MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4003e776e4e321eb6060f0391f74715d54d4a232d63576f6ecaf7ffe19675e81. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 4003e776e4e321eb6060f0391f74715d54d4a232d63576f6ecaf7ffe19675e81
SHA3-384 hash: 0574010f361a7ef9217f6c720e59d0d3d6dea7db19600400f014917934d0ee4201b9258f8491cb6239c439d7bfbb6564
SHA1 hash: 51397342544756d20834b149024c5cecda498926
MD5 hash: 4a1fbb1eb792c9694eb55b9f5031dbb4
humanhash: carbon-missouri-kitten-india
File name:t
Download: download sample
Signature Gafgyt
File size:162 bytes
First seen:2025-08-28 07:33:24 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 3:LySC8Wj6cNOMBLIUL+mZIKzSHHa+L3Wj6cNOMBLIgIbZIKzSHHa+LQ:LySC8i6cN98jLxz3i6cN98IxzQ
TLSH T19FC0126C0018A4B88D70FA52B2119C71E00D41C034740E48D6C80D704D569387060D8D
Magika batch
Reporter abuse_ch
Tags:gafgyt sh
URLMalware sample (SHA256 hash)SignatureTags
http://185.121.13.159/skid.mips21c1a38155620df7ff31b34364069137ff5bea0f6cf57a8c8a13a687792a7d86 Gafgytelf gafgyt ua-wget
http://185.121.13.159/skid.mpsl303eb333f34a2f3846afde57acb6045a6e96954da622647164184903f1d29768 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
38
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=cb418e88-1800-0000-929a-c614ed0d0000 pid=3565 /usr/bin/sudo guuid=3bdd568a-1800-0000-929a-c614f30d0000 pid=3571 /tmp/sample.bin guuid=cb418e88-1800-0000-929a-c614ed0d0000 pid=3565->guuid=3bdd568a-1800-0000-929a-c614f30d0000 pid=3571 execve guuid=a6bec18a-1800-0000-929a-c614f50d0000 pid=3573 /usr/bin/wget net send-data write-file guuid=3bdd568a-1800-0000-929a-c614f30d0000 pid=3571->guuid=a6bec18a-1800-0000-929a-c614f50d0000 pid=3573 execve guuid=4004e492-1800-0000-929a-c6140b0e0000 pid=3595 /usr/bin/chmod guuid=3bdd568a-1800-0000-929a-c614f30d0000 pid=3571->guuid=4004e492-1800-0000-929a-c6140b0e0000 pid=3595 execve guuid=09ea5b93-1800-0000-929a-c6140d0e0000 pid=3597 /usr/bin/dash guuid=3bdd568a-1800-0000-929a-c614f30d0000 pid=3571->guuid=09ea5b93-1800-0000-929a-c6140d0e0000 pid=3597 clone guuid=f6bd0694-1800-0000-929a-c614100e0000 pid=3600 /usr/bin/wget net send-data write-file guuid=3bdd568a-1800-0000-929a-c614f30d0000 pid=3571->guuid=f6bd0694-1800-0000-929a-c614100e0000 pid=3600 execve guuid=2c96bf9d-1800-0000-929a-c614300e0000 pid=3632 /usr/bin/chmod guuid=3bdd568a-1800-0000-929a-c614f30d0000 pid=3571->guuid=2c96bf9d-1800-0000-929a-c614300e0000 pid=3632 execve guuid=cbdb0e9e-1800-0000-929a-c614320e0000 pid=3634 /usr/bin/dash guuid=3bdd568a-1800-0000-929a-c614f30d0000 pid=3571->guuid=cbdb0e9e-1800-0000-929a-c614320e0000 pid=3634 clone 46c5cf3c-ed7d-558b-b835-3a135f52a779 185.121.13.159:80 guuid=a6bec18a-1800-0000-929a-c614f50d0000 pid=3573->46c5cf3c-ed7d-558b-b835-3a135f52a779 send: 138B guuid=f6bd0694-1800-0000-929a-c614100e0000 pid=3600->46c5cf3c-ed7d-558b-b835-3a135f52a779 send: 138B
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 4003e776e4e321eb6060f0391f74715d54d4a232d63576f6ecaf7ffe19675e81

(this sample)

  
Delivery method
Distributed via web download

Comments