MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 577bbdc3cf9a07ba954b0ba7fc7bb0a25a16bfe2e82bf693c02affcb633bccc4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 577bbdc3cf9a07ba954b0ba7fc7bb0a25a16bfe2e82bf693c02affcb633bccc4
SHA3-384 hash: f3ba29d179245c002167dd97993aa2d96154695f44998a175f4f3a2e74b6c3831b538d411086da3f086cf1e1d242c0a9
SHA1 hash: 950f18e5c23883a911baa5b9a144de24e8902fa9
MD5 hash: 692a0e1b892937ba9138dd19336f9d2c
humanhash: robert-uniform-quiet-missouri
File name:SecuriteInfo.com.Linux.DDoS.501.28039.31212
Download: download sample
Signature Gafgyt
File size:15'796 bytes
First seen:2022-02-01 04:03:15 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 384:00XjOz1hTmhCseamwQrIoW+m8/gHryMtmkjkdOWrZ:wJUhtQMoW+l/yoUWO8
TLSH T1BC62C0F6E62C4A41F3D02B636B58DBE08592D07F907E5D5D395E580F71098688310FDC
Reporter SecuriteInfoCom
Tags:elf gafgyt

Intelligence


File Origin
# of uploads :
1
# of downloads :
194
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
anti-debug
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
mips
Packer:
UPX
Botnet:
23.95.226.157/mac2139r209ru120934r123jhr908213jh4r09213
Number of open files:
0
Number of processes launched:
1
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
no suspicious findings
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
52 / 100
Signature
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Behaviour
Behavior Graph:
Threat name:
Linux.Trojan.Gafgyt
Status:
Malicious
First seen:
2022-02-01 02:27:21 UTC
File Type:
ELF32 Big (Exe)
AV detection:
14 of 28 (50.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

elf 577bbdc3cf9a07ba954b0ba7fc7bb0a25a16bfe2e82bf693c02affcb633bccc4

(this sample)

  
Delivery method
Distributed via web download

Comments