MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7ba3fc024b28feb4f16b2d394548b89754b9ac96693208bb7919abadde8a2c0b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: 7ba3fc024b28feb4f16b2d394548b89754b9ac96693208bb7919abadde8a2c0b
SHA3-384 hash: b8da78c5744cfaea351cab21eb7bf818e63179b6a27d247caed385fbaa18e2d13c9118d5df5bc51339780bc255e064b0
SHA1 hash: 82533a33775f866a19e8b964f1cf3a53879bb289
MD5 hash: ced2fa2f5c482b9df48c94652ad1d214
humanhash: avocado-paris-enemy-beryllium
File name:bins.sh
Download: download sample
Signature Gafgyt
File size:1'636 bytes
First seen:2025-01-30 06:46:22 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:vfW+fdfMc4kfRasflf8sfq+fTEsfNfvJfNfO:vh1t4kpbdJy+1F3JFW
TLSH T1413150CF22A14570ECB4AD7F7A6AB90031D4A59AD9C62F5828DC3CFA44CDF0DB401693
Magika shell
Reporter abuse_ch
Tags:gafgyt sh
URLMalware sample (SHA256 hash)SignatureTags
http://bins.freesite.host/bins/mips921efaaa6d6a1d418adc5e361aaf814fadcc852bcd962529c1294fd5c9729a0a Miraielf mirai
http://bins.freesite.host/bins/mipsel3dd8697121a0f7bc93f89c472ed90da2722182b8828fe01fdba9bb943b334062 Miraielf mirai
http://bins.freesite.host/bins/sh4264697a73d4ef26e4962e9bd0b9f3a6172b70d9cd471d005dac622953bed5eef Miraielf mirai
http://bins.freesite.host/bins/x86b443936b8cac69390e7f04299c84a36d82813a558bc2a11b5038967f7258c270 Miraielf mirai
http://bins.freesite.host/bins/armv6l9f6654478a37fc23b7639e2fce75f28f1650f7d9c55f8ba742d8eb5888064282 Miraielf mirai
http://bins.freesite.host/bins/i686aee06aa7372d223dfe26631169ff9eac561616f6b7ac9c12c5c3bc3852af94d8 Miraielf mirai
http://bins.freesite.host/bins/powerpc828951aeed9f4059c5ddd2cd6bd865c37b316aa91b3029ef22a9e50b4587ce64 Miraielf mirai
http://bins.freesite.host/bins/i586145a131ac6e33dc568118ca1a5f750ae99ef5d153c26862a122bd3c5e913aca7 Miraielf mirai
http://bins.freesite.host/bins/m68k1616c02e0fe3c09d4795481023c968d3c6594d06ee8feac13844153c34ae8ae6 Miraielf mirai
http://bins.freesite.host/bins/sparcc8e412c4e16349986bf0f81ec58543cfb648ac3c8cc81516b3ffe62145e6e3e0 Miraielf mirai
http://bins.freesite.host/bins/armv4lfad077d9b2e42581ef9e01cbabd695e138720344b2a33bb57429a6c5673adcb1 Gafgytelf gafgyt
http://bins.freesite.host/bins/armv5la39970a2cbd7788d6a1941731ea9f39a4809253b898781d6ccb193b265244857 Gafgytelf gafgyt

Intelligence


File Origin
# of uploads :
1
# of downloads :
102
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
91.7%
Tags:
trojandownloader agent
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive lolbin remote
Result
Verdict:
MALICIOUS
Threat name:
Win32.Trojan.Gafgyt
Status:
Malicious
First seen:
2025-01-30 02:12:16 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt botnet defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Reads system network configuration
Reads system routing table
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Detected Gafgyt variant
Gafgyt family
Gafgyt/Bashlite
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 7ba3fc024b28feb4f16b2d394548b89754b9ac96693208bb7919abadde8a2c0b

(this sample)

  
Delivery method
Distributed via web download

Comments