MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 574c7ec171581141c05e936057094cae1d40e406774811f5645fa29a5c0efee9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 574c7ec171581141c05e936057094cae1d40e406774811f5645fa29a5c0efee9
SHA3-384 hash: 65cbcd832627f2fc34802e52ec7e761e428a5a45f5259c8dfd0055c19509ef46993986c25c423e6b3660b3c6d18fc4ce
SHA1 hash: 97745f03d0a4f4abea9bf5aeb09343d407d643c5
MD5 hash: 556c96f5ff7391bc9b52d214e7b60491
humanhash: texas-speaker-indigo-fish
File name:sh
Download: download sample
Signature Gafgyt
File size:228 bytes
First seen:2025-01-20 19:56:40 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 3:TKH4vEbJTAJvUdRNqUwXOomTyW2KCEX3FELcUFF2TDNa5YqqPpOSLQ2PrqC00v:h0J8JaicD3Fqj/q4Y7p9QMLj
TLSH T16FD023E541D608770CC81C4DD0730C5C764D655754D511C43F4D822717D198174615C0
Magika shell
Reporter abuse_ch
Tags:gafgyt sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
96
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox
Result
Verdict:
MALICIOUS
Threat name:
Script-Shell.Trojan.Dakkatoni
Status:
Malicious
First seen:
2025-01-20 19:49:08 UTC
File Type:
Text (Shell)
AV detection:
12 of 38 (31.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 574c7ec171581141c05e936057094cae1d40e406774811f5645fa29a5c0efee9

(this sample)

  
Delivery method
Distributed via web download

Comments