MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4b36a87f1cf4d953e6ab87ec7a33d875564e3669574ce5e9ebcd281523a09cd1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: 4b36a87f1cf4d953e6ab87ec7a33d875564e3669574ce5e9ebcd281523a09cd1
SHA3-384 hash: 24379570708971f8c23c6c22930e16ecc3936d5a1f44f4662590d3f592d3ff8dfd059e32ff9881147165f06f2a6c9e76
SHA1 hash: 87ad7b2c3b2e3f9d464ab2d44ba9178929a00572
MD5 hash: 3cc54d96ed956d9a230ea3512a2551ba
humanhash: six-seven-friend-stream
File name:Cia.sh
Download: download sample
Signature Gafgyt
File size:1'825 bytes
First seen:2026-06-11 02:49:10 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:I9LoBBtg7PZgLgMghTgEbDYN4pGC1r/oHhCNIZw/Nkg/wKRoPEDvuPX9:ScB8GR0xbcc17oHo/N5YUoMD2F
TLSH T1E93114DB3011A833B57DEA5FB7BAE5985010C5F63297FB53ED894975CC89B183389A00
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:gafgyt sh
URLMalware sample (SHA256 hash)SignatureTags
http://150.40.127.154/FBI.x86_6418be43df55ff6bd73ba34df1fcb08132a40a98de1cc4365be335f4a1cdfed0d9 Gafgytelf gafgyt mirai ua-wget x86
http://150.40.127.154/FBI.x868dcc6d4480266b140eb989d6cbe68cb58352710933cd0b735366cf00644c44f0 Gafgytelf gafgyt mirai ua-wget x86
http://150.40.127.154/FBI.i6868d808fb89a9f9b6428090e4b371715bc552e4db4ef4e09c814b0b8be374b729c Gafgytelf gafgyt mirai ua-wget x86
http://150.40.127.154/FBI.mipsa60e41c57e3931dcee1520e1401e404302b643e43cb72470e8e79cf351f5852b Gafgytelf gafgyt mips mirai ua-wget
http://150.40.127.154/FBI.mipselb6b0dccf402d349d93ed1220675be4d63fd506e1a207732924a98caea8813ce9 Gafgytelf gafgyt mips mirai ua-wget
http://150.40.127.154/FBI.armf398e8417f7f1d5fde48772b954abf2c13c186ebf315f44627b9a9f804613191 Gafgytarm elf gafgyt mirai ua-wget
http://150.40.127.154/FBI.arm53e85e94ea0fc1e9eb741c123cdbff847ca194a6964e611acb715f22dc705298b Gafgytarm elf gafgyt mirai ua-wget
http://150.40.127.154/FBI.arm63b02909d869aa642bc90ed51a9b45331d49bd66316a96e41ff63d75a1bffdc96 Gafgytarm elf gafgyt mirai ua-wget
http://150.40.127.154/FBI.arm702b4a57b68781020a57ff60e673617ee23f1a0b85b46bfc390e9608db27a3501 Gafgytarm elf gafgyt mirai ua-wget
http://150.40.127.154/FBI.ppc05c778187ff079456fead10405ab911f31fa40a6a501178f34245c13ae737f09 Gafgytelf gafgyt mirai PowerPC ua-wget
http://150.40.127.154/FBI.m68k3704c29dbde14a3daa1c739197e4c0ae5ebbf91594f686a1be3dbaf5a95ff00d Gafgytelf gafgyt m68k mirai ua-wget
http://150.40.127.154/FBI.sh4793e22e2643231deab714c4c4a309d6ba9c0424fa41a320bfa72f42aad3fa5a7 Gafgytelf gafgyt mirai SuperH ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-11T00:01:00Z UTC
Last seen:
2026-06-12T18:38:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=c2c88820-1a00-0000-c377-d22bbf070000 pid=1983 /usr/bin/sudo guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984 /tmp/sample.bin guuid=c2c88820-1a00-0000-c377-d22bbf070000 pid=1983->guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984 execve guuid=8bc4f324-1a00-0000-c377-d22bc1070000 pid=1985 /usr/bin/cp guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=8bc4f324-1a00-0000-c377-d22bc1070000 pid=1985 execve guuid=0b90e42d-1a00-0000-c377-d22bc3070000 pid=1987 /usr/bin/wget net send-data write-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=0b90e42d-1a00-0000-c377-d22bc3070000 pid=1987 execve guuid=5172e935-1a00-0000-c377-d22bcb070000 pid=1995 /usr/bin/curl net send-data write-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=5172e935-1a00-0000-c377-d22bcb070000 pid=1995 execve guuid=a45ade42-1a00-0000-c377-d22bdc070000 pid=2012 /usr/bin/chmod guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=a45ade42-1a00-0000-c377-d22bdc070000 pid=2012 execve guuid=dd9d5443-1a00-0000-c377-d22bde070000 pid=2014 /tmp/FBI.x86_64 net guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=dd9d5443-1a00-0000-c377-d22bde070000 pid=2014 execve guuid=3b3db044-1a00-0000-c377-d22be7070000 pid=2023 /usr/bin/rm delete-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=3b3db044-1a00-0000-c377-d22be7070000 pid=2023 execve guuid=da863a46-1a00-0000-c377-d22be9070000 pid=2025 /usr/bin/wget net send-data write-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=da863a46-1a00-0000-c377-d22be9070000 pid=2025 execve guuid=2ce4a54c-1a00-0000-c377-d22bf7070000 pid=2039 /usr/bin/curl net send-data write-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=2ce4a54c-1a00-0000-c377-d22bf7070000 pid=2039 execve guuid=5e8cda53-1a00-0000-c377-d22b03080000 pid=2051 /usr/bin/chmod guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=5e8cda53-1a00-0000-c377-d22b03080000 pid=2051 execve guuid=e0bd2f54-1a00-0000-c377-d22b05080000 pid=2053 /tmp/FBI.x86 net guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=e0bd2f54-1a00-0000-c377-d22b05080000 pid=2053 execve guuid=d52dc259-1a00-0000-c377-d22b18080000 pid=2072 /usr/bin/rm delete-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=d52dc259-1a00-0000-c377-d22b18080000 pid=2072 execve guuid=a4990d5a-1a00-0000-c377-d22b1a080000 pid=2074 /usr/bin/wget net send-data write-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=a4990d5a-1a00-0000-c377-d22b1a080000 pid=2074 execve guuid=df19e25e-1a00-0000-c377-d22b24080000 pid=2084 /usr/bin/curl net send-data write-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=df19e25e-1a00-0000-c377-d22b24080000 pid=2084 execve guuid=75060a64-1a00-0000-c377-d22b2c080000 pid=2092 /usr/bin/chmod guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=75060a64-1a00-0000-c377-d22b2c080000 pid=2092 execve guuid=ad5a5a64-1a00-0000-c377-d22b2d080000 pid=2093 /tmp/FBI.i686 net guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=ad5a5a64-1a00-0000-c377-d22b2d080000 pid=2093 execve guuid=96c30c6a-1a00-0000-c377-d22b39080000 pid=2105 /usr/bin/rm delete-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=96c30c6a-1a00-0000-c377-d22b39080000 pid=2105 execve guuid=f896b76a-1a00-0000-c377-d22b3a080000 pid=2106 /usr/bin/wget net send-data write-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=f896b76a-1a00-0000-c377-d22b3a080000 pid=2106 execve guuid=15131770-1a00-0000-c377-d22b43080000 pid=2115 /usr/bin/curl net send-data write-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=15131770-1a00-0000-c377-d22b43080000 pid=2115 execve guuid=88621679-1a00-0000-c377-d22b55080000 pid=2133 /usr/bin/chmod guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=88621679-1a00-0000-c377-d22b55080000 pid=2133 execve guuid=d9bb6779-1a00-0000-c377-d22b57080000 pid=2135 /usr/bin/bash guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=d9bb6779-1a00-0000-c377-d22b57080000 pid=2135 clone guuid=88e1757a-1a00-0000-c377-d22b5a080000 pid=2138 /usr/bin/rm delete-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=88e1757a-1a00-0000-c377-d22b5a080000 pid=2138 execve guuid=257d4d7b-1a00-0000-c377-d22b5d080000 pid=2141 /usr/bin/wget net send-data write-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=257d4d7b-1a00-0000-c377-d22b5d080000 pid=2141 execve guuid=9cbf8b82-1a00-0000-c377-d22b6a080000 pid=2154 /usr/bin/curl net send-data write-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=9cbf8b82-1a00-0000-c377-d22b6a080000 pid=2154 execve guuid=6722f789-1a00-0000-c377-d22b74080000 pid=2164 /usr/bin/chmod guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=6722f789-1a00-0000-c377-d22b74080000 pid=2164 execve guuid=fada428a-1a00-0000-c377-d22b76080000 pid=2166 /usr/bin/bash guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=fada428a-1a00-0000-c377-d22b76080000 pid=2166 clone guuid=ee7de08a-1a00-0000-c377-d22b79080000 pid=2169 /usr/bin/rm delete-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=ee7de08a-1a00-0000-c377-d22b79080000 pid=2169 execve guuid=8fe47c8b-1a00-0000-c377-d22b7b080000 pid=2171 /usr/bin/wget net send-data write-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=8fe47c8b-1a00-0000-c377-d22b7b080000 pid=2171 execve guuid=8c719792-1a00-0000-c377-d22b88080000 pid=2184 /usr/bin/curl net send-data write-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=8c719792-1a00-0000-c377-d22b88080000 pid=2184 execve guuid=7134d49a-1a00-0000-c377-d22b97080000 pid=2199 /usr/bin/chmod guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=7134d49a-1a00-0000-c377-d22b97080000 pid=2199 execve guuid=7d305f9b-1a00-0000-c377-d22b99080000 pid=2201 /usr/bin/bash guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=7d305f9b-1a00-0000-c377-d22b99080000 pid=2201 clone guuid=6f54069d-1a00-0000-c377-d22b9e080000 pid=2206 /usr/bin/rm delete-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=6f54069d-1a00-0000-c377-d22b9e080000 pid=2206 execve guuid=38c2649d-1a00-0000-c377-d22ba0080000 pid=2208 /usr/bin/wget net send-data write-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=38c2649d-1a00-0000-c377-d22ba0080000 pid=2208 execve guuid=eafc01a4-1a00-0000-c377-d22bac080000 pid=2220 /usr/bin/curl net send-data write-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=eafc01a4-1a00-0000-c377-d22bac080000 pid=2220 execve guuid=f23ed6ac-1a00-0000-c377-d22bc2080000 pid=2242 /usr/bin/chmod guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=f23ed6ac-1a00-0000-c377-d22bc2080000 pid=2242 execve guuid=335a35ad-1a00-0000-c377-d22bc4080000 pid=2244 /usr/bin/bash guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=335a35ad-1a00-0000-c377-d22bc4080000 pid=2244 clone guuid=573b04ae-1a00-0000-c377-d22bc8080000 pid=2248 /usr/bin/rm delete-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=573b04ae-1a00-0000-c377-d22bc8080000 pid=2248 execve guuid=1fe57cae-1a00-0000-c377-d22bc9080000 pid=2249 /usr/bin/wget net send-data write-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=1fe57cae-1a00-0000-c377-d22bc9080000 pid=2249 execve guuid=bb9225b4-1a00-0000-c377-d22bd8080000 pid=2264 /usr/bin/curl net send-data write-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=bb9225b4-1a00-0000-c377-d22bd8080000 pid=2264 execve guuid=29b0fbc0-1a00-0000-c377-d22bf7080000 pid=2295 /usr/bin/chmod guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=29b0fbc0-1a00-0000-c377-d22bf7080000 pid=2295 execve guuid=b46b71c1-1a00-0000-c377-d22bf9080000 pid=2297 /usr/bin/bash guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=b46b71c1-1a00-0000-c377-d22bf9080000 pid=2297 clone guuid=eb266ec2-1a00-0000-c377-d22bfd080000 pid=2301 /usr/bin/rm delete-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=eb266ec2-1a00-0000-c377-d22bfd080000 pid=2301 execve guuid=db93dec2-1a00-0000-c377-d22bff080000 pid=2303 /usr/bin/wget net send-data write-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=db93dec2-1a00-0000-c377-d22bff080000 pid=2303 execve guuid=31253dc8-1a00-0000-c377-d22b0b090000 pid=2315 /usr/bin/curl net send-data write-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=31253dc8-1a00-0000-c377-d22b0b090000 pid=2315 execve guuid=22ef42d0-1a00-0000-c377-d22b19090000 pid=2329 /usr/bin/chmod guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=22ef42d0-1a00-0000-c377-d22b19090000 pid=2329 execve guuid=4d3197d0-1a00-0000-c377-d22b1b090000 pid=2331 /usr/bin/bash guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=4d3197d0-1a00-0000-c377-d22b1b090000 pid=2331 clone guuid=e832d8d2-1a00-0000-c377-d22b21090000 pid=2337 /usr/bin/rm delete-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=e832d8d2-1a00-0000-c377-d22b21090000 pid=2337 execve guuid=fd7f49d3-1a00-0000-c377-d22b24090000 pid=2340 /usr/bin/wget net send-data write-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=fd7f49d3-1a00-0000-c377-d22b24090000 pid=2340 execve guuid=52987bd8-1a00-0000-c377-d22b2c090000 pid=2348 /usr/bin/curl net send-data write-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=52987bd8-1a00-0000-c377-d22b2c090000 pid=2348 execve guuid=da508fdf-1a00-0000-c377-d22b3e090000 pid=2366 /usr/bin/chmod guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=da508fdf-1a00-0000-c377-d22b3e090000 pid=2366 execve guuid=2a4725e0-1a00-0000-c377-d22b40090000 pid=2368 /usr/bin/bash guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=2a4725e0-1a00-0000-c377-d22b40090000 pid=2368 clone guuid=f514b3e0-1a00-0000-c377-d22b42090000 pid=2370 /usr/bin/rm delete-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=f514b3e0-1a00-0000-c377-d22b42090000 pid=2370 execve guuid=c33a04e1-1a00-0000-c377-d22b44090000 pid=2372 /usr/bin/wget net send-data write-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=c33a04e1-1a00-0000-c377-d22b44090000 pid=2372 execve guuid=b0d71ee7-1a00-0000-c377-d22b51090000 pid=2385 /usr/bin/curl net send-data write-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=b0d71ee7-1a00-0000-c377-d22b51090000 pid=2385 execve guuid=3d1f29ef-1a00-0000-c377-d22b5d090000 pid=2397 /usr/bin/chmod guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=3d1f29ef-1a00-0000-c377-d22b5d090000 pid=2397 execve guuid=5526a3ef-1a00-0000-c377-d22b5f090000 pid=2399 /usr/bin/bash guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=5526a3ef-1a00-0000-c377-d22b5f090000 pid=2399 clone guuid=b58db9f0-1a00-0000-c377-d22b62090000 pid=2402 /usr/bin/rm delete-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=b58db9f0-1a00-0000-c377-d22b62090000 pid=2402 execve guuid=f25636f1-1a00-0000-c377-d22b64090000 pid=2404 /usr/bin/wget net send-data write-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=f25636f1-1a00-0000-c377-d22b64090000 pid=2404 execve guuid=16eb09f6-1a00-0000-c377-d22b69090000 pid=2409 /usr/bin/curl net send-data write-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=16eb09f6-1a00-0000-c377-d22b69090000 pid=2409 execve guuid=bfbdd7fc-1a00-0000-c377-d22b77090000 pid=2423 /usr/bin/chmod guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=bfbdd7fc-1a00-0000-c377-d22b77090000 pid=2423 execve guuid=d0964cfd-1a00-0000-c377-d22b7a090000 pid=2426 /usr/bin/bash guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=d0964cfd-1a00-0000-c377-d22b7a090000 pid=2426 clone guuid=c848a3ff-1a00-0000-c377-d22b80090000 pid=2432 /usr/bin/rm delete-file guuid=113fbb23-1a00-0000-c377-d22bc0070000 pid=1984->guuid=c848a3ff-1a00-0000-c377-d22b80090000 pid=2432 execve b3e29b12-1aeb-5d8d-bbbb-2d9c211df19b 150.40.127.154:80 guuid=0b90e42d-1a00-0000-c377-d22bc3070000 pid=1987->b3e29b12-1aeb-5d8d-bbbb-2d9c211df19b send: 139B guuid=5172e935-1a00-0000-c377-d22bcb070000 pid=1995->b3e29b12-1aeb-5d8d-bbbb-2d9c211df19b send: 88B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=dd9d5443-1a00-0000-c377-d22bde070000 pid=2014->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3eff7043-1a00-0000-c377-d22be0070000 pid=2016 /tmp/FBI.x86_64 guuid=dd9d5443-1a00-0000-c377-d22bde070000 pid=2014->guuid=3eff7043-1a00-0000-c377-d22be0070000 pid=2016 clone guuid=c0f47843-1a00-0000-c377-d22be1070000 pid=2017 /tmp/FBI.x86_64 net send-data write-file zombie guuid=dd9d5443-1a00-0000-c377-d22bde070000 pid=2014->guuid=c0f47843-1a00-0000-c377-d22be1070000 pid=2017 clone cb45f4e0-8c85-55b4-a21f-e458f5c966c8 150.40.127.154:6969 guuid=c0f47843-1a00-0000-c377-d22be1070000 pid=2017->cb45f4e0-8c85-55b4-a21f-e458f5c966c8 send: 28593B guuid=bab49d43-1a00-0000-c377-d22be2070000 pid=2018 /tmp/FBI.x86_64 net send-data write-file guuid=c0f47843-1a00-0000-c377-d22be1070000 pid=2017->guuid=bab49d43-1a00-0000-c377-d22be2070000 pid=2018 clone guuid=12c8e8ba-1a00-0000-c377-d22be8080000 pid=2280 /tmp/FBI.x86_64 guuid=c0f47843-1a00-0000-c377-d22be1070000 pid=2017->guuid=12c8e8ba-1a00-0000-c377-d22be8080000 pid=2280 clone guuid=bab49d43-1a00-0000-c377-d22be2070000 pid=2018->cb45f4e0-8c85-55b4-a21f-e458f5c966c8 send: 27B guuid=3d11ac43-1a00-0000-c377-d22be3070000 pid=2019 /tmp/FBI.x86_64 guuid=bab49d43-1a00-0000-c377-d22be2070000 pid=2018->guuid=3d11ac43-1a00-0000-c377-d22be3070000 pid=2019 clone guuid=201904b3-1e00-0000-c377-d22b44100000 pid=4164 /tmp/FBI.x86_64 net send-data guuid=bab49d43-1a00-0000-c377-d22be2070000 pid=2018->guuid=201904b3-1e00-0000-c377-d22b44100000 pid=4164 clone guuid=152cd843-1a00-0000-c377-d22be5070000 pid=2021 /tmp/FBI.x86_64 guuid=3d11ac43-1a00-0000-c377-d22be3070000 pid=2019->guuid=152cd843-1a00-0000-c377-d22be5070000 pid=2021 clone guuid=da863a46-1a00-0000-c377-d22be9070000 pid=2025->b3e29b12-1aeb-5d8d-bbbb-2d9c211df19b send: 136B guuid=2ce4a54c-1a00-0000-c377-d22bf7070000 pid=2039->b3e29b12-1aeb-5d8d-bbbb-2d9c211df19b send: 85B guuid=e0bd2f54-1a00-0000-c377-d22b05080000 pid=2053->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c3bc4d54-1a00-0000-c377-d22b06080000 pid=2054 /tmp/FBI.x86 guuid=e0bd2f54-1a00-0000-c377-d22b05080000 pid=2053->guuid=c3bc4d54-1a00-0000-c377-d22b06080000 pid=2054 clone guuid=cc7c5e54-1a00-0000-c377-d22b07080000 pid=2055 /tmp/FBI.x86 net send-data write-file zombie guuid=e0bd2f54-1a00-0000-c377-d22b05080000 pid=2053->guuid=cc7c5e54-1a00-0000-c377-d22b07080000 pid=2055 clone guuid=cc7c5e54-1a00-0000-c377-d22b07080000 pid=2055->cb45f4e0-8c85-55b4-a21f-e458f5c966c8 send: 21459B guuid=0768cc55-1a00-0000-c377-d22b0b080000 pid=2059 /tmp/FBI.x86 net send-data write-file guuid=cc7c5e54-1a00-0000-c377-d22b07080000 pid=2055->guuid=0768cc55-1a00-0000-c377-d22b0b080000 pid=2059 clone guuid=c8ba23cd-1a00-0000-c377-d22b13090000 pid=2323 /tmp/FBI.x86 guuid=cc7c5e54-1a00-0000-c377-d22b07080000 pid=2055->guuid=c8ba23cd-1a00-0000-c377-d22b13090000 pid=2323 clone guuid=0768cc55-1a00-0000-c377-d22b0b080000 pid=2059->cb45f4e0-8c85-55b4-a21f-e458f5c966c8 send: 21321B guuid=ebeae555-1a00-0000-c377-d22b0c080000 pid=2060 /tmp/FBI.x86 guuid=0768cc55-1a00-0000-c377-d22b0b080000 pid=2059->guuid=ebeae555-1a00-0000-c377-d22b0c080000 pid=2060 clone guuid=902dfe55-1a00-0000-c377-d22b0d080000 pid=2061 /tmp/FBI.x86 guuid=ebeae555-1a00-0000-c377-d22b0c080000 pid=2060->guuid=902dfe55-1a00-0000-c377-d22b0d080000 pid=2061 clone guuid=a4990d5a-1a00-0000-c377-d22b1a080000 pid=2074->b3e29b12-1aeb-5d8d-bbbb-2d9c211df19b send: 137B guuid=df19e25e-1a00-0000-c377-d22b24080000 pid=2084->b3e29b12-1aeb-5d8d-bbbb-2d9c211df19b send: 86B guuid=ad5a5a64-1a00-0000-c377-d22b2d080000 pid=2093->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=be158364-1a00-0000-c377-d22b2e080000 pid=2094 /tmp/FBI.i686 guuid=ad5a5a64-1a00-0000-c377-d22b2d080000 pid=2093->guuid=be158364-1a00-0000-c377-d22b2e080000 pid=2094 clone guuid=34d79864-1a00-0000-c377-d22b2f080000 pid=2095 /tmp/FBI.i686 net send-data write-file zombie guuid=ad5a5a64-1a00-0000-c377-d22b2d080000 pid=2093->guuid=34d79864-1a00-0000-c377-d22b2f080000 pid=2095 clone guuid=34d79864-1a00-0000-c377-d22b2f080000 pid=2095->cb45f4e0-8c85-55b4-a21f-e458f5c966c8 send: 23112B guuid=456fcc64-1a00-0000-c377-d22b30080000 pid=2096 /tmp/FBI.i686 net send-data write-file guuid=34d79864-1a00-0000-c377-d22b2f080000 pid=2095->guuid=456fcc64-1a00-0000-c377-d22b30080000 pid=2096 clone guuid=670843dc-1a00-0000-c377-d22b34090000 pid=2356 /tmp/FBI.i686 guuid=34d79864-1a00-0000-c377-d22b2f080000 pid=2095->guuid=670843dc-1a00-0000-c377-d22b34090000 pid=2356 clone guuid=456fcc64-1a00-0000-c377-d22b30080000 pid=2096->cb45f4e0-8c85-55b4-a21f-e458f5c966c8 send: 23784B guuid=67a6ff64-1a00-0000-c377-d22b31080000 pid=2097 /tmp/FBI.i686 guuid=456fcc64-1a00-0000-c377-d22b30080000 pid=2096->guuid=67a6ff64-1a00-0000-c377-d22b31080000 pid=2097 clone guuid=a6773b66-1a00-0000-c377-d22b32080000 pid=2098 /tmp/FBI.i686 guuid=67a6ff64-1a00-0000-c377-d22b31080000 pid=2097->guuid=a6773b66-1a00-0000-c377-d22b32080000 pid=2098 clone guuid=f896b76a-1a00-0000-c377-d22b3a080000 pid=2106->b3e29b12-1aeb-5d8d-bbbb-2d9c211df19b send: 137B guuid=15131770-1a00-0000-c377-d22b43080000 pid=2115->b3e29b12-1aeb-5d8d-bbbb-2d9c211df19b send: 86B guuid=257d4d7b-1a00-0000-c377-d22b5d080000 pid=2141->b3e29b12-1aeb-5d8d-bbbb-2d9c211df19b send: 139B guuid=9cbf8b82-1a00-0000-c377-d22b6a080000 pid=2154->b3e29b12-1aeb-5d8d-bbbb-2d9c211df19b send: 88B guuid=8fe47c8b-1a00-0000-c377-d22b7b080000 pid=2171->b3e29b12-1aeb-5d8d-bbbb-2d9c211df19b send: 136B guuid=8c719792-1a00-0000-c377-d22b88080000 pid=2184->b3e29b12-1aeb-5d8d-bbbb-2d9c211df19b send: 85B guuid=38c2649d-1a00-0000-c377-d22ba0080000 pid=2208->b3e29b12-1aeb-5d8d-bbbb-2d9c211df19b send: 137B guuid=eafc01a4-1a00-0000-c377-d22bac080000 pid=2220->b3e29b12-1aeb-5d8d-bbbb-2d9c211df19b send: 86B guuid=1fe57cae-1a00-0000-c377-d22bc9080000 pid=2249->b3e29b12-1aeb-5d8d-bbbb-2d9c211df19b send: 137B guuid=bb9225b4-1a00-0000-c377-d22bd8080000 pid=2264->b3e29b12-1aeb-5d8d-bbbb-2d9c211df19b send: 86B guuid=3ac9faba-1a00-0000-c377-d22be9080000 pid=2281 /tmp/FBI.x86_64 guuid=12c8e8ba-1a00-0000-c377-d22be8080000 pid=2280->guuid=3ac9faba-1a00-0000-c377-d22be9080000 pid=2281 clone guuid=db93dec2-1a00-0000-c377-d22bff080000 pid=2303->b3e29b12-1aeb-5d8d-bbbb-2d9c211df19b send: 137B guuid=31253dc8-1a00-0000-c377-d22b0b090000 pid=2315->b3e29b12-1aeb-5d8d-bbbb-2d9c211df19b send: 86B guuid=d88444cd-1a00-0000-c377-d22b14090000 pid=2324 /tmp/FBI.x86 guuid=c8ba23cd-1a00-0000-c377-d22b13090000 pid=2323->guuid=d88444cd-1a00-0000-c377-d22b14090000 pid=2324 clone guuid=fd7f49d3-1a00-0000-c377-d22b24090000 pid=2340->b3e29b12-1aeb-5d8d-bbbb-2d9c211df19b send: 136B guuid=52987bd8-1a00-0000-c377-d22b2c090000 pid=2348->b3e29b12-1aeb-5d8d-bbbb-2d9c211df19b send: 85B guuid=a4314cdc-1a00-0000-c377-d22b35090000 pid=2357 /tmp/FBI.i686 guuid=670843dc-1a00-0000-c377-d22b34090000 pid=2356->guuid=a4314cdc-1a00-0000-c377-d22b35090000 pid=2357 clone guuid=c33a04e1-1a00-0000-c377-d22b44090000 pid=2372->b3e29b12-1aeb-5d8d-bbbb-2d9c211df19b send: 137B guuid=b0d71ee7-1a00-0000-c377-d22b51090000 pid=2385->b3e29b12-1aeb-5d8d-bbbb-2d9c211df19b send: 86B guuid=f25636f1-1a00-0000-c377-d22b64090000 pid=2404->b3e29b12-1aeb-5d8d-bbbb-2d9c211df19b send: 136B guuid=16eb09f6-1a00-0000-c377-d22b69090000 pid=2409->b3e29b12-1aeb-5d8d-bbbb-2d9c211df19b send: 85B 917da173-99fa-5b2f-852d-120ebeadd476 50.7.23.77:13568 guuid=201904b3-1e00-0000-c377-d22b44100000 pid=4164->917da173-99fa-5b2f-852d-120ebeadd476 send: 5980160B 5a1eed8a-85fe-5cc9-b13b-21dc70289ae4 0.0.0.0:0 guuid=201904b3-1e00-0000-c377-d22b44100000 pid=4164->5a1eed8a-85fe-5cc9-b13b-21dc70289ae4 send: 1460B
Threat name:
Linux.Trojan.Geninst
Status:
Malicious
First seen:
2026-06-11 02:50:42 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Creates a large amount of network flows
File and Directory Permissions Modification
Executes dropped EXE
Writes DNS configuration
Detects Yakuza Botnet, DDoS module
Family: Gafgyt/Bashlite
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 4b36a87f1cf4d953e6ab87ec7a33d875564e3669574ce5e9ebcd281523a09cd1

(this sample)

  
Delivery method
Distributed via web download

Comments