🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 661faee0e7c5c959724dc0db30a76ba67b5c8ef2dec7180eb2f649de77bf79ee. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 661faee0e7c5c959724dc0db30a76ba67b5c8ef2dec7180eb2f649de77bf79ee
SHA3-384 hash: 6a9cd9ab817e860e63ed2066fc4b90b5000ddcc44559c71a4712d2c8a159db096f319180373ab6f2de13def8bfdec1f0
SHA1 hash: 579eaa357d3f31b15f0fa1da52eba97f98bc6a29
MD5 hash: 1963677292efd88bf60d0c687cb0382f
humanhash: maryland-low-glucose-mirror
File name:bins.sh
Download: download sample
Signature Gafgyt
File size:1'214 bytes
First seen:2026-10-05 11:06:57 UTC
Last seen:2026-10-06 00:13:10 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 12:q0F2kV3sbVHW0F2govvo0F24tDX0F2JgfX0F2RzB+RFX0F4DO0F2WNI3ewkX0F2d:vKVeJbI/s+VG+4DLTNIpks2KYBbIKAw
TLSH T15F213ED751E20A36AC65D877B4AF8CA434D0E4C645E1BF0818EC38F4648DE59E481B93
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://104.168.4.206/dissmips6cc5fadd255dbe4a2ba75a297a8e714e47dc85ec1acddab3be3d37866e918872 Gafgytcensys elf gafgyt ua-wget
http://104.168.4.206/dissmpsldc2450e8cdaf1de56a2ff4ee68fcda754c244a2c90cf4e6cc08fdf9b480b6352 Gafgytcensys elf gafgyt ua-wget
http://104.168.4.206/disssh4e1f02c18d600bcf5bae59ddbe040f0bc53c99d458121d0caa8422982e168a5e8 Miraicensys elf mirai ua-wget
http://104.168.4.206/dissx86d711dc9ed0e174d33bb84e0aaca9ac9299db40078730f1edb08cf0a6a0f9921d Gafgytcensys elf gafgyt ua-wget
http://104.168.4.206/dissarm4879df0bee8a6d444d61639500b7df5fb4302713083edc284e4ee53cf5ad95e40 Gafgytcensys elf gafgyt ua-wget
http://104.168.4.206/adissarm54accae06e6459df508b49b158a44a7627bc221982b7495a9e88b02b5682f76c4 Gafgytcensys elf gafgyt mirai ua-wget
http://104.168.4.206/dissarm670a09c4952159e9c80611b1128da01c5875c616311429f047338a432edb06382 Gafgytcensys elf gafgyt mirai ua-wget
http://104.168.4.206/dissarm7405e75cf8c202d00833b9836ec9a0f1f6d358f69a297adccf2074dbf684d9ee2 Miraicensys elf mirai ua-wget
http://104.168.4.206/adb.arm7729978b00d098842363f59a6ffee3ac80e8a41e11c7317c837cd0b4345ed8a31 Miraielf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
86
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-10-05T08:20:00Z UTC
Last seen:
2026-10-06T19:47:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=ecfc5b69-1600-0000-72c4-36d0e60c0000 pid=3302 /usr/bin/sudo guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308 /tmp/sample.bin guuid=ecfc5b69-1600-0000-72c4-36d0e60c0000 pid=3302->guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308 execve guuid=3f08446b-1600-0000-72c4-36d0ee0c0000 pid=3310 /usr/bin/wget net send-data write-file guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=3f08446b-1600-0000-72c4-36d0ee0c0000 pid=3310 execve guuid=d8be5e90-1600-0000-72c4-36d03f0d0000 pid=3391 /usr/bin/chmod guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=d8be5e90-1600-0000-72c4-36d03f0d0000 pid=3391 execve guuid=002db590-1600-0000-72c4-36d0410d0000 pid=3393 /usr/bin/bash guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=002db590-1600-0000-72c4-36d0410d0000 pid=3393 clone guuid=13662e91-1600-0000-72c4-36d0450d0000 pid=3397 /usr/bin/rm delete-file guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=13662e91-1600-0000-72c4-36d0450d0000 pid=3397 execve guuid=e6ef6b91-1600-0000-72c4-36d0470d0000 pid=3399 /usr/bin/wget net send-data write-file guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=e6ef6b91-1600-0000-72c4-36d0470d0000 pid=3399 execve guuid=5315b7bb-1600-0000-72c4-36d0ac0d0000 pid=3500 /usr/bin/chmod guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=5315b7bb-1600-0000-72c4-36d0ac0d0000 pid=3500 execve guuid=b0a704bc-1600-0000-72c4-36d0ae0d0000 pid=3502 /usr/bin/bash guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=b0a704bc-1600-0000-72c4-36d0ae0d0000 pid=3502 clone guuid=b10a8fbc-1600-0000-72c4-36d0b40d0000 pid=3508 /usr/bin/rm delete-file guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=b10a8fbc-1600-0000-72c4-36d0b40d0000 pid=3508 execve guuid=4564ebbc-1600-0000-72c4-36d0b60d0000 pid=3510 /usr/bin/wget net send-data write-file guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=4564ebbc-1600-0000-72c4-36d0b60d0000 pid=3510 execve guuid=af67f9e0-1600-0000-72c4-36d0100e0000 pid=3600 /usr/bin/chmod guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=af67f9e0-1600-0000-72c4-36d0100e0000 pid=3600 execve guuid=2f093fe1-1600-0000-72c4-36d0110e0000 pid=3601 /usr/bin/bash guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=2f093fe1-1600-0000-72c4-36d0110e0000 pid=3601 clone guuid=aaf8cde1-1600-0000-72c4-36d0160e0000 pid=3606 /usr/bin/rm delete-file guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=aaf8cde1-1600-0000-72c4-36d0160e0000 pid=3606 execve guuid=476e19e2-1600-0000-72c4-36d01a0e0000 pid=3610 /usr/bin/wget net send-data write-file guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=476e19e2-1600-0000-72c4-36d01a0e0000 pid=3610 execve guuid=43ce4408-1700-0000-72c4-36d0920e0000 pid=3730 /usr/bin/chmod guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=43ce4408-1700-0000-72c4-36d0920e0000 pid=3730 execve guuid=2f86c808-1700-0000-72c4-36d0930e0000 pid=3731 /tmp/dissx86 guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=2f86c808-1700-0000-72c4-36d0930e0000 pid=3731 execve guuid=e795f908-1700-0000-72c4-36d0960e0000 pid=3734 /usr/bin/rm delete-file guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=e795f908-1700-0000-72c4-36d0960e0000 pid=3734 execve guuid=3c79780a-1700-0000-72c4-36d09c0e0000 pid=3740 /usr/bin/wget net send-data write-file guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=3c79780a-1700-0000-72c4-36d09c0e0000 pid=3740 execve guuid=4c220332-1700-0000-72c4-36d01c0f0000 pid=3868 /usr/bin/chmod guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=4c220332-1700-0000-72c4-36d01c0f0000 pid=3868 execve guuid=646f4432-1700-0000-72c4-36d01d0f0000 pid=3869 /usr/bin/bash guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=646f4432-1700-0000-72c4-36d01d0f0000 pid=3869 clone guuid=819fe832-1700-0000-72c4-36d0250f0000 pid=3877 /usr/bin/rm delete-file guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=819fe832-1700-0000-72c4-36d0250f0000 pid=3877 execve guuid=3b3f3233-1700-0000-72c4-36d0260f0000 pid=3878 /usr/bin/wget net send-data write-file guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=3b3f3233-1700-0000-72c4-36d0260f0000 pid=3878 execve guuid=fc44bb59-1700-0000-72c4-36d0bb0f0000 pid=4027 /usr/bin/chmod guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=fc44bb59-1700-0000-72c4-36d0bb0f0000 pid=4027 execve guuid=e84d285a-1700-0000-72c4-36d0bc0f0000 pid=4028 /usr/bin/bash guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=e84d285a-1700-0000-72c4-36d0bc0f0000 pid=4028 clone guuid=6d63ef5a-1700-0000-72c4-36d0c40f0000 pid=4036 /usr/bin/rm delete-file guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=6d63ef5a-1700-0000-72c4-36d0c40f0000 pid=4036 execve guuid=a222365b-1700-0000-72c4-36d0c50f0000 pid=4037 /usr/bin/wget net send-data write-file guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=a222365b-1700-0000-72c4-36d0c50f0000 pid=4037 execve guuid=9a0e2380-1700-0000-72c4-36d05a100000 pid=4186 /usr/bin/chmod guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=9a0e2380-1700-0000-72c4-36d05a100000 pid=4186 execve guuid=846b6380-1700-0000-72c4-36d05c100000 pid=4188 /usr/bin/bash guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=846b6380-1700-0000-72c4-36d05c100000 pid=4188 clone guuid=c188e480-1700-0000-72c4-36d05e100000 pid=4190 /usr/bin/rm delete-file guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=c188e480-1700-0000-72c4-36d05e100000 pid=4190 execve guuid=e2252381-1700-0000-72c4-36d061100000 pid=4193 /usr/bin/wget net send-data write-file guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=e2252381-1700-0000-72c4-36d061100000 pid=4193 execve guuid=a8ed60a5-1700-0000-72c4-36d0eb100000 pid=4331 /usr/bin/chmod guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=a8ed60a5-1700-0000-72c4-36d0eb100000 pid=4331 execve guuid=4e9faaa5-1700-0000-72c4-36d0ed100000 pid=4333 /usr/bin/bash guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=4e9faaa5-1700-0000-72c4-36d0ed100000 pid=4333 clone guuid=d5e388a6-1700-0000-72c4-36d0f2100000 pid=4338 /usr/bin/rm delete-file guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=d5e388a6-1700-0000-72c4-36d0f2100000 pid=4338 execve guuid=8dfeefa6-1700-0000-72c4-36d0f6100000 pid=4342 /usr/bin/wget net send-data write-file guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=8dfeefa6-1700-0000-72c4-36d0f6100000 pid=4342 execve guuid=e87edec3-1700-0000-72c4-36d063110000 pid=4451 /usr/bin/chmod guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=e87edec3-1700-0000-72c4-36d063110000 pid=4451 execve guuid=dbd61ec4-1700-0000-72c4-36d067110000 pid=4455 /usr/bin/bash guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=dbd61ec4-1700-0000-72c4-36d067110000 pid=4455 clone guuid=e33cacc4-1700-0000-72c4-36d06c110000 pid=4460 /usr/bin/rm delete-file guuid=26ecee6a-1600-0000-72c4-36d0ec0c0000 pid=3308->guuid=e33cacc4-1700-0000-72c4-36d06c110000 pid=4460 execve 0d3a7397-9f16-5b6f-bfb3-119900c026d0 104.168.4.206:80 guuid=3f08446b-1600-0000-72c4-36d0ee0c0000 pid=3310->0d3a7397-9f16-5b6f-bfb3-119900c026d0 send: 136B guuid=e6ef6b91-1600-0000-72c4-36d0470d0000 pid=3399->0d3a7397-9f16-5b6f-bfb3-119900c026d0 send: 136B guuid=4564ebbc-1600-0000-72c4-36d0b60d0000 pid=3510->0d3a7397-9f16-5b6f-bfb3-119900c026d0 send: 135B guuid=476e19e2-1600-0000-72c4-36d01a0e0000 pid=3610->0d3a7397-9f16-5b6f-bfb3-119900c026d0 send: 135B guuid=1153ef08-1700-0000-72c4-36d0950e0000 pid=3733 /tmp/dissx86 net send-data write-file zombie guuid=2f86c808-1700-0000-72c4-36d0930e0000 pid=3731->guuid=1153ef08-1700-0000-72c4-36d0950e0000 pid=3733 clone 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=1153ef08-1700-0000-72c4-36d0950e0000 pid=3733->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 8bffb074-0a94-5743-b355-539bce88d1b1 104.168.4.206:9987 guuid=1153ef08-1700-0000-72c4-36d0950e0000 pid=3733->8bffb074-0a94-5743-b355-539bce88d1b1 send: 87B guuid=3c79780a-1700-0000-72c4-36d09c0e0000 pid=3740->0d3a7397-9f16-5b6f-bfb3-119900c026d0 send: 136B guuid=3b3f3233-1700-0000-72c4-36d0260f0000 pid=3878->0d3a7397-9f16-5b6f-bfb3-119900c026d0 send: 137B guuid=a222365b-1700-0000-72c4-36d0c50f0000 pid=4037->0d3a7397-9f16-5b6f-bfb3-119900c026d0 send: 136B guuid=e2252381-1700-0000-72c4-36d061100000 pid=4193->0d3a7397-9f16-5b6f-bfb3-119900c026d0 send: 136B guuid=8dfeefa6-1700-0000-72c4-36d0f6100000 pid=4342->0d3a7397-9f16-5b6f-bfb3-119900c026d0 send: 136B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2026-10-05 11:07:31 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 661faee0e7c5c959724dc0db30a76ba67b5c8ef2dec7180eb2f649de77bf79ee

(this sample)

  
Delivery method
Distributed via web download

Comments