MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4714a6681225bd25e3c9eee967bf9305f655f61fecc502270fbc177acd0ebc1c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: 4714a6681225bd25e3c9eee967bf9305f655f61fecc502270fbc177acd0ebc1c
SHA3-384 hash: bff16488d22ed7de16118abd06436e8211a7685e1960dd26ac12b32f8481173664424d2fe6f421c25679a7fb589ca6d9
SHA1 hash: 5c8adc513d614bd87c50f45b7ce0c58e143201b2
MD5 hash: 079688a05e660343a5a701c6342d4a7b
humanhash: delta-india-fish-rugby
File name:pXdN91.sh
Download: download sample
Signature Gafgyt
File size:2'036 bytes
First seen:2026-02-04 01:00:27 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:1e9a/seuXErhKAvqZA2YIOUo8oZ3v0biEvvSZXrvNAfE:1U4hKAwYIOUo8oRcI/
TLSH T1474190CB3360CAB8ACB4696F3229741071F9A0B69BBE9F441BD834D9848DD1C30C5A73
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://185.242.3.143/pXdN91.mipsb6f913923e9c8845b3c1fa47035e3bd3c0c1cbab3660d01d90fae3ec8801cb37 Gafgytelf gafgyt mirai ua-wget
http://185.242.3.143/pXdN91.mipsel8942eaaac37811aed637c9f8b194cc3764e5d37c34b94e00ba7b9352bb631cb5 Miraielf mirai ua-wget
http://185.242.3.143/pXdN91.sh48b279ece21d38c7ced805d3d96d4a67b884216ab3b8c6ea7ecdca79d17d3e643 Gafgytelf gafgyt ua-wget
http://185.242.3.143/pXdN91.x6852f0a4ad4cb268800c821a2d9626f3848986e5947dc607ecaa222a2d0922186e Miraielf mirai ua-wget
http://185.242.3.143/pXdN91.armv6l58b186d458c28353bef4661768d909c659f7f399406f3a22a43e900166463fa3 Miraielf gafgyt ua-wget
http://185.242.3.143/pXdN91.i686n/an/aelf ua-wget
http://185.242.3.143/pXdN91.ppc9034bc65224fcaebe0eed6e460129e23a038ecafcc6ee2ed86938fb785586fc6 Miraielf gafgyt mirai ua-wget
http://185.242.3.143/pXdN91.i586b10272ad6b129e7409a245a60e596b45194c848fb0985461bad94a65d3db4651 Miraielf mirai ua-wget
http://185.242.3.143/pXdN91.m68k66388b5108fef8ce48a788723ccdc59b69112c0a9c0ab5f19c3f44cb75175176 Gafgytelf gafgyt ua-wget
http://185.242.3.143/pXdN91.sparcf429f2987bad04075b042146bcdae14ab002c637be93b31fe39b0964217e2332 Miraielf gafgyt mirai ua-wget
http://185.242.3.143/pXdN91.armv4l72357f3bf1627b2b45df7e337454af60aa6f87a4e28544308b598df4d0fa4fdd Miraielf gafgyt mirai ua-wget
http://185.242.3.143/pXdN91.armv5l1d410cfe96b84f1b52da3d8c4627e022226cd1aa34d37a50d56ce8e7cd4aa592 Miraielf gafgyt mirai ua-wget
http://185.242.3.143/pXdN91.armv7l6d23aa17a30f7c9e07485171ab0f5b81719cd824789e3be39ddfe51f388a9636 Gafgytelf gafgyt ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
39
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive medusa mirai virus
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=9a4cade0-1700-0000-64a3-6fffd50b0000 pid=3029 /usr/bin/sudo guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037 /tmp/sample.bin guuid=9a4cade0-1700-0000-64a3-6fffd50b0000 pid=3029->guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037 execve guuid=6b5d4ce3-1700-0000-64a3-6fffe00b0000 pid=3040 /usr/bin/wget net send-data write-file guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=6b5d4ce3-1700-0000-64a3-6fffe00b0000 pid=3040 execve guuid=6970a8eb-1700-0000-64a3-6ffff80b0000 pid=3064 /usr/bin/chmod guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=6970a8eb-1700-0000-64a3-6ffff80b0000 pid=3064 execve guuid=745be9eb-1700-0000-64a3-6ffffa0b0000 pid=3066 /usr/bin/dash guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=745be9eb-1700-0000-64a3-6ffffa0b0000 pid=3066 clone guuid=8c4cf5eb-1700-0000-64a3-6ffffb0b0000 pid=3067 /usr/bin/rm delete-file guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=8c4cf5eb-1700-0000-64a3-6ffffb0b0000 pid=3067 execve guuid=c22f3dec-1700-0000-64a3-6ffffd0b0000 pid=3069 /usr/bin/wget net send-data write-file guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=c22f3dec-1700-0000-64a3-6ffffd0b0000 pid=3069 execve guuid=e2f4b4f1-1700-0000-64a3-6fff080c0000 pid=3080 /usr/bin/chmod guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=e2f4b4f1-1700-0000-64a3-6fff080c0000 pid=3080 execve guuid=b577f3f1-1700-0000-64a3-6fff0a0c0000 pid=3082 /usr/bin/dash guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=b577f3f1-1700-0000-64a3-6fff0a0c0000 pid=3082 clone guuid=6aa10af2-1700-0000-64a3-6fff0b0c0000 pid=3083 /usr/bin/rm delete-file guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=6aa10af2-1700-0000-64a3-6fff0b0c0000 pid=3083 execve guuid=3b265cf2-1700-0000-64a3-6fff0d0c0000 pid=3085 /usr/bin/wget net send-data write-file guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=3b265cf2-1700-0000-64a3-6fff0d0c0000 pid=3085 execve guuid=d16ddff7-1700-0000-64a3-6fff160c0000 pid=3094 /usr/bin/chmod guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=d16ddff7-1700-0000-64a3-6fff160c0000 pid=3094 execve guuid=689629f8-1700-0000-64a3-6fff180c0000 pid=3096 /usr/bin/dash guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=689629f8-1700-0000-64a3-6fff180c0000 pid=3096 clone guuid=724f43f8-1700-0000-64a3-6fff190c0000 pid=3097 /usr/bin/rm delete-file guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=724f43f8-1700-0000-64a3-6fff190c0000 pid=3097 execve guuid=984d84f8-1700-0000-64a3-6fff1b0c0000 pid=3099 /usr/bin/wget net send-data guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=984d84f8-1700-0000-64a3-6fff1b0c0000 pid=3099 execve guuid=5310b5fc-1700-0000-64a3-6fff260c0000 pid=3110 /usr/bin/chmod guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=5310b5fc-1700-0000-64a3-6fff260c0000 pid=3110 execve guuid=b0cbfdfc-1700-0000-64a3-6fff270c0000 pid=3111 /usr/bin/dash guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=b0cbfdfc-1700-0000-64a3-6fff270c0000 pid=3111 clone guuid=0c1006fd-1700-0000-64a3-6fff290c0000 pid=3113 /usr/bin/rm guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=0c1006fd-1700-0000-64a3-6fff290c0000 pid=3113 execve guuid=85b84dfd-1700-0000-64a3-6fff2b0c0000 pid=3115 /usr/bin/wget net send-data write-file guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=85b84dfd-1700-0000-64a3-6fff2b0c0000 pid=3115 execve guuid=8becc502-1800-0000-64a3-6fff3b0c0000 pid=3131 /usr/bin/chmod guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=8becc502-1800-0000-64a3-6fff3b0c0000 pid=3131 execve guuid=91702203-1800-0000-64a3-6fff3d0c0000 pid=3133 /usr/bin/dash guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=91702203-1800-0000-64a3-6fff3d0c0000 pid=3133 clone guuid=accb2f03-1800-0000-64a3-6fff3e0c0000 pid=3134 /usr/bin/rm delete-file guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=accb2f03-1800-0000-64a3-6fff3e0c0000 pid=3134 execve guuid=cc1e7803-1800-0000-64a3-6fff400c0000 pid=3136 /usr/bin/wget net send-data guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=cc1e7803-1800-0000-64a3-6fff400c0000 pid=3136 execve guuid=27b63b06-1800-0000-64a3-6fff4c0c0000 pid=3148 /usr/bin/chmod guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=27b63b06-1800-0000-64a3-6fff4c0c0000 pid=3148 execve guuid=fe997506-1800-0000-64a3-6fff4e0c0000 pid=3150 /usr/bin/dash guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=fe997506-1800-0000-64a3-6fff4e0c0000 pid=3150 clone guuid=d01e7c06-1800-0000-64a3-6fff4f0c0000 pid=3151 /usr/bin/rm guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=d01e7c06-1800-0000-64a3-6fff4f0c0000 pid=3151 execve guuid=44a1ae06-1800-0000-64a3-6fff500c0000 pid=3152 /usr/bin/wget net send-data write-file guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=44a1ae06-1800-0000-64a3-6fff500c0000 pid=3152 execve guuid=c53fcd0b-1800-0000-64a3-6fff5a0c0000 pid=3162 /usr/bin/chmod guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=c53fcd0b-1800-0000-64a3-6fff5a0c0000 pid=3162 execve guuid=050e020c-1800-0000-64a3-6fff5c0c0000 pid=3164 /usr/bin/dash guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=050e020c-1800-0000-64a3-6fff5c0c0000 pid=3164 clone guuid=5f290d0c-1800-0000-64a3-6fff5d0c0000 pid=3165 /usr/bin/rm delete-file guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=5f290d0c-1800-0000-64a3-6fff5d0c0000 pid=3165 execve guuid=6e904f0c-1800-0000-64a3-6fff5f0c0000 pid=3167 /usr/bin/wget net send-data write-file guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=6e904f0c-1800-0000-64a3-6fff5f0c0000 pid=3167 execve guuid=32895911-1800-0000-64a3-6fff690c0000 pid=3177 /usr/bin/chmod guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=32895911-1800-0000-64a3-6fff690c0000 pid=3177 execve guuid=144dd011-1800-0000-64a3-6fff6b0c0000 pid=3179 /usr/bin/dash guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=144dd011-1800-0000-64a3-6fff6b0c0000 pid=3179 clone guuid=3ef5df11-1800-0000-64a3-6fff6c0c0000 pid=3180 /usr/bin/rm delete-file guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=3ef5df11-1800-0000-64a3-6fff6c0c0000 pid=3180 execve guuid=b7842212-1800-0000-64a3-6fff6e0c0000 pid=3182 /usr/bin/wget net send-data write-file guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=b7842212-1800-0000-64a3-6fff6e0c0000 pid=3182 execve guuid=53853b17-1800-0000-64a3-6fff770c0000 pid=3191 /usr/bin/chmod guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=53853b17-1800-0000-64a3-6fff770c0000 pid=3191 execve guuid=ce5f8717-1800-0000-64a3-6fff790c0000 pid=3193 /usr/bin/dash guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=ce5f8717-1800-0000-64a3-6fff790c0000 pid=3193 clone guuid=87119717-1800-0000-64a3-6fff7a0c0000 pid=3194 /usr/bin/rm delete-file guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=87119717-1800-0000-64a3-6fff7a0c0000 pid=3194 execve guuid=f7941a18-1800-0000-64a3-6fff7b0c0000 pid=3195 /usr/bin/wget net send-data write-file guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=f7941a18-1800-0000-64a3-6fff7b0c0000 pid=3195 execve guuid=12e6d81e-1800-0000-64a3-6fff820c0000 pid=3202 /usr/bin/chmod guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=12e6d81e-1800-0000-64a3-6fff820c0000 pid=3202 execve guuid=ff5b451f-1800-0000-64a3-6fff830c0000 pid=3203 /usr/bin/dash guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=ff5b451f-1800-0000-64a3-6fff830c0000 pid=3203 clone guuid=3ea4601f-1800-0000-64a3-6fff840c0000 pid=3204 /usr/bin/rm delete-file guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=3ea4601f-1800-0000-64a3-6fff840c0000 pid=3204 execve guuid=11c10220-1800-0000-64a3-6fff850c0000 pid=3205 /usr/bin/wget net send-data write-file guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=11c10220-1800-0000-64a3-6fff850c0000 pid=3205 execve guuid=33490026-1800-0000-64a3-6fff860c0000 pid=3206 /usr/bin/chmod guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=33490026-1800-0000-64a3-6fff860c0000 pid=3206 execve guuid=05dd0c27-1800-0000-64a3-6fff870c0000 pid=3207 /usr/bin/dash guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=05dd0c27-1800-0000-64a3-6fff870c0000 pid=3207 clone guuid=40c33327-1800-0000-64a3-6fff880c0000 pid=3208 /usr/bin/rm delete-file guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=40c33327-1800-0000-64a3-6fff880c0000 pid=3208 execve guuid=cc302e28-1800-0000-64a3-6fff890c0000 pid=3209 /usr/bin/wget net send-data write-file guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=cc302e28-1800-0000-64a3-6fff890c0000 pid=3209 execve guuid=a076132e-1800-0000-64a3-6fff8c0c0000 pid=3212 /usr/bin/chmod guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=a076132e-1800-0000-64a3-6fff8c0c0000 pid=3212 execve guuid=d09d862e-1800-0000-64a3-6fff8e0c0000 pid=3214 /usr/bin/dash guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=d09d862e-1800-0000-64a3-6fff8e0c0000 pid=3214 clone guuid=276d9b2e-1800-0000-64a3-6fff8f0c0000 pid=3215 /usr/bin/rm delete-file guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=276d9b2e-1800-0000-64a3-6fff8f0c0000 pid=3215 execve guuid=eb862b2f-1800-0000-64a3-6fff910c0000 pid=3217 /usr/bin/wget net send-data write-file guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=eb862b2f-1800-0000-64a3-6fff910c0000 pid=3217 execve guuid=da3ad736-1800-0000-64a3-6fff9e0c0000 pid=3230 /usr/bin/chmod guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=da3ad736-1800-0000-64a3-6fff9e0c0000 pid=3230 execve guuid=b9494f37-1800-0000-64a3-6fffa00c0000 pid=3232 /usr/bin/dash guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=b9494f37-1800-0000-64a3-6fffa00c0000 pid=3232 clone guuid=fe9f6737-1800-0000-64a3-6fffa10c0000 pid=3233 /usr/bin/rm delete-file guuid=e07cd3e2-1700-0000-64a3-6fffdd0b0000 pid=3037->guuid=fe9f6737-1800-0000-64a3-6fffa10c0000 pid=3233 execve 07f980ea-6c7d-59f9-90bf-dda55e295103 185.242.3.143:80 guuid=6b5d4ce3-1700-0000-64a3-6fffe00b0000 pid=3040->07f980ea-6c7d-59f9-90bf-dda55e295103 send: 139B guuid=c22f3dec-1700-0000-64a3-6ffffd0b0000 pid=3069->07f980ea-6c7d-59f9-90bf-dda55e295103 send: 141B guuid=3b265cf2-1700-0000-64a3-6fff0d0c0000 pid=3085->07f980ea-6c7d-59f9-90bf-dda55e295103 send: 138B guuid=984d84f8-1700-0000-64a3-6fff1b0c0000 pid=3099->07f980ea-6c7d-59f9-90bf-dda55e295103 send: 138B guuid=85b84dfd-1700-0000-64a3-6fff2b0c0000 pid=3115->07f980ea-6c7d-59f9-90bf-dda55e295103 send: 141B guuid=cc1e7803-1800-0000-64a3-6fff400c0000 pid=3136->07f980ea-6c7d-59f9-90bf-dda55e295103 send: 139B guuid=44a1ae06-1800-0000-64a3-6fff500c0000 pid=3152->07f980ea-6c7d-59f9-90bf-dda55e295103 send: 138B guuid=6e904f0c-1800-0000-64a3-6fff5f0c0000 pid=3167->07f980ea-6c7d-59f9-90bf-dda55e295103 send: 139B guuid=b7842212-1800-0000-64a3-6fff6e0c0000 pid=3182->07f980ea-6c7d-59f9-90bf-dda55e295103 send: 139B guuid=f7941a18-1800-0000-64a3-6fff7b0c0000 pid=3195->07f980ea-6c7d-59f9-90bf-dda55e295103 send: 140B guuid=11c10220-1800-0000-64a3-6fff850c0000 pid=3205->07f980ea-6c7d-59f9-90bf-dda55e295103 send: 141B guuid=cc302e28-1800-0000-64a3-6fff890c0000 pid=3209->07f980ea-6c7d-59f9-90bf-dda55e295103 send: 141B guuid=eb862b2f-1800-0000-64a3-6fff910c0000 pid=3217->07f980ea-6c7d-59f9-90bf-dda55e295103 send: 141B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-02-04 01:01:51 UTC
File Type:
Text (Shell)
AV detection:
21 of 36 (58.33%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 4714a6681225bd25e3c9eee967bf9305f655f61fecc502270fbc177acd0ebc1c

(this sample)

  
Delivery method
Distributed via web download

Comments