MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7a2f1eaa22364619718c27b04a5ed545bdaa88cd3bc7e99676b2b618156ff698. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 7a2f1eaa22364619718c27b04a5ed545bdaa88cd3bc7e99676b2b618156ff698
SHA3-384 hash: 9421455091e7186529dccbcd0b14225b9780d3f00eb34be16fd2a7f4dc6d89da90422537e099f1daf3d725c46d56e5f3
SHA1 hash: 37130011e611f606fb7473affac452e2c3707f07
MD5 hash: 4ab9270085839c685da1c9a3185f5ab8
humanhash: oxygen-video-speaker-low
File name:msps
Download: download sample
Signature Gafgyt
File size:64'300 bytes
First seen:2025-04-27 18:32:22 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 1536:b3o+expkZXlG9X4LxbKEmc4BKc9BwaT/Iqv61RdV:b3oUZJbKEmc4BKGTIqS1fV
TLSH T19E53C59E2E369FEEF36EC33447B70A75D254239A26D1CB84D26DF1051E2020E485FBA5
telfhash t1bd012848883826f59b760dd82bbdff75e05130df0a129e778d10b99ada2e9429e00c0c
Magika elf
Reporter abuse_ch
Tags:elf gafgyt

Intelligence


File Origin
# of uploads :
1
# of downloads :
100
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
mirai
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
mips
Packer:
not packed
Botnet:
unknown
Number of open files:
0
Number of processes launched:
1
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
no suspicious findings
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Linux.Backdoor.Gafgyt
Status:
Malicious
First seen:
2025-04-24 16:06:31 UTC
File Type:
ELF32 Big (Exe)
AV detection:
16 of 36 (44.44%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

elf 7a2f1eaa22364619718c27b04a5ed545bdaa88cd3bc7e99676b2b618156ff698

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh

Comments