🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6e4cef2e5490e725bda01c60b51ad64b7ee4905cd94948d8dbca776b5cd75fe4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 6e4cef2e5490e725bda01c60b51ad64b7ee4905cd94948d8dbca776b5cd75fe4
SHA3-384 hash: e7869dd8504a0dcd5bdf21cf5c863278d6dee8bbbe7909a0415e0c4218e0b6a256f44d684bada9c173aa690798e18de3
SHA1 hash: fade627761232f17f616be37b4d3b172d5219f2d
MD5 hash: adf0c9401e6e94a970fd0507eab41a59
humanhash: uncle-georgia-green-eleven
File name:bins.sh
Download: download sample
Signature Gafgyt
File size:2'207 bytes
First seen:2025-02-22 16:06:25 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:1cVugPkbpsUTNIbEjUwIq3y98RKdOaMaLaoZv:1cVugPkbpsUwEjUwIq3Y8RqDt+oR
TLSH T1AC41B08A916A09756EA0F92733F78C103696E09BC4D6AF0919DC76E9008DDCF2017AF7
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://37.44.238.66/hoodlum.mips372488b8cecb45ce03923f19df5d904980761cd8a7f2ca87ce6c5b7fcff0e20a Gafgytelf gafgyt opendir
http://37.44.238.66/hoodlum.mpsla18ad447236c0345bbaae2ff79e736af5de72ed5eae0d7389690e74b0cd79246 Gafgytelf gafgyt opendir
http://37.44.238.66/hoodlum.sh420a9ba9737ef22133db526bf26b8b376191b5e4457b1b406384af0346bcdc4f1 Gafgytelf gafgyt opendir
http://37.44.238.66/hoodlum.x86b18fd19ba74bb9322a684d9fceda45d57c587f6d2488b8b45a093531762d0020 Gafgytelf gafgyt opendir
http://37.44.238.66/hoodlum.arm6d761ae38684f805fd09725a77aeb65ead2b807a023d0d7de3f8c0148d0355d69 Gafgytelf gafgyt opendir
http://37.44.238.66/hoodlum.i6868fd2ef68325614ca08a318ee89a9747fcc680b5802fe64b3439e25fb987d375f Gafgytelf gafgyt opendir
http://37.44.238.66/hoodlum.ppcacd7c50951d69571efab27356514e232338de5ddf1e2632b7a1af090778c4d2a Gafgytelf gafgyt opendir
http://37.44.238.66/hoodlum.i586bef49b6194de69c6a390caead8ec74e6c0641b911699b3ffb9c9856509883c8e Gafgytelf gafgyt opendir
http://37.44.238.66/hoodlum.m68kb27399321ed2641a450c52811c7ea3b2e6eef864aab7c49f66e95cb2245dc330 Gafgytelf gafgyt opendir
http://37.44.238.66/hoodlum.sparcd6ac8e4f0b117ff7fb14a4de30f52ed5ecaf3c9791d0ab01dec075b973e59aad Gafgytelf gafgyt opendir
http://37.44.238.66/hoodlum.arm4fabd6308a61a5991c5da0945256ceee26cc88b5e839e41dc02444bdafe485667 Gafgytelf gafgyt opendir
http://37.44.238.66/hoodlum.arm510962293ec817a48997b8d2c9e4a43610373a35fe7360937f261e5d278fdef7e Gafgytelf gafgyt opendir
http://37.44.238.66/hoodlum.arm7n/an/an/a
http://37.44.238.66/hoodlum.ppc440fpn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
16
Origin country :
US US
Vendor Threat Intelligence
Verdict:
Malicious
Score:
94.9%
Tags:
downloader trojan agent
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
lolbin obfuscated remote
Threat name:
Win32.Trojan.Generic
Status:
Malicious
First seen:
2025-02-22 16:07:11 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 6e4cef2e5490e725bda01c60b51ad64b7ee4905cd94948d8dbca776b5cd75fe4

(this sample)

  
Delivery method
Distributed via web download

Comments