MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 81da269aff4745ba4e326dd488e4dc4b1031a47cc12c5af3bf2e6164489480ee. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 81da269aff4745ba4e326dd488e4dc4b1031a47cc12c5af3bf2e6164489480ee
SHA3-384 hash: 6e4ccd9c526d4c5577bb29b9a84dd563ca96a8101d4cf511096f1491fec59a42b09f361a20e837b27627c463d3be0476
SHA1 hash: c0fd34b9aaa1d782563889e5f475f7ceffb4cb03
MD5 hash: 479feb8fba4aa6a2c999a767b6c31451
humanhash: nuts-emma-rugby-chicken
File name:ur0a.sh
Download: download sample
Signature Gafgyt
File size:1'727 bytes
First seen:2026-04-23 11:37:43 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:YpgpGhpgpIpbspM53pG/kypMpC3pspShpQ3pj:YKshCC9sC0fWCWCu3J
TLSH T1183150C621E198757DF5F52732A88510B8C5A1C752CFAF49AEEC38D484CDD08B415B93
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139.143/MIPS41ae9c9293e3fa20bb467cd3e0551837101ec592f84a12bb3a649dbb79cf7638 Miraielf gafgyt mips mirai opendir ua-wget
http://176.65.139.143/MIPSELn/an/aelf gafgyt mips opendir ua-wget
http://176.65.139.143/SH42c203bf2914035458200a9300783e6a08d624693febf17650e8f8b6b39c18488 Miraielf gafgyt mirai opendir SuperH ua-wget
http://176.65.139.143/X86_64c876cffb991d5916bf5fd3bc4991dabf3e7ee776481f77bfc11bb3d20cf92ada Miraielf gafgyt mirai opendir ua-wget x86
http://176.65.139.143/I6861608f9c477cd52dd4f36eb9af46cb65d7a719019d7ff60e858446c397cc75bde Miraielf gafgyt mirai opendir ua-wget x86
http://176.65.139.143/POWERPC2f7d62f92942a794d1bbc33a6447d2665b98538a9c7a49a236b1d1dd2423cc28 Miraielf gafgyt mirai opendir PowerPC ua-wget
http://176.65.139.143/I586bf0df86359d4d81f8e6c752b52824748b5ac223fd6ce5e28891f703cc946e432 Miraielf gafgyt mirai opendir ua-wget x86
http://176.65.139.143/M68K9bfe534e6df528c366b30b62cfffc2b13fe9ceb6a7e49418d58585b4463ca6da Miraielf m68k mirai opendir ua-wget
http://176.65.139.143/SPARC4c5979118963c5f00fee20087e7ea65f7a07234f6befd17a39b943aa5d294f61 Miraielf mirai opendir sparc ua-wget
http://176.65.139.143/ARMV4L9ad3b2928edfa615d0d19220dfc52c0a176f8d2f55ba3fe129879325840da4d4 Gafgytarm elf gafgyt opendir ua-wget
http://176.65.139.143/ARMV5Le141465a9a44bd03a86e594d80609921771a1f12bcc656e97b39d5bd01c63a56 Gafgytarm elf gafgyt geofenced opendir ua-wget USA
http://176.65.139.143/ARMV6Lf4fa39763da0dd7a2b6f2033442fb586557ea23451b797ab5cf9699e2ae4b6f1 Gafgytarm elf gafgyt mirai opendir ua-wget
http://176.65.139.143/ARMV7Lcdca813e68da420c7aae63fc7a31f926413c8d24e42c0add78795e339509a3f0 Gafgytarm elf gafgyt mirai opendir ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive medusa mirai
Verdict:
Malicious
File Type:
text
First seen:
2026-04-23T08:11:00Z UTC
Last seen:
2026-04-24T14:44:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=f44237be-1600-0000-34d6-d3cef00e0000 pid=3824 /usr/bin/sudo guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831 /tmp/sample.bin guuid=f44237be-1600-0000-34d6-d3cef00e0000 pid=3824->guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831 execve guuid=dfa797c0-1600-0000-34d6-d3cef90e0000 pid=3833 /usr/bin/wget net send-data write-file guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=dfa797c0-1600-0000-34d6-d3cef90e0000 pid=3833 execve guuid=80414fc5-1600-0000-34d6-d3ce0d0f0000 pid=3853 /usr/bin/chmod guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=80414fc5-1600-0000-34d6-d3ce0d0f0000 pid=3853 execve guuid=5f7c99c5-1600-0000-34d6-d3ce0e0f0000 pid=3854 /usr/bin/dash guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=5f7c99c5-1600-0000-34d6-d3ce0e0f0000 pid=3854 clone guuid=053fa7c5-1600-0000-34d6-d3ce0f0f0000 pid=3855 /usr/bin/rm guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=053fa7c5-1600-0000-34d6-d3ce0f0f0000 pid=3855 execve guuid=3bb4ebc5-1600-0000-34d6-d3ce110f0000 pid=3857 /usr/bin/wget net send-data write-file guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=3bb4ebc5-1600-0000-34d6-d3ce110f0000 pid=3857 execve guuid=65f9a5c9-1600-0000-34d6-d3ce1c0f0000 pid=3868 /usr/bin/chmod guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=65f9a5c9-1600-0000-34d6-d3ce1c0f0000 pid=3868 execve guuid=f4a5edc9-1600-0000-34d6-d3ce1d0f0000 pid=3869 /usr/bin/dash guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=f4a5edc9-1600-0000-34d6-d3ce1d0f0000 pid=3869 clone guuid=c2d801ca-1600-0000-34d6-d3ce1e0f0000 pid=3870 /usr/bin/rm guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=c2d801ca-1600-0000-34d6-d3ce1e0f0000 pid=3870 execve guuid=b41782ca-1600-0000-34d6-d3ce220f0000 pid=3874 /usr/bin/wget net send-data write-file guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=b41782ca-1600-0000-34d6-d3ce220f0000 pid=3874 execve guuid=53c223cf-1600-0000-34d6-d3ce310f0000 pid=3889 /usr/bin/chmod guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=53c223cf-1600-0000-34d6-d3ce310f0000 pid=3889 execve guuid=b06668cf-1600-0000-34d6-d3ce320f0000 pid=3890 /usr/bin/dash guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=b06668cf-1600-0000-34d6-d3ce320f0000 pid=3890 clone guuid=6d7f7ccf-1600-0000-34d6-d3ce330f0000 pid=3891 /usr/bin/rm guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=6d7f7ccf-1600-0000-34d6-d3ce330f0000 pid=3891 execve guuid=b63fdfcf-1600-0000-34d6-d3ce350f0000 pid=3893 /usr/bin/wget net send-data write-file guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=b63fdfcf-1600-0000-34d6-d3ce350f0000 pid=3893 execve guuid=2af192d4-1600-0000-34d6-d3ce480f0000 pid=3912 /usr/bin/chmod guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=2af192d4-1600-0000-34d6-d3ce480f0000 pid=3912 execve guuid=79f9e9d4-1600-0000-34d6-d3ce4a0f0000 pid=3914 /usr/bin/dash guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=79f9e9d4-1600-0000-34d6-d3ce4a0f0000 pid=3914 clone guuid=a388f3d4-1600-0000-34d6-d3ce4b0f0000 pid=3915 /usr/bin/rm guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=a388f3d4-1600-0000-34d6-d3ce4b0f0000 pid=3915 execve guuid=462233d5-1600-0000-34d6-d3ce4c0f0000 pid=3916 /usr/bin/wget net send-data write-file guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=462233d5-1600-0000-34d6-d3ce4c0f0000 pid=3916 execve guuid=59acdfd8-1600-0000-34d6-d3ce550f0000 pid=3925 /usr/bin/chmod guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=59acdfd8-1600-0000-34d6-d3ce550f0000 pid=3925 execve guuid=56c422d9-1600-0000-34d6-d3ce560f0000 pid=3926 /usr/bin/dash guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=56c422d9-1600-0000-34d6-d3ce560f0000 pid=3926 clone guuid=78222cd9-1600-0000-34d6-d3ce570f0000 pid=3927 /usr/bin/rm guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=78222cd9-1600-0000-34d6-d3ce570f0000 pid=3927 execve guuid=e7f56cd9-1600-0000-34d6-d3ce580f0000 pid=3928 /usr/bin/wget net send-data write-file guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=e7f56cd9-1600-0000-34d6-d3ce580f0000 pid=3928 execve guuid=f460cedc-1600-0000-34d6-d3ce590f0000 pid=3929 /usr/bin/chmod guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=f460cedc-1600-0000-34d6-d3ce590f0000 pid=3929 execve guuid=ccfb0edd-1600-0000-34d6-d3ce5a0f0000 pid=3930 /usr/bin/dash guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=ccfb0edd-1600-0000-34d6-d3ce5a0f0000 pid=3930 clone guuid=eb751add-1600-0000-34d6-d3ce5b0f0000 pid=3931 /usr/bin/rm guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=eb751add-1600-0000-34d6-d3ce5b0f0000 pid=3931 execve guuid=c69459dd-1600-0000-34d6-d3ce5c0f0000 pid=3932 /usr/bin/wget net send-data write-file guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=c69459dd-1600-0000-34d6-d3ce5c0f0000 pid=3932 execve guuid=f692e7e0-1600-0000-34d6-d3ce620f0000 pid=3938 /usr/bin/chmod guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=f692e7e0-1600-0000-34d6-d3ce620f0000 pid=3938 execve guuid=f3fc4de1-1600-0000-34d6-d3ce640f0000 pid=3940 /usr/bin/dash guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=f3fc4de1-1600-0000-34d6-d3ce640f0000 pid=3940 clone guuid=c65a5de1-1600-0000-34d6-d3ce650f0000 pid=3941 /usr/bin/rm guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=c65a5de1-1600-0000-34d6-d3ce650f0000 pid=3941 execve guuid=8b7da4e1-1600-0000-34d6-d3ce680f0000 pid=3944 /usr/bin/wget net send-data write-file guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=8b7da4e1-1600-0000-34d6-d3ce680f0000 pid=3944 execve guuid=13c753e6-1600-0000-34d6-d3ce7d0f0000 pid=3965 /usr/bin/chmod guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=13c753e6-1600-0000-34d6-d3ce7d0f0000 pid=3965 execve guuid=3c968fe6-1600-0000-34d6-d3ce7f0f0000 pid=3967 /usr/bin/dash guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=3c968fe6-1600-0000-34d6-d3ce7f0f0000 pid=3967 clone guuid=0a079ce6-1600-0000-34d6-d3ce800f0000 pid=3968 /usr/bin/rm guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=0a079ce6-1600-0000-34d6-d3ce800f0000 pid=3968 execve guuid=e16626e7-1600-0000-34d6-d3ce820f0000 pid=3970 /usr/bin/wget net send-data write-file guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=e16626e7-1600-0000-34d6-d3ce820f0000 pid=3970 execve guuid=731720ec-1600-0000-34d6-d3ce930f0000 pid=3987 /usr/bin/chmod guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=731720ec-1600-0000-34d6-d3ce930f0000 pid=3987 execve guuid=0fd260ec-1600-0000-34d6-d3ce970f0000 pid=3991 /usr/bin/dash guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=0fd260ec-1600-0000-34d6-d3ce970f0000 pid=3991 clone guuid=08ea66ec-1600-0000-34d6-d3ce980f0000 pid=3992 /usr/bin/rm guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=08ea66ec-1600-0000-34d6-d3ce980f0000 pid=3992 execve guuid=baeda3ec-1600-0000-34d6-d3ce990f0000 pid=3993 /usr/bin/wget net send-data write-file guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=baeda3ec-1600-0000-34d6-d3ce990f0000 pid=3993 execve guuid=252138f0-1600-0000-34d6-d3cea80f0000 pid=4008 /usr/bin/chmod guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=252138f0-1600-0000-34d6-d3cea80f0000 pid=4008 execve guuid=a989a3f0-1600-0000-34d6-d3cea90f0000 pid=4009 /usr/bin/dash guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=a989a3f0-1600-0000-34d6-d3cea90f0000 pid=4009 clone guuid=19c8b4f0-1600-0000-34d6-d3ceab0f0000 pid=4011 /usr/bin/rm guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=19c8b4f0-1600-0000-34d6-d3ceab0f0000 pid=4011 execve guuid=51fb22f1-1600-0000-34d6-d3cead0f0000 pid=4013 /usr/bin/wget net send-data write-file guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=51fb22f1-1600-0000-34d6-d3cead0f0000 pid=4013 execve guuid=da96e1f5-1600-0000-34d6-d3cebe0f0000 pid=4030 /usr/bin/chmod guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=da96e1f5-1600-0000-34d6-d3cebe0f0000 pid=4030 execve guuid=05c93af6-1600-0000-34d6-d3cec00f0000 pid=4032 /usr/bin/dash guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=05c93af6-1600-0000-34d6-d3cec00f0000 pid=4032 clone guuid=80764bf6-1600-0000-34d6-d3cec10f0000 pid=4033 /usr/bin/rm guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=80764bf6-1600-0000-34d6-d3cec10f0000 pid=4033 execve guuid=380c97f6-1600-0000-34d6-d3cec50f0000 pid=4037 /usr/bin/wget net send-data write-file guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=380c97f6-1600-0000-34d6-d3cec50f0000 pid=4037 execve guuid=2f2220fb-1600-0000-34d6-d3ced40f0000 pid=4052 /usr/bin/chmod guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=2f2220fb-1600-0000-34d6-d3ced40f0000 pid=4052 execve guuid=11195afb-1600-0000-34d6-d3ced60f0000 pid=4054 /usr/bin/dash guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=11195afb-1600-0000-34d6-d3ced60f0000 pid=4054 clone guuid=4d9464fb-1600-0000-34d6-d3ced70f0000 pid=4055 /usr/bin/rm guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=4d9464fb-1600-0000-34d6-d3ced70f0000 pid=4055 execve guuid=8a099ffb-1600-0000-34d6-d3ced90f0000 pid=4057 /usr/bin/wget net send-data write-file guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=8a099ffb-1600-0000-34d6-d3ced90f0000 pid=4057 execve guuid=a1b0d4ff-1600-0000-34d6-d3cee80f0000 pid=4072 /usr/bin/chmod guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=a1b0d4ff-1600-0000-34d6-d3cee80f0000 pid=4072 execve guuid=f4782200-1700-0000-34d6-d3ceec0f0000 pid=4076 /usr/bin/dash guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=f4782200-1700-0000-34d6-d3ceec0f0000 pid=4076 clone guuid=46f22c00-1700-0000-34d6-d3ceed0f0000 pid=4077 /usr/bin/rm guuid=bfd456c0-1600-0000-34d6-d3cef70e0000 pid=3831->guuid=46f22c00-1700-0000-34d6-d3ceed0f0000 pid=4077 execve f7922c93-220b-5752-9f3f-7fa0632a371e 176.65.139.143:80 guuid=dfa797c0-1600-0000-34d6-d3cef90e0000 pid=3833->f7922c93-220b-5752-9f3f-7fa0632a371e send: 133B guuid=3bb4ebc5-1600-0000-34d6-d3ce110f0000 pid=3857->f7922c93-220b-5752-9f3f-7fa0632a371e send: 135B guuid=b41782ca-1600-0000-34d6-d3ce220f0000 pid=3874->f7922c93-220b-5752-9f3f-7fa0632a371e send: 132B guuid=b63fdfcf-1600-0000-34d6-d3ce350f0000 pid=3893->f7922c93-220b-5752-9f3f-7fa0632a371e send: 135B guuid=462233d5-1600-0000-34d6-d3ce4c0f0000 pid=3916->f7922c93-220b-5752-9f3f-7fa0632a371e send: 133B guuid=e7f56cd9-1600-0000-34d6-d3ce580f0000 pid=3928->f7922c93-220b-5752-9f3f-7fa0632a371e send: 136B guuid=c69459dd-1600-0000-34d6-d3ce5c0f0000 pid=3932->f7922c93-220b-5752-9f3f-7fa0632a371e send: 133B guuid=8b7da4e1-1600-0000-34d6-d3ce680f0000 pid=3944->f7922c93-220b-5752-9f3f-7fa0632a371e send: 133B guuid=e16626e7-1600-0000-34d6-d3ce820f0000 pid=3970->f7922c93-220b-5752-9f3f-7fa0632a371e send: 134B guuid=baeda3ec-1600-0000-34d6-d3ce990f0000 pid=3993->f7922c93-220b-5752-9f3f-7fa0632a371e send: 135B guuid=51fb22f1-1600-0000-34d6-d3cead0f0000 pid=4013->f7922c93-220b-5752-9f3f-7fa0632a371e send: 135B guuid=380c97f6-1600-0000-34d6-d3cec50f0000 pid=4037->f7922c93-220b-5752-9f3f-7fa0632a371e send: 135B guuid=8a099ffb-1600-0000-34d6-d3ced90f0000 pid=4057->f7922c93-220b-5752-9f3f-7fa0632a371e send: 135B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-04-23 02:33:43 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 81da269aff4745ba4e326dd488e4dc4b1031a47cc12c5af3bf2e6164489480ee

(this sample)

  
Delivery method
Distributed via web download

Comments