MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3be913565735d606fc2d64b098763b52ed9a6ba9ca93d89f723409b0348557eb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 7


Intelligence 7 IOCs YARA 4 File information Comments

SHA256 hash: 3be913565735d606fc2d64b098763b52ed9a6ba9ca93d89f723409b0348557eb
SHA3-384 hash: 52191de406a0db7ac442be0e54286d17b059dcdf47f12294983eba83ae9d0ac7a5bfb87427c58419a40d86edec5071a5
SHA1 hash: dca564af6045aa747b75a3cdbbe4aa0f42bea966
MD5 hash: 99b06443719f827bb218ecdf32e6711f
humanhash: charlie-mango-papa-west
File name:spc
Download: download sample
Signature Gafgyt
File size:104'181 bytes
First seen:2025-06-19 01:56:10 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 1536:mADFrx6eS//QXWI7iblV/9SEIplJLbvA7M0Wp5:mAD76eQP7V/cplJXDH
TLSH T1E4A3B73B2B531E63C0D6443146B74371BDAADB4C34BC8BAB98D05D6D2E0AE9834457EE
telfhash t1c82136128cb70b093ff29b6c6caf59d5526264153a305eb1cf54c44c893f0b7a172be5
Magika elf
Reporter abuse_ch
Tags:elf gafgyt

Intelligence


File Origin
# of uploads :
1
# of downloads :
113
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
gcc
Status:
terminated
Behavior Graph:
%3 guuid=6a3d59d9-1600-0000-3c99-a68bef0c0000 pid=3311 /usr/bin/sudo guuid=142528dc-1600-0000-3c99-a68bf30c0000 pid=3315 /tmp/sample.bin guuid=6a3d59d9-1600-0000-3c99-a68bef0c0000 pid=3311->guuid=142528dc-1600-0000-3c99-a68bf30c0000 pid=3315 execve
Result
Threat name:
Detection:
malicious
Classification:
spre.troj
Score:
60 / 100
Signature
Contains symbols with names commonly found in malware
Opens /proc/net/* files useful for finding connected devices and routers
Sample tries to kill multiple processes (SIGKILL)
Yara detected Gafgyt
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1718089 Sample: spc.elf Startdate: 19/06/2025 Architecture: LINUX Score: 60 25 207.167.64.24, 5058, 56884 UNASSIGNED Reserved 2->25 27 109.202.202.202, 80 INIT7CH Switzerland 2->27 29 4 other IPs or domains 2->29 33 Yara detected Gafgyt 2->33 35 Contains symbols with names commonly found in malware 2->35 9 spc.elf 2->9         started        signatures3 process4 signatures5 37 Opens /proc/net/* files useful for finding connected devices and routers 9->37 12 spc.elf 9->12         started        process6 process7 14 spc.elf 12->14         started        process8 16 spc.elf 14->16         started        19 spc.elf 14->19         started        21 spc.elf 14->21         started        23 431 other processes 14->23 signatures9 31 Sample tries to kill multiple processes (SIGKILL) 16->31
Threat name:
Linux.Trojan.Gafgyt
Status:
Malicious
First seen:
2025-06-19 16:31:35 UTC
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Verdict:
Malicious
Tags:
Unix.Trojan.Mirai-5607483-0
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:botnet_plaintext_c2
Author:cip
Description:Attempts to match at least some of the strings used in some botnet variants which use plaintext communication protocols.
Rule name:Mal_LNX_Gafgyt_Botnet_ELF
Author:Phatcharadol Thangplub
Description:Use to detect Gafgyt botnet, and there variants.
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

elf 3be913565735d606fc2d64b098763b52ed9a6ba9ca93d89f723409b0348557eb

(this sample)

  
Delivery method
Distributed via web download

Comments