MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3e75cc8e83d6f5767823d8d6af243af3eff14885e86bc3edb7b130bafd1f80e4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 3e75cc8e83d6f5767823d8d6af243af3eff14885e86bc3edb7b130bafd1f80e4
SHA3-384 hash: 33eae06444bdbab34391fc533e0feeb13dd4d6f437617743a2e4e12d086f657b5e6bf15a34cb6bae8cab4130cb98c4b3
SHA1 hash: 6f98aa9c27c307b31f1338246cfffcaa9ae4ca96
MD5 hash: 9d4178980b2740e2a13cc091be1128f2
humanhash: three-blossom-low-artist
File name:ISIS.sh
Download: download sample
Signature Gafgyt
File size:2'062 bytes
First seen:2026-01-12 11:18:43 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:1uth4tlSaLaMalskHdHp4H/9zc9QtQfk0ja1pufQ/ylkdvA/FWpszbsylkdved+S:1uth4tlSaLaMalsCdpelzc9QtQfk0ja+
TLSH T1DE41BE8E20920870BC66A4777275BE0070D5939FA4D9BF4F7ADC38E5098CEF5E425B82
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://192.210.214.149/m-i.p-s.ISISdc966bf0d1b7eb048fcf658d7f4676818456a5882aca6717a6408ae923544a98 Gafgytelf gafgyt ua-wget
http://192.210.214.149/m-p.s-l.ISIS299d7b24d3433aced87e8637667b4280997d9a10a8ed194cc5f5819832ca69ab Gafgytelf gafgyt ua-wget
http://192.210.214.149/s-h.4-.ISISb1d624340813c3a08151e246b33e2caf7d2024809712eef46cd8978c3b31fd4a Gafgytelf gafgyt ua-wget
http://192.210.214.149/x-8.6-.ISIS7b541360a623d5f8897b171c585caba9e381655ceb2a48b19e3d6fbef9d2203e Gafgytelf gafgyt ua-wget
http://192.210.214.149/a-r.m-6.ISIS78daddb177fcbed8d06d899a70935c690a312a170ae1fa52756d4bb02d1f7db0 Gafgytelf gafgyt ua-wget
http://192.210.214.149/x-3.2-.ISISn/an/aelf ua-wget
http://192.210.214.149/a-r.m-7.ISIS7e9296cee4339badfbecc4d338a51cd08b24c0ddfaac54433595da973cd506d9 Gafgytelf gafgyt ua-wget
http://192.210.214.149/p-p.c-.ISIS8f63467913134275f64e621550fa5fdb9427c3a8a4560812dbe4a31d7f290497 Gafgytelf gafgyt ua-wget
http://192.210.214.149/i-5.8-6.ISISn/an/aelf ua-wget
http://192.210.214.149/m-6.8-k.ISISn/an/aelf ua-wget
http://192.210.214.149/a-r.m-4.ISIS8f63467913134275f64e621550fa5fdb9427c3a8a4560812dbe4a31d7f290497 Gafgytelf gafgyt ua-wget
http://192.210.214.149/a-r.m-5.ISIS6382b41c894650cffefe6b142cd2a5d04e52c9bbdbb68087115500af823299fb Gafgytelf gafgyt ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
36
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive medusa mirai
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=ffaa56af-1e00-0000-7690-b49bc30c0000 pid=3267 /usr/bin/sudo guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272 /tmp/sample.bin guuid=ffaa56af-1e00-0000-7690-b49bc30c0000 pid=3267->guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272 execve guuid=bd2a99b1-1e00-0000-7690-b49bc90c0000 pid=3273 /usr/bin/wget net send-data write-file guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=bd2a99b1-1e00-0000-7690-b49bc90c0000 pid=3273 execve guuid=49d446dc-1e00-0000-7690-b49b1c0d0000 pid=3356 /usr/bin/chmod guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=49d446dc-1e00-0000-7690-b49b1c0d0000 pid=3356 execve guuid=8cdc78dc-1e00-0000-7690-b49b1d0d0000 pid=3357 /usr/bin/dash guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=8cdc78dc-1e00-0000-7690-b49b1d0d0000 pid=3357 clone guuid=b59885dc-1e00-0000-7690-b49b1f0d0000 pid=3359 /usr/bin/rm delete-file guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=b59885dc-1e00-0000-7690-b49b1f0d0000 pid=3359 execve guuid=fe30c4dc-1e00-0000-7690-b49b200d0000 pid=3360 /usr/bin/wget net send-data write-file guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=fe30c4dc-1e00-0000-7690-b49b200d0000 pid=3360 execve guuid=d2052605-1f00-0000-7690-b49ba40d0000 pid=3492 /usr/bin/chmod guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=d2052605-1f00-0000-7690-b49ba40d0000 pid=3492 execve guuid=9a416505-1f00-0000-7690-b49ba50d0000 pid=3493 /usr/bin/dash guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=9a416505-1f00-0000-7690-b49ba50d0000 pid=3493 clone guuid=56168d05-1f00-0000-7690-b49ba60d0000 pid=3494 /usr/bin/rm delete-file guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=56168d05-1f00-0000-7690-b49ba60d0000 pid=3494 execve guuid=0761c805-1f00-0000-7690-b49ba70d0000 pid=3495 /usr/bin/wget net send-data write-file guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=0761c805-1f00-0000-7690-b49ba70d0000 pid=3495 execve guuid=8457722c-1f00-0000-7690-b49bfc0d0000 pid=3580 /usr/bin/chmod guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=8457722c-1f00-0000-7690-b49bfc0d0000 pid=3580 execve guuid=580dbe2c-1f00-0000-7690-b49bfe0d0000 pid=3582 /usr/bin/dash guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=580dbe2c-1f00-0000-7690-b49bfe0d0000 pid=3582 clone guuid=3680c82c-1f00-0000-7690-b49bff0d0000 pid=3583 /usr/bin/rm delete-file guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=3680c82c-1f00-0000-7690-b49bff0d0000 pid=3583 execve guuid=2bfa062d-1f00-0000-7690-b49b010e0000 pid=3585 /usr/bin/wget net send-data write-file guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=2bfa062d-1f00-0000-7690-b49b010e0000 pid=3585 execve guuid=beefb653-1f00-0000-7690-b49b3d0e0000 pid=3645 /usr/bin/chmod guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=beefb653-1f00-0000-7690-b49b3d0e0000 pid=3645 execve guuid=e262f453-1f00-0000-7690-b49b3e0e0000 pid=3646 /usr/bin/dash guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=e262f453-1f00-0000-7690-b49b3e0e0000 pid=3646 clone guuid=89cb0454-1f00-0000-7690-b49b3f0e0000 pid=3647 /usr/bin/rm delete-file guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=89cb0454-1f00-0000-7690-b49b3f0e0000 pid=3647 execve guuid=137a9554-1f00-0000-7690-b49b400e0000 pid=3648 /usr/bin/wget net send-data write-file guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=137a9554-1f00-0000-7690-b49b400e0000 pid=3648 execve guuid=f7f2407b-1f00-0000-7690-b49b9f0e0000 pid=3743 /usr/bin/chmod guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=f7f2407b-1f00-0000-7690-b49b9f0e0000 pid=3743 execve guuid=2cce7c7b-1f00-0000-7690-b49ba00e0000 pid=3744 /usr/bin/dash guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=2cce7c7b-1f00-0000-7690-b49ba00e0000 pid=3744 clone guuid=cfe4887b-1f00-0000-7690-b49ba10e0000 pid=3745 /usr/bin/rm delete-file guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=cfe4887b-1f00-0000-7690-b49ba10e0000 pid=3745 execve guuid=dccbde7b-1f00-0000-7690-b49ba20e0000 pid=3746 /usr/bin/wget net send-data guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=dccbde7b-1f00-0000-7690-b49ba20e0000 pid=3746 execve guuid=6f91438c-1f00-0000-7690-b49bdf0e0000 pid=3807 /usr/bin/chmod guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=6f91438c-1f00-0000-7690-b49bdf0e0000 pid=3807 execve guuid=ea06b68c-1f00-0000-7690-b49be10e0000 pid=3809 /usr/bin/dash guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=ea06b68c-1f00-0000-7690-b49be10e0000 pid=3809 clone guuid=0862c38c-1f00-0000-7690-b49be30e0000 pid=3811 /usr/bin/rm guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=0862c38c-1f00-0000-7690-b49be30e0000 pid=3811 execve guuid=5e7b2c8d-1f00-0000-7690-b49be60e0000 pid=3814 /usr/bin/wget net send-data write-file guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=5e7b2c8d-1f00-0000-7690-b49be60e0000 pid=3814 execve guuid=3fbfa9b4-1f00-0000-7690-b49b7b0f0000 pid=3963 /usr/bin/chmod guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=3fbfa9b4-1f00-0000-7690-b49b7b0f0000 pid=3963 execve guuid=f160e2b4-1f00-0000-7690-b49b7d0f0000 pid=3965 /usr/bin/dash guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=f160e2b4-1f00-0000-7690-b49b7d0f0000 pid=3965 clone guuid=ac7df2b4-1f00-0000-7690-b49b7e0f0000 pid=3966 /usr/bin/rm delete-file guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=ac7df2b4-1f00-0000-7690-b49b7e0f0000 pid=3966 execve guuid=f0714db5-1f00-0000-7690-b49b800f0000 pid=3968 /usr/bin/wget net send-data write-file guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=f0714db5-1f00-0000-7690-b49b800f0000 pid=3968 execve guuid=379834dc-1f00-0000-7690-b49b09100000 pid=4105 /usr/bin/chmod guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=379834dc-1f00-0000-7690-b49b09100000 pid=4105 execve guuid=2a9876dc-1f00-0000-7690-b49b0c100000 pid=4108 /usr/bin/dash guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=2a9876dc-1f00-0000-7690-b49b0c100000 pid=4108 clone guuid=500685dc-1f00-0000-7690-b49b0d100000 pid=4109 /usr/bin/rm delete-file guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=500685dc-1f00-0000-7690-b49b0d100000 pid=4109 execve guuid=e466dbdc-1f00-0000-7690-b49b11100000 pid=4113 /usr/bin/wget net send-data guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=e466dbdc-1f00-0000-7690-b49b11100000 pid=4113 execve guuid=50a1d1ec-1f00-0000-7690-b49b4b100000 pid=4171 /usr/bin/chmod guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=50a1d1ec-1f00-0000-7690-b49b4b100000 pid=4171 execve guuid=a4181fed-1f00-0000-7690-b49b4d100000 pid=4173 /usr/bin/dash guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=a4181fed-1f00-0000-7690-b49b4d100000 pid=4173 clone guuid=5ff62eed-1f00-0000-7690-b49b4e100000 pid=4174 /usr/bin/rm guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=5ff62eed-1f00-0000-7690-b49b4e100000 pid=4174 execve guuid=08df84ed-1f00-0000-7690-b49b50100000 pid=4176 /usr/bin/wget net send-data guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=08df84ed-1f00-0000-7690-b49b50100000 pid=4176 execve guuid=8ba795fe-1f00-0000-7690-b49b7c100000 pid=4220 /usr/bin/chmod guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=8ba795fe-1f00-0000-7690-b49b7c100000 pid=4220 execve guuid=ff87f6fe-1f00-0000-7690-b49b7e100000 pid=4222 /usr/bin/dash guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=ff87f6fe-1f00-0000-7690-b49b7e100000 pid=4222 clone guuid=efc707ff-1f00-0000-7690-b49b7f100000 pid=4223 /usr/bin/rm guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=efc707ff-1f00-0000-7690-b49b7f100000 pid=4223 execve guuid=6cdb54ff-1f00-0000-7690-b49b80100000 pid=4224 /usr/bin/wget net send-data write-file guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=6cdb54ff-1f00-0000-7690-b49b80100000 pid=4224 execve guuid=9b268f26-2000-0000-7690-b49bf0100000 pid=4336 /usr/bin/chmod guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=9b268f26-2000-0000-7690-b49bf0100000 pid=4336 execve guuid=7dcb1127-2000-0000-7690-b49bf1100000 pid=4337 /usr/bin/dash guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=7dcb1127-2000-0000-7690-b49bf1100000 pid=4337 clone guuid=31ca2827-2000-0000-7690-b49bf2100000 pid=4338 /usr/bin/rm delete-file guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=31ca2827-2000-0000-7690-b49bf2100000 pid=4338 execve guuid=22e07a27-2000-0000-7690-b49bf3100000 pid=4339 /usr/bin/wget net send-data write-file guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=22e07a27-2000-0000-7690-b49bf3100000 pid=4339 execve guuid=2838554f-2000-0000-7690-b49b8f110000 pid=4495 /usr/bin/chmod guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=2838554f-2000-0000-7690-b49b8f110000 pid=4495 execve guuid=2d0aae4f-2000-0000-7690-b49b90110000 pid=4496 /usr/bin/dash guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=2d0aae4f-2000-0000-7690-b49b90110000 pid=4496 clone guuid=ef9dc54f-2000-0000-7690-b49b93110000 pid=4499 /usr/bin/rm delete-file guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=ef9dc54f-2000-0000-7690-b49b93110000 pid=4499 execve guuid=96011450-2000-0000-7690-b49b95110000 pid=4501 /usr/bin/wget net send-data write-file guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=96011450-2000-0000-7690-b49b95110000 pid=4501 execve guuid=f575b477-2000-0000-7690-b49b07120000 pid=4615 /usr/bin/chmod guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=f575b477-2000-0000-7690-b49b07120000 pid=4615 execve guuid=7272ea77-2000-0000-7690-b49b08120000 pid=4616 /usr/bin/dash guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=7272ea77-2000-0000-7690-b49b08120000 pid=4616 clone guuid=d187f677-2000-0000-7690-b49b09120000 pid=4617 /usr/bin/rm delete-file guuid=bd4536b1-1e00-0000-7690-b49bc80c0000 pid=3272->guuid=d187f677-2000-0000-7690-b49b09120000 pid=4617 execve c0cbad57-912f-52e3-95e3-bc0d9ad1a3e7 192.210.214.149:80 guuid=bd2a99b1-1e00-0000-7690-b49bc90c0000 pid=3273->c0cbad57-912f-52e3-95e3-bc0d9ad1a3e7 send: 142B guuid=fe30c4dc-1e00-0000-7690-b49b200d0000 pid=3360->c0cbad57-912f-52e3-95e3-bc0d9ad1a3e7 send: 142B guuid=0761c805-1f00-0000-7690-b49ba70d0000 pid=3495->c0cbad57-912f-52e3-95e3-bc0d9ad1a3e7 send: 141B guuid=2bfa062d-1f00-0000-7690-b49b010e0000 pid=3585->c0cbad57-912f-52e3-95e3-bc0d9ad1a3e7 send: 141B guuid=137a9554-1f00-0000-7690-b49b400e0000 pid=3648->c0cbad57-912f-52e3-95e3-bc0d9ad1a3e7 send: 142B guuid=dccbde7b-1f00-0000-7690-b49ba20e0000 pid=3746->c0cbad57-912f-52e3-95e3-bc0d9ad1a3e7 send: 141B guuid=5e7b2c8d-1f00-0000-7690-b49be60e0000 pid=3814->c0cbad57-912f-52e3-95e3-bc0d9ad1a3e7 send: 142B guuid=f0714db5-1f00-0000-7690-b49b800f0000 pid=3968->c0cbad57-912f-52e3-95e3-bc0d9ad1a3e7 send: 141B guuid=e466dbdc-1f00-0000-7690-b49b11100000 pid=4113->c0cbad57-912f-52e3-95e3-bc0d9ad1a3e7 send: 142B guuid=08df84ed-1f00-0000-7690-b49b50100000 pid=4176->c0cbad57-912f-52e3-95e3-bc0d9ad1a3e7 send: 142B guuid=6cdb54ff-1f00-0000-7690-b49b80100000 pid=4224->c0cbad57-912f-52e3-95e3-bc0d9ad1a3e7 send: 141B guuid=22e07a27-2000-0000-7690-b49bf3100000 pid=4339->c0cbad57-912f-52e3-95e3-bc0d9ad1a3e7 send: 142B guuid=96011450-2000-0000-7690-b49b95110000 pid=4501->c0cbad57-912f-52e3-95e3-bc0d9ad1a3e7 send: 142B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-01-12 11:19:40 UTC
File Type:
Text (Shell)
AV detection:
14 of 24 (58.33%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 3e75cc8e83d6f5767823d8d6af243af3eff14885e86bc3edb7b130bafd1f80e4

(this sample)

  
Delivery method
Distributed via web download

Comments