MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 41abee81a9cf1657e98ea8c7a6a966d70e032d44cc3b526253fe636230c710df. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 41abee81a9cf1657e98ea8c7a6a966d70e032d44cc3b526253fe636230c710df
SHA3-384 hash: 17914fe4b6c87395519106ecd21687e09713567f658d95a43efa7b479b2d6dbc97062adb5917fb148470325446cee7fc
SHA1 hash: ba1095dd0b23faa69607a336006a9926a97dbd56
MD5 hash: 799ac1182fe4b01cbcc46b416c524e96
humanhash: ohio-queen-oklahoma-mountain
File name:bins.sh
Download: download sample
Signature Gafgyt
File size:1'402 bytes
First seen:2025-11-22 22:30:46 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:sYlYE1YUYnAG19ZVwaVmA+lt31rkCN541VcqV2AVEVaAI6IMpos:aR98vPJwlHMpos
TLSH T1F121348AD130AB62CECBCA2F77A06BC9908D45B3A26F9F659944DE35DC4F5843117B00
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://178.162.242.155/mipsn/an/amirai opendir
http://178.162.242.155/mipseld4813b51f18d08c979f28a0e18c16dd5289914e70406da3270c3c0a68406ee37 Gafgytgafgyt mirai opendir
http://178.162.242.155/x86_64n/an/amirai opendir
http://178.162.242.155/armv6ln/an/amirai opendir
http://178.162.242.155/i686n/an/amirai opendir
http://178.162.242.155/powerpcn/an/amirai opendir
http://178.162.242.155/i586n/an/amirai opendir
http://178.162.242.155/m68kn/an/amirai opendir
http://178.162.242.155/sparcn/an/amirai opendir
http://178.162.242.155/armv4ln/an/amirai opendir
http://178.162.242.155/armv5ln/an/amirai opendir
http://178.162.242.155/powerpcx440fpn/an/amirai opendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
34
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive mirai
Verdict:
Malicious
File Type:
text
First seen:
2025-11-22T20:46:00Z UTC
Last seen:
2025-11-23T00:05:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=14a7fc0d-1a00-0000-f767-ab2aeb080000 pid=2283 /usr/bin/sudo guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292 /tmp/sample.bin guuid=14a7fc0d-1a00-0000-f767-ab2aeb080000 pid=2283->guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292 execve guuid=125ad910-1a00-0000-f767-ab2af6080000 pid=2294 /usr/bin/wget net send-data guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=125ad910-1a00-0000-f767-ab2af6080000 pid=2294 execve guuid=fa179115-1a00-0000-f767-ab2afe080000 pid=2302 /usr/bin/curl net send-data write-file guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=fa179115-1a00-0000-f767-ab2afe080000 pid=2302 execve guuid=a40a782d-1a00-0000-f767-ab2a0e090000 pid=2318 /usr/bin/chmod guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=a40a782d-1a00-0000-f767-ab2a0e090000 pid=2318 execve guuid=41a7e82d-1a00-0000-f767-ab2a10090000 pid=2320 /home/sandbox/mips guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=41a7e82d-1a00-0000-f767-ab2a10090000 pid=2320 execve guuid=94fb412e-1a00-0000-f767-ab2a11090000 pid=2321 /usr/bin/rm delete-file guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=94fb412e-1a00-0000-f767-ab2a11090000 pid=2321 execve guuid=fcb0ac2e-1a00-0000-f767-ab2a14090000 pid=2324 /usr/bin/wget net send-data write-file guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=fcb0ac2e-1a00-0000-f767-ab2a14090000 pid=2324 execve guuid=d3fbeb34-1a00-0000-f767-ab2a1c090000 pid=2332 /usr/bin/curl net send-data write-file guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=d3fbeb34-1a00-0000-f767-ab2a1c090000 pid=2332 execve guuid=8ecc663b-1a00-0000-f767-ab2a2e090000 pid=2350 /usr/bin/chmod guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=8ecc663b-1a00-0000-f767-ab2a2e090000 pid=2350 execve guuid=5c50a23b-1a00-0000-f767-ab2a2f090000 pid=2351 /usr/bin/dash guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=5c50a23b-1a00-0000-f767-ab2a2f090000 pid=2351 clone guuid=519edb3c-1a00-0000-f767-ab2a34090000 pid=2356 /usr/bin/rm delete-file guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=519edb3c-1a00-0000-f767-ab2a34090000 pid=2356 execve guuid=f15f133d-1a00-0000-f767-ab2a35090000 pid=2357 /usr/bin/wget net send-data guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=f15f133d-1a00-0000-f767-ab2a35090000 pid=2357 execve guuid=5f12e73f-1a00-0000-f767-ab2a3d090000 pid=2365 /usr/bin/curl net send-data write-file guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=5f12e73f-1a00-0000-f767-ab2a3d090000 pid=2365 execve guuid=92b50e47-1a00-0000-f767-ab2a4b090000 pid=2379 /usr/bin/chmod guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=92b50e47-1a00-0000-f767-ab2a4b090000 pid=2379 execve guuid=4ecd7e47-1a00-0000-f767-ab2a4c090000 pid=2380 /home/sandbox/x86_64 guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=4ecd7e47-1a00-0000-f767-ab2a4c090000 pid=2380 execve guuid=b812db47-1a00-0000-f767-ab2a4e090000 pid=2382 /usr/bin/rm delete-file guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=b812db47-1a00-0000-f767-ab2a4e090000 pid=2382 execve guuid=18872748-1a00-0000-f767-ab2a50090000 pid=2384 /usr/bin/wget net send-data guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=18872748-1a00-0000-f767-ab2a50090000 pid=2384 execve guuid=bc1ee54a-1a00-0000-f767-ab2a5a090000 pid=2394 /usr/bin/curl net send-data write-file guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=bc1ee54a-1a00-0000-f767-ab2a5a090000 pid=2394 execve guuid=518e5050-1a00-0000-f767-ab2a68090000 pid=2408 /usr/bin/chmod guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=518e5050-1a00-0000-f767-ab2a68090000 pid=2408 execve guuid=5b5eaf50-1a00-0000-f767-ab2a6b090000 pid=2411 /home/sandbox/armv6l guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=5b5eaf50-1a00-0000-f767-ab2a6b090000 pid=2411 execve guuid=3f36f050-1a00-0000-f767-ab2a6d090000 pid=2413 /usr/bin/rm delete-file guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=3f36f050-1a00-0000-f767-ab2a6d090000 pid=2413 execve guuid=d4ba3f51-1a00-0000-f767-ab2a6f090000 pid=2415 /usr/bin/wget net send-data guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=d4ba3f51-1a00-0000-f767-ab2a6f090000 pid=2415 execve guuid=30f01b54-1a00-0000-f767-ab2a75090000 pid=2421 /usr/bin/curl net send-data write-file guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=30f01b54-1a00-0000-f767-ab2a75090000 pid=2421 execve guuid=c521c958-1a00-0000-f767-ab2a7e090000 pid=2430 /usr/bin/chmod guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=c521c958-1a00-0000-f767-ab2a7e090000 pid=2430 execve guuid=bada0459-1a00-0000-f767-ab2a7f090000 pid=2431 /home/sandbox/i686 guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=bada0459-1a00-0000-f767-ab2a7f090000 pid=2431 execve guuid=c0874459-1a00-0000-f767-ab2a80090000 pid=2432 /usr/bin/rm delete-file guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=c0874459-1a00-0000-f767-ab2a80090000 pid=2432 execve guuid=5c82ac59-1a00-0000-f767-ab2a81090000 pid=2433 /usr/bin/wget net send-data guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=5c82ac59-1a00-0000-f767-ab2a81090000 pid=2433 execve guuid=ad1ece5c-1a00-0000-f767-ab2a88090000 pid=2440 /usr/bin/curl net send-data write-file guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=ad1ece5c-1a00-0000-f767-ab2a88090000 pid=2440 execve guuid=a1f76e60-1a00-0000-f767-ab2a8f090000 pid=2447 /usr/bin/chmod guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=a1f76e60-1a00-0000-f767-ab2a8f090000 pid=2447 execve guuid=2338e960-1a00-0000-f767-ab2a90090000 pid=2448 /home/sandbox/powerpc guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=2338e960-1a00-0000-f767-ab2a90090000 pid=2448 execve guuid=94095d61-1a00-0000-f767-ab2a92090000 pid=2450 /usr/bin/rm delete-file guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=94095d61-1a00-0000-f767-ab2a92090000 pid=2450 execve guuid=399ea861-1a00-0000-f767-ab2a94090000 pid=2452 /usr/bin/wget net send-data guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=399ea861-1a00-0000-f767-ab2a94090000 pid=2452 execve guuid=dbc78f64-1a00-0000-f767-ab2a9e090000 pid=2462 /usr/bin/curl net send-data write-file guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=dbc78f64-1a00-0000-f767-ab2a9e090000 pid=2462 execve guuid=b1c7d36a-1a00-0000-f767-ab2aae090000 pid=2478 /usr/bin/chmod guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=b1c7d36a-1a00-0000-f767-ab2aae090000 pid=2478 execve guuid=5f15336b-1a00-0000-f767-ab2ab0090000 pid=2480 /home/sandbox/i586 guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=5f15336b-1a00-0000-f767-ab2ab0090000 pid=2480 execve guuid=d24c826b-1a00-0000-f767-ab2ab1090000 pid=2481 /usr/bin/rm delete-file guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=d24c826b-1a00-0000-f767-ab2ab1090000 pid=2481 execve guuid=8089f66b-1a00-0000-f767-ab2ab2090000 pid=2482 /usr/bin/wget net send-data guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=8089f66b-1a00-0000-f767-ab2ab2090000 pid=2482 execve guuid=eb760d6f-1a00-0000-f767-ab2aba090000 pid=2490 /usr/bin/curl net send-data write-file guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=eb760d6f-1a00-0000-f767-ab2aba090000 pid=2490 execve guuid=63de1174-1a00-0000-f767-ab2ac9090000 pid=2505 /usr/bin/chmod guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=63de1174-1a00-0000-f767-ab2ac9090000 pid=2505 execve guuid=d2116574-1a00-0000-f767-ab2acb090000 pid=2507 /home/sandbox/m68k guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=d2116574-1a00-0000-f767-ab2acb090000 pid=2507 execve guuid=5c039574-1a00-0000-f767-ab2acd090000 pid=2509 /usr/bin/rm delete-file guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=5c039574-1a00-0000-f767-ab2acd090000 pid=2509 execve guuid=82a1d074-1a00-0000-f767-ab2acf090000 pid=2511 /usr/bin/wget net send-data guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=82a1d074-1a00-0000-f767-ab2acf090000 pid=2511 execve guuid=bbbeef77-1a00-0000-f767-ab2ad9090000 pid=2521 /usr/bin/curl net send-data write-file guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=bbbeef77-1a00-0000-f767-ab2ad9090000 pid=2521 execve guuid=e17a9f7b-1a00-0000-f767-ab2ae2090000 pid=2530 /usr/bin/chmod guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=e17a9f7b-1a00-0000-f767-ab2ae2090000 pid=2530 execve guuid=cee7de7b-1a00-0000-f767-ab2ae4090000 pid=2532 /home/sandbox/sparc guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=cee7de7b-1a00-0000-f767-ab2ae4090000 pid=2532 execve guuid=4a4a127c-1a00-0000-f767-ab2ae6090000 pid=2534 /usr/bin/rm delete-file guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=4a4a127c-1a00-0000-f767-ab2ae6090000 pid=2534 execve guuid=eca5797c-1a00-0000-f767-ab2ae9090000 pid=2537 /usr/bin/wget net send-data guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=eca5797c-1a00-0000-f767-ab2ae9090000 pid=2537 execve guuid=7fafb07f-1a00-0000-f767-ab2aee090000 pid=2542 /usr/bin/curl net send-data write-file guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=7fafb07f-1a00-0000-f767-ab2aee090000 pid=2542 execve guuid=90b8ff85-1a00-0000-f767-ab2afc090000 pid=2556 /usr/bin/chmod guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=90b8ff85-1a00-0000-f767-ab2afc090000 pid=2556 execve guuid=69ad3c86-1a00-0000-f767-ab2afe090000 pid=2558 /home/sandbox/armv4l guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=69ad3c86-1a00-0000-f767-ab2afe090000 pid=2558 execve guuid=7e517386-1a00-0000-f767-ab2a000a0000 pid=2560 /usr/bin/rm delete-file guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=7e517386-1a00-0000-f767-ab2a000a0000 pid=2560 execve guuid=3a86b486-1a00-0000-f767-ab2a020a0000 pid=2562 /usr/bin/wget net send-data guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=3a86b486-1a00-0000-f767-ab2a020a0000 pid=2562 execve guuid=44b5ae89-1a00-0000-f767-ab2a080a0000 pid=2568 /usr/bin/curl net send-data write-file guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=44b5ae89-1a00-0000-f767-ab2a080a0000 pid=2568 execve guuid=824abd8d-1a00-0000-f767-ab2a120a0000 pid=2578 /usr/bin/chmod guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=824abd8d-1a00-0000-f767-ab2a120a0000 pid=2578 execve guuid=67ce208e-1a00-0000-f767-ab2a140a0000 pid=2580 /home/sandbox/armv5l guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=67ce208e-1a00-0000-f767-ab2a140a0000 pid=2580 execve guuid=77be5a8e-1a00-0000-f767-ab2a160a0000 pid=2582 /usr/bin/rm delete-file guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=77be5a8e-1a00-0000-f767-ab2a160a0000 pid=2582 execve guuid=bda49e8e-1a00-0000-f767-ab2a170a0000 pid=2583 /usr/bin/wget net send-data guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=bda49e8e-1a00-0000-f767-ab2a170a0000 pid=2583 execve guuid=f1c3da91-1a00-0000-f767-ab2a210a0000 pid=2593 /usr/bin/curl net send-data write-file guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=f1c3da91-1a00-0000-f767-ab2a210a0000 pid=2593 execve guuid=80db2c96-1a00-0000-f767-ab2a2d0a0000 pid=2605 /usr/bin/chmod guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=80db2c96-1a00-0000-f767-ab2a2d0a0000 pid=2605 execve guuid=e0136b96-1a00-0000-f767-ab2a2e0a0000 pid=2606 /home/sandbox/powerpcx440fp guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=e0136b96-1a00-0000-f767-ab2a2e0a0000 pid=2606 execve guuid=d41fb596-1a00-0000-f767-ab2a2f0a0000 pid=2607 /usr/bin/rm delete-file guuid=50669e10-1a00-0000-f767-ab2af4080000 pid=2292->guuid=d41fb596-1a00-0000-f767-ab2a2f0a0000 pid=2607 execve 9834677e-5001-5f34-ade9-94a06402bd7d 178.162.242.155:80 guuid=125ad910-1a00-0000-f767-ab2af6080000 pid=2294->9834677e-5001-5f34-ade9-94a06402bd7d send: 134B guuid=fa179115-1a00-0000-f767-ab2afe080000 pid=2302->9834677e-5001-5f34-ade9-94a06402bd7d send: 83B guuid=fcb0ac2e-1a00-0000-f767-ab2a14090000 pid=2324->9834677e-5001-5f34-ade9-94a06402bd7d send: 136B guuid=d3fbeb34-1a00-0000-f767-ab2a1c090000 pid=2332->9834677e-5001-5f34-ade9-94a06402bd7d send: 85B guuid=f15f133d-1a00-0000-f767-ab2a35090000 pid=2357->9834677e-5001-5f34-ade9-94a06402bd7d send: 136B guuid=5f12e73f-1a00-0000-f767-ab2a3d090000 pid=2365->9834677e-5001-5f34-ade9-94a06402bd7d send: 85B guuid=18872748-1a00-0000-f767-ab2a50090000 pid=2384->9834677e-5001-5f34-ade9-94a06402bd7d send: 136B guuid=bc1ee54a-1a00-0000-f767-ab2a5a090000 pid=2394->9834677e-5001-5f34-ade9-94a06402bd7d send: 85B guuid=d4ba3f51-1a00-0000-f767-ab2a6f090000 pid=2415->9834677e-5001-5f34-ade9-94a06402bd7d send: 134B guuid=30f01b54-1a00-0000-f767-ab2a75090000 pid=2421->9834677e-5001-5f34-ade9-94a06402bd7d send: 83B guuid=5c82ac59-1a00-0000-f767-ab2a81090000 pid=2433->9834677e-5001-5f34-ade9-94a06402bd7d send: 137B guuid=ad1ece5c-1a00-0000-f767-ab2a88090000 pid=2440->9834677e-5001-5f34-ade9-94a06402bd7d send: 86B guuid=399ea861-1a00-0000-f767-ab2a94090000 pid=2452->9834677e-5001-5f34-ade9-94a06402bd7d send: 134B guuid=dbc78f64-1a00-0000-f767-ab2a9e090000 pid=2462->9834677e-5001-5f34-ade9-94a06402bd7d send: 83B guuid=8089f66b-1a00-0000-f767-ab2ab2090000 pid=2482->9834677e-5001-5f34-ade9-94a06402bd7d send: 134B guuid=eb760d6f-1a00-0000-f767-ab2aba090000 pid=2490->9834677e-5001-5f34-ade9-94a06402bd7d send: 83B guuid=82a1d074-1a00-0000-f767-ab2acf090000 pid=2511->9834677e-5001-5f34-ade9-94a06402bd7d send: 135B guuid=bbbeef77-1a00-0000-f767-ab2ad9090000 pid=2521->9834677e-5001-5f34-ade9-94a06402bd7d send: 84B guuid=eca5797c-1a00-0000-f767-ab2ae9090000 pid=2537->9834677e-5001-5f34-ade9-94a06402bd7d send: 136B guuid=7fafb07f-1a00-0000-f767-ab2aee090000 pid=2542->9834677e-5001-5f34-ade9-94a06402bd7d send: 85B guuid=3a86b486-1a00-0000-f767-ab2a020a0000 pid=2562->9834677e-5001-5f34-ade9-94a06402bd7d send: 136B guuid=44b5ae89-1a00-0000-f767-ab2a080a0000 pid=2568->9834677e-5001-5f34-ade9-94a06402bd7d send: 85B guuid=bda49e8e-1a00-0000-f767-ab2a170a0000 pid=2583->9834677e-5001-5f34-ade9-94a06402bd7d send: 143B guuid=f1c3da91-1a00-0000-f767-ab2a210a0000 pid=2593->9834677e-5001-5f34-ade9-94a06402bd7d send: 92B
Threat name:
Script-Shell.Trojan.Geninst
Status:
Malicious
First seen:
2025-11-22 22:31:21 UTC
File Type:
Text (Shell)
AV detection:
15 of 37 (40.54%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 41abee81a9cf1657e98ea8c7a6a966d70e032d44cc3b526253fe636230c710df

(this sample)

  
Delivery method
Distributed via web download

Comments