MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 71715f3dffa1f759daf555579cdd0c275637c3e47668e89dabac66c0a9529ab9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 8


Intelligence 8 IOCs YARA 3 File information Comments

SHA256 hash: 71715f3dffa1f759daf555579cdd0c275637c3e47668e89dabac66c0a9529ab9
SHA3-384 hash: 971110fd9d70a38dcb188784309d35d65c49768b5a4d78822022a6f4c902af0f074b8821a996ab9a7db77ed2c099aa8c
SHA1 hash: a052acd982ed8927579c83acc1f2bf6c8a53e8cf
MD5 hash: 8360e33f8394537cda9c241e7dc16cb1
humanhash: montana-five-crazy-lima
File name:fuckjewishpeople.sh
Download: download sample
Signature Gafgyt
File size:2'544 bytes
First seen:2026-02-18 18:21:36 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:wOqNZNfgNU/qNuNbKzAddqNYN4tCXaqN1NLc5QyqNNNTERB211qN1wN1A1V1a1fX:wOqNZNfgNU/qNuNuzAddqNYN4tCXaqNZ
TLSH T12A51B38F739BB722AFD3D472B45521302683C165D0ED5A4CF6C438DDD06DCA4A29D1D2
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.88.9.60/fuckjewishpeople.mipsn/an/amirai opendir
http://45.88.9.60/fuckjewishpeople.mpsln/an/amirai opendir
http://45.88.9.60/fuckjewishpeople.x86a98a6c69ee74c4b89a7bfb0ed8a116b2dd5e60be7bca8983061cd2b8082bdc5a Gafgytgafgyt mirai opendir
http://45.88.9.60/fuckjewishpeople.ppcn/an/amirai opendir
http://45.88.9.60/fuckjewishpeople.sparcn/an/amirai opendir
http://45.88.9.60/fuckjewishpeople.arm4n/an/amirai opendir
http://45.88.9.60/fuckjewishpeople.arm5n/an/amirai opendir
http://45.88.9.60/fuckjewishpeople.arm6n/an/amirai opendir
http://45.88.9.60/fuckjewishpeople.arm7n/an/amirai opendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
44
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive medusa mirai
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=1fec5c6b-1800-0000-fd4e-ae0c470d0000 pid=3399 /usr/bin/sudo guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405 /tmp/sample.bin guuid=1fec5c6b-1800-0000-fd4e-ae0c470d0000 pid=3399->guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405 execve guuid=d6095f6d-1800-0000-fd4e-ae0c4f0d0000 pid=3407 /usr/bin/pgrep guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=d6095f6d-1800-0000-fd4e-ae0c4f0d0000 pid=3407 execve guuid=a8b81971-1800-0000-fd4e-ae0c5a0d0000 pid=3418 /usr/bin/wget net send-data guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=a8b81971-1800-0000-fd4e-ae0c5a0d0000 pid=3418 execve guuid=297d6276-1800-0000-fd4e-ae0c6b0d0000 pid=3435 /usr/bin/curl net send-data write-file guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=297d6276-1800-0000-fd4e-ae0c6b0d0000 pid=3435 execve guuid=f765ab7b-1800-0000-fd4e-ae0c7c0d0000 pid=3452 /usr/bin/chmod guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=f765ab7b-1800-0000-fd4e-ae0c7c0d0000 pid=3452 execve guuid=45d7f47b-1800-0000-fd4e-ae0c7e0d0000 pid=3454 /usr/bin/bash guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=45d7f47b-1800-0000-fd4e-ae0c7e0d0000 pid=3454 clone guuid=eea74c7c-1800-0000-fd4e-ae0c800d0000 pid=3456 /usr/bin/rm delete-file guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=eea74c7c-1800-0000-fd4e-ae0c800d0000 pid=3456 execve guuid=c1d2a77c-1800-0000-fd4e-ae0c820d0000 pid=3458 /usr/bin/pgrep guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=c1d2a77c-1800-0000-fd4e-ae0c820d0000 pid=3458 execve guuid=cf569180-1800-0000-fd4e-ae0c8e0d0000 pid=3470 /usr/bin/wget net send-data guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=cf569180-1800-0000-fd4e-ae0c8e0d0000 pid=3470 execve guuid=b5514783-1800-0000-fd4e-ae0c990d0000 pid=3481 /usr/bin/curl net send-data write-file guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=b5514783-1800-0000-fd4e-ae0c990d0000 pid=3481 execve guuid=d58aa787-1800-0000-fd4e-ae0ca60d0000 pid=3494 /usr/bin/chmod guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=d58aa787-1800-0000-fd4e-ae0ca60d0000 pid=3494 execve guuid=6fb0e687-1800-0000-fd4e-ae0ca70d0000 pid=3495 /usr/bin/bash guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=6fb0e687-1800-0000-fd4e-ae0ca70d0000 pid=3495 clone guuid=09e90788-1800-0000-fd4e-ae0ca80d0000 pid=3496 /usr/bin/rm delete-file guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=09e90788-1800-0000-fd4e-ae0ca80d0000 pid=3496 execve guuid=383b4b88-1800-0000-fd4e-ae0ca90d0000 pid=3497 /usr/bin/pgrep guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=383b4b88-1800-0000-fd4e-ae0ca90d0000 pid=3497 execve guuid=ddc69b8a-1800-0000-fd4e-ae0caa0d0000 pid=3498 /usr/bin/wget net send-data write-file guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=ddc69b8a-1800-0000-fd4e-ae0caa0d0000 pid=3498 execve guuid=446c2994-1800-0000-fd4e-ae0cbb0d0000 pid=3515 /usr/bin/chmod guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=446c2994-1800-0000-fd4e-ae0cbb0d0000 pid=3515 execve guuid=41f46694-1800-0000-fd4e-ae0cbd0d0000 pid=3517 /tmp/fuckjewishpeople.x86 net guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=41f46694-1800-0000-fd4e-ae0cbd0d0000 pid=3517 execve guuid=aa8bb994-1800-0000-fd4e-ae0cc20d0000 pid=3522 /usr/bin/rm delete-file guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=aa8bb994-1800-0000-fd4e-ae0cc20d0000 pid=3522 execve guuid=96bbf994-1800-0000-fd4e-ae0cc40d0000 pid=3524 /usr/bin/pgrep guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=96bbf994-1800-0000-fd4e-ae0cc40d0000 pid=3524 execve guuid=5448aa97-1800-0000-fd4e-ae0ccc0d0000 pid=3532 /usr/bin/wget net send-data guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=5448aa97-1800-0000-fd4e-ae0ccc0d0000 pid=3532 execve guuid=f31a959a-1800-0000-fd4e-ae0cd70d0000 pid=3543 /usr/bin/curl net send-data write-file guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=f31a959a-1800-0000-fd4e-ae0cd70d0000 pid=3543 execve guuid=fa3bdea1-1800-0000-fd4e-ae0cdf0d0000 pid=3551 /usr/bin/chmod guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=fa3bdea1-1800-0000-fd4e-ae0cdf0d0000 pid=3551 execve guuid=c0ee23a2-1800-0000-fd4e-ae0ce10d0000 pid=3553 /usr/bin/bash guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=c0ee23a2-1800-0000-fd4e-ae0ce10d0000 pid=3553 clone guuid=d4a151a2-1800-0000-fd4e-ae0ce30d0000 pid=3555 /usr/bin/rm delete-file guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=d4a151a2-1800-0000-fd4e-ae0ce30d0000 pid=3555 execve guuid=846daea2-1800-0000-fd4e-ae0ce50d0000 pid=3557 /usr/bin/pgrep guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=846daea2-1800-0000-fd4e-ae0ce50d0000 pid=3557 execve guuid=6b7b6aa6-1800-0000-fd4e-ae0cf30d0000 pid=3571 /usr/bin/wget net send-data guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=6b7b6aa6-1800-0000-fd4e-ae0cf30d0000 pid=3571 execve guuid=9c4ffca8-1800-0000-fd4e-ae0cff0d0000 pid=3583 /usr/bin/curl net send-data write-file guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=9c4ffca8-1800-0000-fd4e-ae0cff0d0000 pid=3583 execve guuid=597326ae-1800-0000-fd4e-ae0c0d0e0000 pid=3597 /usr/bin/chmod guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=597326ae-1800-0000-fd4e-ae0c0d0e0000 pid=3597 execve guuid=3e9d6dae-1800-0000-fd4e-ae0c0f0e0000 pid=3599 /usr/bin/bash guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=3e9d6dae-1800-0000-fd4e-ae0c0f0e0000 pid=3599 clone guuid=87cc8cae-1800-0000-fd4e-ae0c100e0000 pid=3600 /usr/bin/rm delete-file guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=87cc8cae-1800-0000-fd4e-ae0c100e0000 pid=3600 execve guuid=c23ed9ae-1800-0000-fd4e-ae0c120e0000 pid=3602 /usr/bin/pgrep guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=c23ed9ae-1800-0000-fd4e-ae0c120e0000 pid=3602 execve guuid=17d130b1-1800-0000-fd4e-ae0c1a0e0000 pid=3610 /usr/bin/wget net send-data guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=17d130b1-1800-0000-fd4e-ae0c1a0e0000 pid=3610 execve guuid=6d9cc5b3-1800-0000-fd4e-ae0c230e0000 pid=3619 /usr/bin/curl net send-data write-file guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=6d9cc5b3-1800-0000-fd4e-ae0c230e0000 pid=3619 execve guuid=6d1bb7b7-1800-0000-fd4e-ae0c2d0e0000 pid=3629 /usr/bin/chmod guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=6d1bb7b7-1800-0000-fd4e-ae0c2d0e0000 pid=3629 execve guuid=5075f6b7-1800-0000-fd4e-ae0c2f0e0000 pid=3631 /usr/bin/bash guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=5075f6b7-1800-0000-fd4e-ae0c2f0e0000 pid=3631 clone guuid=74fd1eb8-1800-0000-fd4e-ae0c300e0000 pid=3632 /usr/bin/rm delete-file guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=74fd1eb8-1800-0000-fd4e-ae0c300e0000 pid=3632 execve guuid=763f65b8-1800-0000-fd4e-ae0c310e0000 pid=3633 /usr/bin/pgrep guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=763f65b8-1800-0000-fd4e-ae0c310e0000 pid=3633 execve guuid=b796cbba-1800-0000-fd4e-ae0c390e0000 pid=3641 /usr/bin/wget net send-data guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=b796cbba-1800-0000-fd4e-ae0c390e0000 pid=3641 execve guuid=4fe359bd-1800-0000-fd4e-ae0c410e0000 pid=3649 /usr/bin/curl net send-data write-file guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=4fe359bd-1800-0000-fd4e-ae0c410e0000 pid=3649 execve guuid=e4f831c1-1800-0000-fd4e-ae0c540e0000 pid=3668 /usr/bin/chmod guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=e4f831c1-1800-0000-fd4e-ae0c540e0000 pid=3668 execve guuid=e3fc71c1-1800-0000-fd4e-ae0c560e0000 pid=3670 /usr/bin/bash guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=e3fc71c1-1800-0000-fd4e-ae0c560e0000 pid=3670 clone guuid=08f38dc1-1800-0000-fd4e-ae0c580e0000 pid=3672 /usr/bin/rm delete-file guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=08f38dc1-1800-0000-fd4e-ae0c580e0000 pid=3672 execve guuid=32c3cdc1-1800-0000-fd4e-ae0c590e0000 pid=3673 /usr/bin/pgrep guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=32c3cdc1-1800-0000-fd4e-ae0c590e0000 pid=3673 execve guuid=01491bc4-1800-0000-fd4e-ae0c650e0000 pid=3685 /usr/bin/wget net send-data guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=01491bc4-1800-0000-fd4e-ae0c650e0000 pid=3685 execve guuid=62adc1c6-1800-0000-fd4e-ae0c700e0000 pid=3696 /usr/bin/curl net send-data write-file guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=62adc1c6-1800-0000-fd4e-ae0c700e0000 pid=3696 execve guuid=68673ccb-1800-0000-fd4e-ae0c760e0000 pid=3702 /usr/bin/chmod guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=68673ccb-1800-0000-fd4e-ae0c760e0000 pid=3702 execve guuid=bb99a0cb-1800-0000-fd4e-ae0c770e0000 pid=3703 /usr/bin/bash guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=bb99a0cb-1800-0000-fd4e-ae0c770e0000 pid=3703 clone guuid=1d22d8cb-1800-0000-fd4e-ae0c780e0000 pid=3704 /usr/bin/rm delete-file guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=1d22d8cb-1800-0000-fd4e-ae0c780e0000 pid=3704 execve guuid=16fd3fcc-1800-0000-fd4e-ae0c790e0000 pid=3705 /usr/bin/pgrep guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=16fd3fcc-1800-0000-fd4e-ae0c790e0000 pid=3705 execve guuid=4d3ad6cf-1800-0000-fd4e-ae0c7a0e0000 pid=3706 /usr/bin/wget net send-data guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=4d3ad6cf-1800-0000-fd4e-ae0c7a0e0000 pid=3706 execve guuid=548eabd2-1800-0000-fd4e-ae0c7e0e0000 pid=3710 /usr/bin/curl net send-data write-file guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=548eabd2-1800-0000-fd4e-ae0c7e0e0000 pid=3710 execve guuid=9f66efd7-1800-0000-fd4e-ae0c8d0e0000 pid=3725 /usr/bin/chmod guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=9f66efd7-1800-0000-fd4e-ae0c8d0e0000 pid=3725 execve guuid=86a82fd8-1800-0000-fd4e-ae0c8f0e0000 pid=3727 /usr/bin/bash guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=86a82fd8-1800-0000-fd4e-ae0c8f0e0000 pid=3727 clone guuid=060451d8-1800-0000-fd4e-ae0c900e0000 pid=3728 /usr/bin/rm delete-file guuid=0fed076d-1800-0000-fd4e-ae0c4d0d0000 pid=3405->guuid=060451d8-1800-0000-fd4e-ae0c900e0000 pid=3728 execve 9c86237a-5c91-532b-a088-1046223075f5 45.88.9.60:80 guuid=a8b81971-1800-0000-fd4e-ae0c5a0d0000 pid=3418->9c86237a-5c91-532b-a088-1046223075f5 send: 146B guuid=297d6276-1800-0000-fd4e-ae0c6b0d0000 pid=3435->9c86237a-5c91-532b-a088-1046223075f5 send: 95B guuid=cf569180-1800-0000-fd4e-ae0c8e0d0000 pid=3470->9c86237a-5c91-532b-a088-1046223075f5 send: 146B guuid=b5514783-1800-0000-fd4e-ae0c990d0000 pid=3481->9c86237a-5c91-532b-a088-1046223075f5 send: 95B guuid=ddc69b8a-1800-0000-fd4e-ae0caa0d0000 pid=3498->9c86237a-5c91-532b-a088-1046223075f5 send: 145B b4bf20d4-f7c8-5c24-8830-c23364537aa4 8.8.4.4:53 guuid=41f46694-1800-0000-fd4e-ae0cbd0d0000 pid=3517->b4bf20d4-f7c8-5c24-8830-c23364537aa4 con guuid=b5a09d94-1800-0000-fd4e-ae0cbf0d0000 pid=3519 /tmp/fuckjewishpeople.x86 guuid=41f46694-1800-0000-fd4e-ae0cbd0d0000 pid=3517->guuid=b5a09d94-1800-0000-fd4e-ae0cbf0d0000 pid=3519 clone guuid=f1e1a394-1800-0000-fd4e-ae0cc00d0000 pid=3520 /tmp/fuckjewishpeople.x86 net zombie guuid=b5a09d94-1800-0000-fd4e-ae0cbf0d0000 pid=3519->guuid=f1e1a394-1800-0000-fd4e-ae0cc00d0000 pid=3520 clone 58f9c086-22a6-58e4-9133-5b3d48617a57 45.88.9.60:4258 guuid=f1e1a394-1800-0000-fd4e-ae0cc00d0000 pid=3520->58f9c086-22a6-58e4-9133-5b3d48617a57 con guuid=5448aa97-1800-0000-fd4e-ae0ccc0d0000 pid=3532->9c86237a-5c91-532b-a088-1046223075f5 send: 145B guuid=f31a959a-1800-0000-fd4e-ae0cd70d0000 pid=3543->9c86237a-5c91-532b-a088-1046223075f5 send: 94B guuid=6b7b6aa6-1800-0000-fd4e-ae0cf30d0000 pid=3571->9c86237a-5c91-532b-a088-1046223075f5 send: 147B guuid=9c4ffca8-1800-0000-fd4e-ae0cff0d0000 pid=3583->9c86237a-5c91-532b-a088-1046223075f5 send: 96B guuid=17d130b1-1800-0000-fd4e-ae0c1a0e0000 pid=3610->9c86237a-5c91-532b-a088-1046223075f5 send: 146B guuid=6d9cc5b3-1800-0000-fd4e-ae0c230e0000 pid=3619->9c86237a-5c91-532b-a088-1046223075f5 send: 95B guuid=b796cbba-1800-0000-fd4e-ae0c390e0000 pid=3641->9c86237a-5c91-532b-a088-1046223075f5 send: 146B guuid=4fe359bd-1800-0000-fd4e-ae0c410e0000 pid=3649->9c86237a-5c91-532b-a088-1046223075f5 send: 95B guuid=01491bc4-1800-0000-fd4e-ae0c650e0000 pid=3685->9c86237a-5c91-532b-a088-1046223075f5 send: 146B guuid=62adc1c6-1800-0000-fd4e-ae0c700e0000 pid=3696->9c86237a-5c91-532b-a088-1046223075f5 send: 95B guuid=4d3ad6cf-1800-0000-fd4e-ae0c7a0e0000 pid=3706->9c86237a-5c91-532b-a088-1046223075f5 send: 146B guuid=548eabd2-1800-0000-fd4e-ae0c7e0e0000 pid=3710->9c86237a-5c91-532b-a088-1046223075f5 send: 95B
Threat name:
Linux.Trojan.Geninst
Status:
Malicious
First seen:
2026-02-18 19:15:56 UTC
AV detection:
20 of 38 (52.63%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
Reads CPU attributes
Reads system network configuration
Enumerates running processes
Reads system routing table
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 71715f3dffa1f759daf555579cdd0c275637c3e47668e89dabac66c0a9529ab9

(this sample)

  
Delivery method
Distributed via web download

Comments