MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5839ee721dcc485bcb03386fabb7f4ed4bf118430319bc6da8cc3c03fbb0f794. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 5839ee721dcc485bcb03386fabb7f4ed4bf118430319bc6da8cc3c03fbb0f794
SHA3-384 hash: ee182a0b4354bb5fa53123d19fcb974ab78d2f43c5c187a7f02bae08199dacdd1f35c9cc9183763ac3ac4470162a846c
SHA1 hash: 8f2e01e63a95455b4edd94180750f5d7f438a5fe
MD5 hash: 775cc78a7352dda3e6c89da5a283a735
humanhash: enemy-nevada-colorado-kitten
File name:Sakura.sh
Download: download sample
Signature Gafgyt
File size:2'140 bytes
First seen:2026-05-23 06:13:51 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:1ed8RZttQdMiFgfbNp+TuU2IwLL3Z5vIwr7qT:1ed8RZttQdMYgfbNp+TuU2IwLrZ5vIw2
TLSH T1394182DB12520BF7ACA5E83332B444A0F9D4A19594C5DF0B2DDC3ED458BFDAC68456C2
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://85.204.125.76/m-i.p-s.Sakura6ec3194c794943ea35ca0adfc2f8509465a4f7fe81adb9a211d824ce30fd4873 Gafgytelf gafgyt opendir ua-wget x86
http://85.204.125.76/m-p.s-l.Sakura6ec3194c794943ea35ca0adfc2f8509465a4f7fe81adb9a211d824ce30fd4873 Gafgytelf gafgyt opendir ua-wget x86
http://85.204.125.76/s-h.4-.Sakura6ec3194c794943ea35ca0adfc2f8509465a4f7fe81adb9a211d824ce30fd4873 Gafgytelf gafgyt opendir ua-wget x86
http://85.204.125.76/x-8.6-.Sakura6ec3194c794943ea35ca0adfc2f8509465a4f7fe81adb9a211d824ce30fd4873 Gafgytelf gafgyt opendir ua-wget x86
http://85.204.125.76/a-r.m-6.Sakura6ec3194c794943ea35ca0adfc2f8509465a4f7fe81adb9a211d824ce30fd4873 Gafgytelf gafgyt opendir ua-wget x86
http://85.204.125.76/x-3.2-.Sakura6ec3194c794943ea35ca0adfc2f8509465a4f7fe81adb9a211d824ce30fd4873 Gafgytelf gafgyt opendir ua-wget x86
http://85.204.125.76/a-r.m-7.Sakura6ec3194c794943ea35ca0adfc2f8509465a4f7fe81adb9a211d824ce30fd4873 Gafgytelf gafgyt opendir ua-wget x86
http://85.204.125.76/p-p.c-.Sakura6ec3194c794943ea35ca0adfc2f8509465a4f7fe81adb9a211d824ce30fd4873 Gafgytelf gafgyt opendir ua-wget x86
http://85.204.125.76/i-5.8-6.Sakura6ec3194c794943ea35ca0adfc2f8509465a4f7fe81adb9a211d824ce30fd4873 Gafgytelf gafgyt opendir ua-wget x86
http://85.204.125.76/m-6.8-k.Sakura6ec3194c794943ea35ca0adfc2f8509465a4f7fe81adb9a211d824ce30fd4873 Gafgytelf gafgyt opendir ua-wget x86
http://85.204.125.76/a-r.m-4.Sakura6ec3194c794943ea35ca0adfc2f8509465a4f7fe81adb9a211d824ce30fd4873 Gafgytelf gafgyt opendir ua-wget x86
http://85.204.125.76/a-r.m-5.Sakura6ec3194c794943ea35ca0adfc2f8509465a4f7fe81adb9a211d824ce30fd4873 Gafgytelf gafgyt opendir ua-wget x86

Intelligence


File Origin
# of uploads :
1
# of downloads :
50
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
text
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=9d31b24e-1800-0000-402e-e2426d0b0000 pid=2925 /usr/bin/sudo guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929 /tmp/sample.bin guuid=9d31b24e-1800-0000-402e-e2426d0b0000 pid=2925->guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929 execve guuid=ed07fb50-1800-0000-402e-e242730b0000 pid=2931 /usr/bin/wget net send-data write-file guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=ed07fb50-1800-0000-402e-e242730b0000 pid=2931 execve guuid=ccb2a86d-1800-0000-402e-e242ac0b0000 pid=2988 /usr/bin/chmod guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=ccb2a86d-1800-0000-402e-e242ac0b0000 pid=2988 execve guuid=c44b306e-1800-0000-402e-e242ad0b0000 pid=2989 /usr/bin/dash guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=c44b306e-1800-0000-402e-e242ad0b0000 pid=2989 clone guuid=4baa3e6e-1800-0000-402e-e242af0b0000 pid=2991 /usr/bin/rm delete-file guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=4baa3e6e-1800-0000-402e-e242af0b0000 pid=2991 execve guuid=fff9806e-1800-0000-402e-e242b00b0000 pid=2992 /usr/bin/wget net send-data write-file guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=fff9806e-1800-0000-402e-e242b00b0000 pid=2992 execve guuid=eb996a88-1800-0000-402e-e242ca0b0000 pid=3018 /usr/bin/chmod guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=eb996a88-1800-0000-402e-e242ca0b0000 pid=3018 execve guuid=fcc7ab88-1800-0000-402e-e242cc0b0000 pid=3020 /usr/bin/dash guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=fcc7ab88-1800-0000-402e-e242cc0b0000 pid=3020 clone guuid=a846b588-1800-0000-402e-e242cd0b0000 pid=3021 /usr/bin/rm delete-file guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=a846b588-1800-0000-402e-e242cd0b0000 pid=3021 execve guuid=6e033f89-1800-0000-402e-e242d00b0000 pid=3024 /usr/bin/wget net send-data write-file guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=6e033f89-1800-0000-402e-e242d00b0000 pid=3024 execve guuid=7cb3fea3-1800-0000-402e-e2421a0c0000 pid=3098 /usr/bin/chmod guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=7cb3fea3-1800-0000-402e-e2421a0c0000 pid=3098 execve guuid=02a63ba4-1800-0000-402e-e2421c0c0000 pid=3100 /usr/bin/dash guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=02a63ba4-1800-0000-402e-e2421c0c0000 pid=3100 clone guuid=e39c47a4-1800-0000-402e-e2421d0c0000 pid=3101 /usr/bin/rm delete-file guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=e39c47a4-1800-0000-402e-e2421d0c0000 pid=3101 execve guuid=57c68ca4-1800-0000-402e-e2421e0c0000 pid=3102 /usr/bin/wget net send-data write-file guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=57c68ca4-1800-0000-402e-e2421e0c0000 pid=3102 execve guuid=bccc4bbe-1800-0000-402e-e242600c0000 pid=3168 /usr/bin/chmod guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=bccc4bbe-1800-0000-402e-e242600c0000 pid=3168 execve guuid=52dc95be-1800-0000-402e-e242620c0000 pid=3170 /usr/bin/dash guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=52dc95be-1800-0000-402e-e242620c0000 pid=3170 clone guuid=626da1be-1800-0000-402e-e242630c0000 pid=3171 /usr/bin/rm delete-file guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=626da1be-1800-0000-402e-e242630c0000 pid=3171 execve guuid=d64a0bbf-1800-0000-402e-e242650c0000 pid=3173 /usr/bin/wget net send-data write-file guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=d64a0bbf-1800-0000-402e-e242650c0000 pid=3173 execve guuid=871f15e1-1800-0000-402e-e242830c0000 pid=3203 /usr/bin/chmod guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=871f15e1-1800-0000-402e-e242830c0000 pid=3203 execve guuid=20619ae1-1800-0000-402e-e242850c0000 pid=3205 /usr/bin/dash guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=20619ae1-1800-0000-402e-e242850c0000 pid=3205 clone guuid=761fade1-1800-0000-402e-e242870c0000 pid=3207 /usr/bin/rm delete-file guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=761fade1-1800-0000-402e-e242870c0000 pid=3207 execve guuid=76ddefe1-1800-0000-402e-e242880c0000 pid=3208 /usr/bin/wget net send-data write-file guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=76ddefe1-1800-0000-402e-e242880c0000 pid=3208 execve guuid=a5055c03-1900-0000-402e-e242ac0c0000 pid=3244 /usr/bin/chmod guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=a5055c03-1900-0000-402e-e242ac0c0000 pid=3244 execve guuid=3cfabf03-1900-0000-402e-e242ad0c0000 pid=3245 /usr/bin/dash guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=3cfabf03-1900-0000-402e-e242ad0c0000 pid=3245 clone guuid=97a6cd03-1900-0000-402e-e242ae0c0000 pid=3246 /usr/bin/rm delete-file guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=97a6cd03-1900-0000-402e-e242ae0c0000 pid=3246 execve guuid=f6731204-1900-0000-402e-e242b00c0000 pid=3248 /usr/bin/wget net send-data write-file guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=f6731204-1900-0000-402e-e242b00c0000 pid=3248 execve guuid=27c67722-1900-0000-402e-e242d60c0000 pid=3286 /usr/bin/chmod guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=27c67722-1900-0000-402e-e242d60c0000 pid=3286 execve guuid=e628ca22-1900-0000-402e-e242d80c0000 pid=3288 /usr/bin/dash guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=e628ca22-1900-0000-402e-e242d80c0000 pid=3288 clone guuid=e7bbdb22-1900-0000-402e-e242da0c0000 pid=3290 /usr/bin/rm delete-file guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=e7bbdb22-1900-0000-402e-e242da0c0000 pid=3290 execve guuid=0a3f3823-1900-0000-402e-e242dc0c0000 pid=3292 /usr/bin/wget net send-data write-file guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=0a3f3823-1900-0000-402e-e242dc0c0000 pid=3292 execve guuid=b4d5883d-1900-0000-402e-e242110d0000 pid=3345 /usr/bin/chmod guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=b4d5883d-1900-0000-402e-e242110d0000 pid=3345 execve guuid=0176e13d-1900-0000-402e-e242120d0000 pid=3346 /usr/bin/dash guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=0176e13d-1900-0000-402e-e242120d0000 pid=3346 clone guuid=5d06f33d-1900-0000-402e-e242130d0000 pid=3347 /usr/bin/rm delete-file guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=5d06f33d-1900-0000-402e-e242130d0000 pid=3347 execve guuid=d8a6653e-1900-0000-402e-e242140d0000 pid=3348 /usr/bin/wget net send-data write-file guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=d8a6653e-1900-0000-402e-e242140d0000 pid=3348 execve guuid=1fe81b58-1900-0000-402e-e242320d0000 pid=3378 /usr/bin/chmod guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=1fe81b58-1900-0000-402e-e242320d0000 pid=3378 execve guuid=82638b58-1900-0000-402e-e242340d0000 pid=3380 /usr/bin/dash guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=82638b58-1900-0000-402e-e242340d0000 pid=3380 clone guuid=39889858-1900-0000-402e-e242360d0000 pid=3382 /usr/bin/rm delete-file guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=39889858-1900-0000-402e-e242360d0000 pid=3382 execve guuid=9b04e858-1900-0000-402e-e242370d0000 pid=3383 /usr/bin/wget net send-data write-file guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=9b04e858-1900-0000-402e-e242370d0000 pid=3383 execve guuid=449e7772-1900-0000-402e-e242620d0000 pid=3426 /usr/bin/chmod guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=449e7772-1900-0000-402e-e242620d0000 pid=3426 execve guuid=23aadd72-1900-0000-402e-e242650d0000 pid=3429 /usr/bin/dash guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=23aadd72-1900-0000-402e-e242650d0000 pid=3429 clone guuid=0f00ee72-1900-0000-402e-e242660d0000 pid=3430 /usr/bin/rm delete-file guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=0f00ee72-1900-0000-402e-e242660d0000 pid=3430 execve guuid=53484973-1900-0000-402e-e242680d0000 pid=3432 /usr/bin/wget net send-data write-file guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=53484973-1900-0000-402e-e242680d0000 pid=3432 execve guuid=0a957992-1900-0000-402e-e242b10d0000 pid=3505 /usr/bin/chmod guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=0a957992-1900-0000-402e-e242b10d0000 pid=3505 execve guuid=0713b692-1900-0000-402e-e242b30d0000 pid=3507 /usr/bin/dash guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=0713b692-1900-0000-402e-e242b30d0000 pid=3507 clone guuid=2a54c292-1900-0000-402e-e242b40d0000 pid=3508 /usr/bin/rm delete-file guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=2a54c292-1900-0000-402e-e242b40d0000 pid=3508 execve guuid=f3d80193-1900-0000-402e-e242b60d0000 pid=3510 /usr/bin/wget net send-data write-file guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=f3d80193-1900-0000-402e-e242b60d0000 pid=3510 execve guuid=6b0068ac-1900-0000-402e-e242ca0d0000 pid=3530 /usr/bin/chmod guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=6b0068ac-1900-0000-402e-e242ca0d0000 pid=3530 execve guuid=92e4d8ac-1900-0000-402e-e242cb0d0000 pid=3531 /usr/bin/dash guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=92e4d8ac-1900-0000-402e-e242cb0d0000 pid=3531 clone guuid=14beeaac-1900-0000-402e-e242cc0d0000 pid=3532 /usr/bin/rm delete-file guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=14beeaac-1900-0000-402e-e242cc0d0000 pid=3532 execve guuid=6ac052ad-1900-0000-402e-e242cd0d0000 pid=3533 /usr/bin/wget net send-data write-file guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=6ac052ad-1900-0000-402e-e242cd0d0000 pid=3533 execve guuid=85700dc8-1900-0000-402e-e2420b0e0000 pid=3595 /usr/bin/chmod guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=85700dc8-1900-0000-402e-e2420b0e0000 pid=3595 execve guuid=780952c8-1900-0000-402e-e2420d0e0000 pid=3597 /usr/bin/dash guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=780952c8-1900-0000-402e-e2420d0e0000 pid=3597 clone guuid=74f75fc8-1900-0000-402e-e2420e0e0000 pid=3598 /usr/bin/rm delete-file guuid=b5c5ba50-1800-0000-402e-e242710b0000 pid=2929->guuid=74f75fc8-1900-0000-402e-e2420e0e0000 pid=3598 execve f02c14ef-f735-5e79-81f5-063b232980ef 85.204.125.76:80 guuid=ed07fb50-1800-0000-402e-e242730b0000 pid=2931->f02c14ef-f735-5e79-81f5-063b232980ef send: 142B guuid=fff9806e-1800-0000-402e-e242b00b0000 pid=2992->f02c14ef-f735-5e79-81f5-063b232980ef send: 142B guuid=6e033f89-1800-0000-402e-e242d00b0000 pid=3024->f02c14ef-f735-5e79-81f5-063b232980ef send: 141B guuid=57c68ca4-1800-0000-402e-e2421e0c0000 pid=3102->f02c14ef-f735-5e79-81f5-063b232980ef send: 141B guuid=d64a0bbf-1800-0000-402e-e242650c0000 pid=3173->f02c14ef-f735-5e79-81f5-063b232980ef send: 142B guuid=76ddefe1-1800-0000-402e-e242880c0000 pid=3208->f02c14ef-f735-5e79-81f5-063b232980ef send: 141B guuid=f6731204-1900-0000-402e-e242b00c0000 pid=3248->f02c14ef-f735-5e79-81f5-063b232980ef send: 142B guuid=0a3f3823-1900-0000-402e-e242dc0c0000 pid=3292->f02c14ef-f735-5e79-81f5-063b232980ef send: 141B guuid=d8a6653e-1900-0000-402e-e242140d0000 pid=3348->f02c14ef-f735-5e79-81f5-063b232980ef send: 142B guuid=9b04e858-1900-0000-402e-e242370d0000 pid=3383->f02c14ef-f735-5e79-81f5-063b232980ef send: 142B guuid=53484973-1900-0000-402e-e242680d0000 pid=3432->f02c14ef-f735-5e79-81f5-063b232980ef send: 141B guuid=f3d80193-1900-0000-402e-e242b60d0000 pid=3510->f02c14ef-f735-5e79-81f5-063b232980ef send: 142B guuid=6ac052ad-1900-0000-402e-e242cd0d0000 pid=3533->f02c14ef-f735-5e79-81f5-063b232980ef send: 142B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 5839ee721dcc485bcb03386fabb7f4ed4bf118430319bc6da8cc3c03fbb0f794

(this sample)

  
Delivery method
Distributed via web download

Comments