MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7658c4f7d5b708cb7345f1cfb4d26c50c3ef70a75ab25b1bf1bddafea47cc184. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 7658c4f7d5b708cb7345f1cfb4d26c50c3ef70a75ab25b1bf1bddafea47cc184
SHA3-384 hash: 080b6fb8e8231d8e80209840411045e671e5bea7ba0503857c5e455c7a402639ba2aba1170a1be374c050f2eeedcd589
SHA1 hash: 313e4dadd1209dfee114f1cfe40d426063368337
MD5 hash: 24bbaab2d34a3903feb28d2f29a15c38
humanhash: romeo-gee-georgia-william
File name:fuckjewishpeople.sh
Download: download sample
Signature Gafgyt
File size:2'035 bytes
First seen:2025-04-26 13:53:12 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:UufgNA5bKzATNd4tC5SLc5yJ6TERdS1f1A1V1a1hUBaXevwFqxgTfvYNI:UufgNA5uzATNd4tC5SLc5yJ6TERc1f1l
TLSH T1CB415B4B73DBA625EEE7E472749060202383C489D0ED9B4CF6E935CDD0A9CA4736A5C2
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://156.253.227.62/fuckjewishpeople.mipsc6ef0b4aad5a272cbbb6e1f305dfa66860b12f3bdb659f9a3aba4d17d98d444f Gafgytcensys elf gafgyt ua-wget
http://156.253.227.62/fuckjewishpeople.mpsl448497005a8e29b62b13a948a0a380e2c7f729fddb1f5b2b3d20ca36b0da940c Gafgytcensys elf gafgyt ua-wget
http://156.253.227.62/fuckjewishpeople.x8620ac4542f8084f31bf327f53eb77cf3bf62c13a4f81896d41c8f4d9d0f243ad3 Ladvixcensys elf ladvix ua-wget
http://156.253.227.62/fuckjewishpeople.ppcn/an/acensys elf ua-wget
http://156.253.227.62/fuckjewishpeople.sparc107a7be3e5f2771bd6e7e649cd9db20ab9c5bbd8f1cb0a891989b7dfdd64db06 Gafgytcensys elf gafgyt ua-wget
http://156.253.227.62/fuckjewishpeople.arm433a296d63d4960fa1e4cfdd8ab442b1c12a05aa291a10bc66262f69e3b292c5d Gafgytcensys elf gafgyt ua-wget
http://156.253.227.62/fuckjewishpeople.arm59a5ba03d1ebefd585836a591674db613e6ab3647ea288b1c002a96c9280bc337 Gafgytcensys elf gafgyt ua-wget
http://156.253.227.62/fuckjewishpeople.arm69871f430ea86c08b2a4ae8952f892579684858f2fbcd6d6922a5c8b349a5444c Gafgytcensys elf gafgyt ua-wget
http://156.253.227.62/fuckjewishpeople.arm72b9a413dd90e4e84ad97cd67f03c4f64e77f24537cbf2364169e1877320056bc Gafgytcensys elf gafgyt ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
92.5%
Tags:
downloader agent hype
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
lolbin remote
Threat name:
Linux.Trojan.Geninst
Status:
Malicious
First seen:
2025-04-26 13:54:16 UTC
File Type:
Text (Shell)
AV detection:
17 of 24 (70.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 7658c4f7d5b708cb7345f1cfb4d26c50c3ef70a75ab25b1bf1bddafea47cc184

(this sample)

  
Delivery method
Distributed via web download

Comments