c0000 pid=3312 /usr/bin/chmod guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=a9801159-1800-0000-5888-aa96f00c0000 pid=3312 execve guuid=11545d59-1800-0000-5888-aa96f20c0000 pid=3314 /usr/bin/bash guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=11545d59-1800-0000-5888-aa96f20c0000 pid=3314 clone guuid=77a0a85a-1800-0000-5888-aa96f60c0000 pid=3318 /usr/bin/rm delete-file guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=77a0a85a-1800-0000-5888-aa96f60c0000 pid=3318 execve guuid=6eb9405b-1800-0000-5888-aa96f90c0000 pid=3321 /usr/bin/wget net send-data write-file guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=6eb9405b-1800-0000-5888-aa96f90c0000 pid=3321 execve guuid=03ed3065-1800-0000-5888-aa96110d0000 pid=3345 /usr/bin/chmod guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=03ed3065-1800-0000-5888-aa96110d0000 pid=3345 execve guuid=36d87465-1800-0000-5888-aa96120d0000 pid=3346 /usr/bin/bash guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=36d87465-1800-0000-5888-aa96120d0000 pid=3346 clone guuid=4b2a7d66-1800-0000-5888-aa96160d0000 pid=3350 /usr/bin/rm delete-file guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=4b2a7d66-1800-0000-5888-aa96160d0000 pid=3350 execve guuid=67a8e566-1800-0000-5888-aa96190d0000 pid=3353 /usr/bin/wget net send-data write-file guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=67a8e566-1800-0000-5888-aa96190d0000 pid=3353 execve guuid=17f68471-1800-0000-5888-aa96300d0000 pid=3376 /usr/bin/chmod guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=17f68471-1800-0000-5888-aa96300d0000 pid=3376 execve guuid=7917e071-1800-0000-5888-aa96310d0000 pid=3377 /usr/bin/bash guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=7917e071-1800-0000-5888-aa96310d0000 pid=3377 clone guuid=f3897872-1800-0000-5888-aa96350d0000 pid=3381 /usr/bin/rm delete-file guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=f3897872-1800-0000-5888-aa96350d0000 pid=3381 execve guuid=8f25d272-1800-0000-5888-aa96370d0000 pid=3383 /usr/bin/wget net send-data write-file guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=8f25d272-1800-0000-5888-aa96370d0000 pid=3383 execve guuid=1f059c7e-1800-0000-5888-aa96400d0000 pid=3392 /usr/bin/chmod guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=1f059c7e-1800-0000-5888-aa96400d0000 pid=3392 execve guuid=cfa62b7f-1800-0000-5888-aa96420d0000 pid=3394 /usr/bin/bash guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=cfa62b7f-1800-0000-5888-aa96420d0000 pid=3394 clone guuid=b58b9381-1800-0000-5888-aa96490d0000 pid=3401 /usr/bin/rm delete-file guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=b58b9381-1800-0000-5888-aa96490d0000 pid=3401 execve guuid=707eef81-1800-0000-5888-aa964a0d0000 pid=3402 /usr/bin/wget net send-data guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=707eef81-1800-0000-5888-aa964a0d0000 pid=3402 execve guuid=cd0e7e87-1800-0000-5888-aa96560d0000 pid=3414 /usr/bin/chmod guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=cd0e7e87-1800-0000-5888-aa96560d0000 pid=3414 execve guuid=e6b5ca87-1800-0000-5888-aa96580d0000 pid=3416 /usr/bin/bash guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=e6b5ca87-1800-0000-5888-aa96580d0000 pid=3416 clone guuid=5ee1e387-1800-0000-5888-aa96590d0000 pid=3417 /usr/bin/rm guuid=260da2d7-1700-0000-5888-aa96310c0000 pid=3121->guuid=5ee1e387-1800-0000-5888-aa96590d0000 pid=3417 execve ec4192e8-5288-5372-a2de-e40b6fa61ae6 31.56.39.249:80 guuid=049cfdd7-1700-0000-5888-aa96340c0000 pid=3124->ec4192e8-5288-5372-a2de-e40b6fa61ae6 send: 137B guuid=fabd20e5-1700-0000-5888-aa96570c0000 pid=3159->ec4192e8-5288-5372-a2de-e40b6fa61ae6 send: 137B guuid=7ffb4ef1-1700-0000-5888-aa96700c0000 pid=3184->ec4192e8-5288-5372-a2de-e40b6fa61ae6 send: 136B guuid=523acefc-1700-0000-5888-aa96750c0000 pid=3189->ec4192e8-5288-5372-a2de-e40b6fa61ae6 send: 136B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=a1fda407-1800-0000-5888-aa96850c0000 pid=3205->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=feb3c707-1800-0000-5888-aa96870c0000 pid=3207 /tmp/Demon.x86 guuid=a1fda407-1800-0000-5888-aa96850c0000 pid=3205->guuid=feb3c707-1800-0000-5888-aa96870c0000 pid=3207 clone guuid=cfecd007-1800-0000-5888-aa96880c0000 pid=3208 /tmp/Demon.x86 net send-data zombie guuid=feb3c707-1800-0000-5888-aa96870c0000 pid=3207->guuid=cfecd007-1800-0000-5888-aa96880c0000 pid=3208 clone 6743b226-939f-597c-ab42-f7cf3983935b 31.56.39.249:666 guuid=cfecd007-1800-0000-5888-aa96880c0000 pid=3208->6743b226-939f-597c-ab42-f7cf3983935b send: 128B guuid=05ff5c08-1800-0000-5888-aa968b0c0000 pid=3211->ec4192e8-5288-5372-a2de-e40b6fa61ae6 send: 137B guuid=b8d2b716-1800-0000-5888-aa96a20c0000 pid=3234->ec4192e8-5288-5372-a2de-e40b6fa61ae6 send: 137B guuid=34b00823-1800-0000-5888-aa96a60c0000 pid=3238->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=79d72b25-1800-0000-5888-aa96a70c0000 pid=3239 /tmp/Demon.i686 guuid=34b00823-1800-0000-5888-aa96a60c0000 pid=3238->guuid=79d72b25-1800-0000-5888-aa96a70c0000 pid=3239 clone guuid=71553825-1800-0000-5888-aa96a80c0000 pid=3240 /tmp/Demon.i686 net send-data zombie guuid=79d72b25-1800-0000-5888-aa96a70c0000 pid=3239->guuid=71553825-1800-0000-5888-aa96a80c0000 pid=3240 clone guuid=71553825-1800-0000-5888-aa96a80c0000 pid=3240->6743b226-939f-597c-ab42-f7cf3983935b send: 128B guuid=4bc53526-1800-0000-5888-aa96aa0c0000 pid=3242->ec4192e8-5288-5372-a2de-e40b6fa61ae6 send: 136B guuid=3997bc36-1800-0000-5888-aa96bd0c0000 pid=3261->ec4192e8-5288-5372-a2de-e40b6fa61ae6 send: 137B guuid=69e4b041-1800-0000-5888-aa96c60c0000 pid=3270->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=49619e42-1800-0000-5888-aa96c70c0000 pid=3271 /tmp/Demon.i586 guuid=69e4b041-1800-0000-5888-aa96c60c0000 pid=3270->guuid=49619e42-1800-0000-5888-aa96c70c0000 pid=3271 clone guuid=5caba742-1800-0000-5888-aa96c80c0000 pid=3272 /tmp/Demon.i586 net send-data zombie guuid=49619e42-1800-0000-5888-aa96c70c0000 pid=3271->guuid=5caba742-1800-0000-5888-aa96c80c0000 pid=3272 clone guuid=5caba742-1800-0000-5888-aa96c80c0000 pid=3272->6743b226-939f-597c-ab42-f7cf3983935b send: 384B guuid=924a1643-1800-0000-5888-aa96cb0c0000 pid=3275->ec4192e8-5288-5372-a2de-e40b6fa61ae6 send: 137B guuid=c428704e-1800-0000-5888-aa96e40c0000 pid=3300->ec4192e8-5288-5372-a2de-e40b6fa61ae6 send: 138B guuid=6eb9405b-1800-0000-5888-aa96f90c0000 pid=3321->ec4192e8-5288-5372-a2de-e40b6fa61ae6 send: 137B guuid=67a8e566-1800-0000-5888-aa96190d0000 pid=3353->ec4192e8-5288-5372-a2de-e40b6fa61ae6 send: 137B guuid=8f25d272-1800-0000-5888-aa96370d0000 pid=3383->ec4192e8-5288-5372-a2de-e40b6fa61ae6 send: 137B guuid=707eef81-1800-0000-5888-aa964a0d0000 pid=3402->ec4192e8-5288-5372-a2de-e40b6fa61ae6 send: 141B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-06-17 18:46:20 UTC
File Type:
Text (Shell)
AV detection:
25 of 38 (65.79%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt botnet defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Reads system network configuration
Reads system routing table
File and Directory Permissions Modification
Executes dropped EXE
Detected Gafgyt variant
Gafgyt family
Gafgyt/Bashlite
Malware Config
C2 Extraction:
31.56.39.249:666
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 3ac38c1708e7221ee617c9f80273d1d6dac3c2591f59b72bb9c1e9df1a87eff6

(this sample)

  
Delivery method
Distributed via web download

Comments