MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 60f401afeb6054e531916adb8118df45fcd7d4c1d166ac28197c67ecba2ba60c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 60f401afeb6054e531916adb8118df45fcd7d4c1d166ac28197c67ecba2ba60c
SHA3-384 hash: d13d50864d0e6de2cfeb6e3db29e9e96e0ca959db10d6f51f9d93aba583374fee05592c86917f77a6429b21fa25a811b
SHA1 hash: 7f53cbcacbc25f28c848cc5e56a4dcafd06c9734
MD5 hash: 319ea341973f79a0767d607302d0fc05
humanhash: ack-batman-august-stream
File name:cat.sh
Download: download sample
Signature Gafgyt
File size:1'815 bytes
First seen:2026-03-27 07:25:50 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:uzjzbssHsMwB8Xxtx+Z0LMTLMwCctGuXusSuX47zfFhQsBPOqGxIY7FDbad6F:CDQDidPS7cd6F
TLSH T1C63184C9083519D40A579E80A9B186C5B90BE7D0BA948EC7E7C61D7170BCDD434B87DA
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://64.89.163.118/iowa0dc4d8932b1319965f4639567680d3a1d5f6fd772ae5f154ca6ef1a4b01038d2 Gafgytelf ua-wget
http://64.89.163.118/alabama567407079429b656f934d756da30eb0d1f2b6bf3e0765c67b7095e6ea4ce316e Gafgytelf ua-wget
http://64.89.163.118/alaska2b6febb43bf9a1eadb08c6910276f7192b3e9c8ffb1fcbdb99770657681a3999 Miraielf mirai ua-wget
http://64.89.163.118/arizona3f9e3b8acf70dc1fc178cdecd755eb9cdb8f8367e2a8ec884aa181932392dce3 Miraielf mirai ua-wget
http://64.89.163.118/arkansas6ab1f75873cc848ba44f0280545bc605dad3631deacac546f8f67da0870b296e Miraielf mirai ua-wget
http://64.89.163.118/california794aaf6fa3e6e1170fe1ee1ab3ba99836d46753fb00b31564629ef7f18a91160 Miraielf mirai ua-wget
http://64.89.163.118/coloradoa7359b810b45f7bb0fcb56a5da5dae41f9c65c7a4c4e5fc0267ffb5a26756c19 Miraielf mirai ua-wget
http://64.89.163.118/connecticut27111421f6310cf286aa062d6f6c296a87345d61fdf8db6238092f1b0751662b Miraielf mirai ua-wget
http://64.89.163.118/delawarebcda6a09f766b4e12a493da81cd7680296cf2b74b8eb99f45be5e9136fa7b433 Miraielf mirai ua-wget
http://64.89.163.118/florida4bafd0db45b44a978092247b4178e3775ae19153f7c6d981fb7780d9b0d8e82a Miraielf mirai ua-wget
http://64.89.163.118/georgia46831dae03c26030c63b02df4d7aa4e0bbf403d2a07590fca5bf20d1adeba246 Miraielf mirai ua-wget
http://64.89.163.118/hawaii9c84623c5a9b5f79023eea9b94bba6ac2a2257a15ceb7c2f5f65b8d3cdbea0ea Miraielf mirai ua-wget
http://64.89.163.118/idaho63ca83fdf2cda2de3b68672cf07128a9ad822c6a255342d0cc1ef1767532569e Miraielf mirai ua-wget
http://64.89.163.118/illinois98c01d760ac3efcd9994fe893165baf552d7f9ab694557907690864dc263489e Miraielf mirai ua-wget
http://64.89.163.118/indiana8062f4d71cf4338aa54950270d18fdeb5b3064fa498c2e944f32f5ded6d8f284 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
50
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=443d012b-1a00-0000-c940-66f05b0a0000 pid=2651 /usr/bin/sudo guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658 /tmp/sample.bin guuid=443d012b-1a00-0000-c940-66f05b0a0000 pid=2651->guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658 execve guuid=365caf2d-1a00-0000-c940-66f0640a0000 pid=2660 /usr/bin/wget net send-data write-file guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=365caf2d-1a00-0000-c940-66f0640a0000 pid=2660 execve guuid=56c0463d-1a00-0000-c940-66f0850a0000 pid=2693 /usr/bin/chmod guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=56c0463d-1a00-0000-c940-66f0850a0000 pid=2693 execve guuid=6a07923d-1a00-0000-c940-66f0860a0000 pid=2694 /home/sandbox/iowa guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=6a07923d-1a00-0000-c940-66f0860a0000 pid=2694 execve guuid=a0e2383e-1a00-0000-c940-66f08b0a0000 pid=2699 /usr/bin/wget net send-data write-file guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=a0e2383e-1a00-0000-c940-66f08b0a0000 pid=2699 execve guuid=2847fb4a-1a00-0000-c940-66f0a90a0000 pid=2729 /usr/bin/chmod guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=2847fb4a-1a00-0000-c940-66f0a90a0000 pid=2729 execve guuid=7d40434b-1a00-0000-c940-66f0aa0a0000 pid=2730 /usr/bin/dash guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=7d40434b-1a00-0000-c940-66f0aa0a0000 pid=2730 clone guuid=5ed3dd4b-1a00-0000-c940-66f0ad0a0000 pid=2733 /usr/bin/dash guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=5ed3dd4b-1a00-0000-c940-66f0ad0a0000 pid=2733 clone guuid=cbe9f04b-1a00-0000-c940-66f0ae0a0000 pid=2734 /usr/bin/chmod guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=cbe9f04b-1a00-0000-c940-66f0ae0a0000 pid=2734 execve guuid=5f34714c-1a00-0000-c940-66f0b10a0000 pid=2737 /usr/bin/dash guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=5f34714c-1a00-0000-c940-66f0b10a0000 pid=2737 clone guuid=58d3fc4c-1a00-0000-c940-66f0b30a0000 pid=2739 /usr/bin/dash guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=58d3fc4c-1a00-0000-c940-66f0b30a0000 pid=2739 clone guuid=14201c4d-1a00-0000-c940-66f0b40a0000 pid=2740 /usr/bin/chmod guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=14201c4d-1a00-0000-c940-66f0b40a0000 pid=2740 execve guuid=980ced4d-1a00-0000-c940-66f0b50a0000 pid=2741 /usr/bin/dash guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=980ced4d-1a00-0000-c940-66f0b50a0000 pid=2741 clone guuid=f0acf54d-1a00-0000-c940-66f0b60a0000 pid=2742 /usr/bin/dash guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=f0acf54d-1a00-0000-c940-66f0b60a0000 pid=2742 clone guuid=a662004e-1a00-0000-c940-66f0b70a0000 pid=2743 /usr/bin/chmod guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=a662004e-1a00-0000-c940-66f0b70a0000 pid=2743 execve guuid=95bd4d4e-1a00-0000-c940-66f0b80a0000 pid=2744 /usr/bin/dash guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=95bd4d4e-1a00-0000-c940-66f0b80a0000 pid=2744 clone guuid=4f4e574e-1a00-0000-c940-66f0b90a0000 pid=2745 /usr/bin/dash guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=4f4e574e-1a00-0000-c940-66f0b90a0000 pid=2745 clone guuid=01da674e-1a00-0000-c940-66f0ba0a0000 pid=2746 /usr/bin/chmod guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=01da674e-1a00-0000-c940-66f0ba0a0000 pid=2746 execve guuid=5f3bb34e-1a00-0000-c940-66f0bb0a0000 pid=2747 /usr/bin/dash guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=5f3bb34e-1a00-0000-c940-66f0bb0a0000 pid=2747 clone guuid=03d2ba4e-1a00-0000-c940-66f0bc0a0000 pid=2748 /usr/bin/dash guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=03d2ba4e-1a00-0000-c940-66f0bc0a0000 pid=2748 clone guuid=e9b0c64e-1a00-0000-c940-66f0bd0a0000 pid=2749 /usr/bin/chmod guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=e9b0c64e-1a00-0000-c940-66f0bd0a0000 pid=2749 execve guuid=87cf9e4f-1a00-0000-c940-66f0c00a0000 pid=2752 /usr/bin/dash guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=87cf9e4f-1a00-0000-c940-66f0c00a0000 pid=2752 clone guuid=009ed34f-1a00-0000-c940-66f0c10a0000 pid=2753 /usr/bin/dash guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=009ed34f-1a00-0000-c940-66f0c10a0000 pid=2753 clone guuid=ab1bfe4f-1a00-0000-c940-66f0c30a0000 pid=2755 /usr/bin/chmod guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=ab1bfe4f-1a00-0000-c940-66f0c30a0000 pid=2755 execve guuid=a9b18b50-1a00-0000-c940-66f0c50a0000 pid=2757 /usr/bin/dash guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=a9b18b50-1a00-0000-c940-66f0c50a0000 pid=2757 clone guuid=291cab50-1a00-0000-c940-66f0c70a0000 pid=2759 /usr/bin/dash guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=291cab50-1a00-0000-c940-66f0c70a0000 pid=2759 clone guuid=d50ed450-1a00-0000-c940-66f0c80a0000 pid=2760 /usr/bin/chmod guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=d50ed450-1a00-0000-c940-66f0c80a0000 pid=2760 execve guuid=f4446151-1a00-0000-c940-66f0cb0a0000 pid=2763 /usr/bin/dash guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=f4446151-1a00-0000-c940-66f0cb0a0000 pid=2763 clone guuid=a8e78551-1a00-0000-c940-66f0cc0a0000 pid=2764 /usr/bin/dash guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=a8e78551-1a00-0000-c940-66f0cc0a0000 pid=2764 clone guuid=30c8a851-1a00-0000-c940-66f0ce0a0000 pid=2766 /usr/bin/chmod guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=30c8a851-1a00-0000-c940-66f0ce0a0000 pid=2766 execve guuid=0d3c3d52-1a00-0000-c940-66f0d10a0000 pid=2769 /usr/bin/dash guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=0d3c3d52-1a00-0000-c940-66f0d10a0000 pid=2769 clone guuid=d4d45c52-1a00-0000-c940-66f0d20a0000 pid=2770 /usr/bin/dash guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=d4d45c52-1a00-0000-c940-66f0d20a0000 pid=2770 clone guuid=ce4a8252-1a00-0000-c940-66f0d30a0000 pid=2771 /usr/bin/chmod guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=ce4a8252-1a00-0000-c940-66f0d30a0000 pid=2771 execve guuid=946b0c53-1a00-0000-c940-66f0d50a0000 pid=2773 /usr/bin/dash guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=946b0c53-1a00-0000-c940-66f0d50a0000 pid=2773 clone guuid=d2e83053-1a00-0000-c940-66f0d60a0000 pid=2774 /usr/bin/dash guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=d2e83053-1a00-0000-c940-66f0d60a0000 pid=2774 clone guuid=598b5253-1a00-0000-c940-66f0d70a0000 pid=2775 /usr/bin/chmod guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=598b5253-1a00-0000-c940-66f0d70a0000 pid=2775 execve guuid=a928e053-1a00-0000-c940-66f0da0a0000 pid=2778 /usr/bin/dash guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=a928e053-1a00-0000-c940-66f0da0a0000 pid=2778 clone guuid=d6b9fd53-1a00-0000-c940-66f0db0a0000 pid=2779 /usr/bin/dash guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=d6b9fd53-1a00-0000-c940-66f0db0a0000 pid=2779 clone guuid=26932654-1a00-0000-c940-66f0dd0a0000 pid=2781 /usr/bin/chmod guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=26932654-1a00-0000-c940-66f0dd0a0000 pid=2781 execve guuid=de2bb354-1a00-0000-c940-66f0df0a0000 pid=2783 /usr/bin/dash guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=de2bb354-1a00-0000-c940-66f0df0a0000 pid=2783 clone guuid=d3a7dc54-1a00-0000-c940-66f0e10a0000 pid=2785 /usr/bin/dash guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=d3a7dc54-1a00-0000-c940-66f0e10a0000 pid=2785 clone guuid=cfd7e954-1a00-0000-c940-66f0e20a0000 pid=2786 /usr/bin/chmod guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=cfd7e954-1a00-0000-c940-66f0e20a0000 pid=2786 execve guuid=37354355-1a00-0000-c940-66f0e40a0000 pid=2788 /usr/bin/dash guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=37354355-1a00-0000-c940-66f0e40a0000 pid=2788 clone guuid=a9385155-1a00-0000-c940-66f0e50a0000 pid=2789 /usr/bin/dash guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=a9385155-1a00-0000-c940-66f0e50a0000 pid=2789 clone guuid=d6485b55-1a00-0000-c940-66f0e60a0000 pid=2790 /usr/bin/chmod guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=d6485b55-1a00-0000-c940-66f0e60a0000 pid=2790 execve guuid=a12dbd55-1a00-0000-c940-66f0e70a0000 pid=2791 /usr/bin/dash guuid=c0c7612d-1a00-0000-c940-66f0620a0000 pid=2658->guuid=a12dbd55-1a00-0000-c940-66f0e70a0000 pid=2791 clone b6177f27-82fe-5c91-8fa0-9b83237d96cd 64.89.163.118:80 guuid=365caf2d-1a00-0000-c940-66f0640a0000 pid=2660->b6177f27-82fe-5c91-8fa0-9b83237d96cd send: 132B guuid=06c9243e-1a00-0000-c940-66f0890a0000 pid=2697 /home/sandbox/iowa zombie guuid=6a07923d-1a00-0000-c940-66f0860a0000 pid=2694->guuid=06c9243e-1a00-0000-c940-66f0890a0000 pid=2697 clone guuid=f60c323e-1a00-0000-c940-66f08a0a0000 pid=2698 /home/sandbox/iowa delete-file net send-data zombie guuid=06c9243e-1a00-0000-c940-66f0890a0000 pid=2697->guuid=f60c323e-1a00-0000-c940-66f08a0a0000 pid=2698 clone a65a72d5-728b-5ba7-8f46-c806325bb205 64.89.163.118:7080 guuid=f60c323e-1a00-0000-c940-66f08a0a0000 pid=2698->a65a72d5-728b-5ba7-8f46-c806325bb205 send: 237B guuid=19e6f33e-1a00-0000-c940-66f08e0a0000 pid=2702 /home/sandbox/iowa guuid=f60c323e-1a00-0000-c940-66f08a0a0000 pid=2698->guuid=19e6f33e-1a00-0000-c940-66f08e0a0000 pid=2702 clone guuid=ff2b073f-1a00-0000-c940-66f08f0a0000 pid=2703 /home/sandbox/iowa guuid=f60c323e-1a00-0000-c940-66f08a0a0000 pid=2698->guuid=ff2b073f-1a00-0000-c940-66f08f0a0000 pid=2703 clone guuid=a0e2383e-1a00-0000-c940-66f08b0a0000 pid=2699->b6177f27-82fe-5c91-8fa0-9b83237d96cd send: 135B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-27 05:32:51 UTC
File Type:
Text (Shell)
AV detection:
6 of 36 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Deletes log files
Enumerates running processes
File and Directory Permissions Modification
Deletes Audit logs
Deletes itself
Deletes system logs
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 60f401afeb6054e531916adb8118df45fcd7d4c1d166ac28197c67ecba2ba60c

(this sample)

  
Delivery method
Distributed via web download

Comments