MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 73691c73ab823bdff7a9672eff9532958e870daf4c5fb047750347ec164ccac4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 73691c73ab823bdff7a9672eff9532958e870daf4c5fb047750347ec164ccac4
SHA3-384 hash: 3a333881d550dd1c59f48b8488c4f3ecfda1c7eb373e1fca5375ae4cbf142e4f7568b51eeff0d498e6320ee03a44479e
SHA1 hash: 226a9e3d3acf527278a4180145e35ab946a22cda
MD5 hash: d637a9002d762fb61d090b94e381136e
humanhash: red-ten-freddie-michigan
File name:rondo.aqu.sh
Download: download sample
Signature Gafgyt
File size:10'876 bytes
First seen:2026-01-08 07:03:45 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:hiOfWVc1dZd4cjzlZ16EMvyK6tTVRei0E3a+nIlIfm1Uvp6Yr+weCOnlxko+yz:hs9W7I1vVYTSPPCQn
TLSH T1332238C83DD213B728ED4852A1D7837C5F84C5F570639DA6F40A8AB6AAB044CF2DDB51
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://41.231.37.153/rondo.loln/an/aua-wget
http://41.231.37.153/rondo.x86_64a5f035343b91205375751e0fb4d828aef261532508ef80129ffe7a9ba8a30ed0 Gafgytgafgyt RondoDox ua-wget
http://41.231.37.153/rondo.i686293a3a492aef65a88cf5434ee66ad55875deb66885871c9199296e707fb17926 Miraimirai ua-wget
http://41.231.37.153/rondo.i58638b3192b7e792073bde272b917f53336ad35d17482d5140b362f697861bd2c55 Miraimirai ua-wget
http://41.231.37.153/rondo.i486f1beda333a121d1fc43ca60075f62a6e9848b5d9e41ef177d934ebc7138a696f Miraimirai ua-wget
http://41.231.37.153/rondo.armv6l29ed805642950a7709d058067ec1882d877beb02e67b56b673b5e2d2b17272d2 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.armv5l635916119ab6903aa6f8672e8c59d9c658c279b6fee9b7490abfff1b58395402 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.armv4l92a92f68af94dfc82046ebe54a51a639d972608d2516255250cd222ad2b8fddd Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.armv7lec6125b2e7dba1419d5cb0d0ffbcd40de93826062968999d29a933f1485249dc Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.powerpc852713af646fc9ebe10d87b98556f42763cd8490bcb855847a46e6db0fced634 Miraimirai ua-wget
http://41.231.37.153/rondo.powerpc-440fp2311ce1f03fd7a7c7b2130ebcd7cf84c346e22cec9e00749835746cfd2f2efa5 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.mips5075648683ceb6822b87509f97f7d15436d510feb0a019053084cb63eb44520d Gafgytgafgyt ua-wget
http://41.231.37.153/rondo.mipseld4d72de0e0335c9a3f3eec7cdfd93f7fcc5ee85fc1b8692b8fdab77355db7190 Gafgytgafgyt ua-wget
http://41.231.37.153/rondo.arc700a448a233d175276ab77aa4cf9fd63dd02f9e6fd5f4ee160ce99f177df7d27d11 Miraimirai ua-wget
http://41.231.37.153/rondo.sh487b5360fc1a9b326ab7cdece074614eb30e23bd0ff7b179cb121e29aac0edb31 Miraimirai ua-wget
http://41.231.37.153/rondo.sparc8ccaa9a601ec1a1750338b8074d60609b53cde76135f1761fd705428dd195bb7 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.m68k9aedf0f1ae99ae01eed2d8edec1dd9f2a2257435a91c6a57d4b368946b0f1d18 Miraimirai ua-wget
http://41.231.37.153/rondo.armebb335b5eeaf8ea4f275a66c22322e2f35a36707979aa430ea3dadc29564f3ba09 MiraiRondoDox ua-wget
http://41.231.37.153/rondo.armebhf4e7384185cdff726ae05bad052983c0b3854bd5a3a69897d980cacef2f9a06fc RondoDoxua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
51
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive masquerade
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-08T04:37:00Z UTC
Last seen:
2026-01-08T05:10:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Threat name:
Script-Shell.Trojan.Heuristic
Status:
Malicious
First seen:
2026-01-08 07:04:31 UTC
File Type:
Text (Shell)
AV detection:
7 of 24 (29.17%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:xmrig antivm credential_access defense_evasion discovery execution linux miner persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to shm directory
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads CPU attributes
Reads process memory
Abuse Elevation Control Mechanism: Sudo and Sudo Caching
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Deletes log files
Enumerates running processes
Modifies init.d
Modifies rc script
Reads hardware information
Reads list of loaded kernel modules
Write file to user bin folder
Writes file to system bin folder
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Renames itself
XMRig Miner payload
Xmrig family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 73691c73ab823bdff7a9672eff9532958e870daf4c5fb047750347ec164ccac4

(this sample)

  
Delivery method
Distributed via web download

Comments