MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 83494ed11fc33a848fd5c8d6fc92d92b9a5a4c712fc9ecfcdb84cef6271ea0bf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 83494ed11fc33a848fd5c8d6fc92d92b9a5a4c712fc9ecfcdb84cef6271ea0bf
SHA3-384 hash: 774c0388568851a82d6f30160ec7bad52666041da0e5c038867695832258a4047f6869beff77a8ef75e153c5adf7f949
SHA1 hash: 655b3e158548d7bbc89f38330490d97c554b2988
MD5 hash: 11b5319f12983cb1c99edc750d66724c
humanhash: earth-table-asparagus-failed
File name:update.sh
Download: download sample
Signature Gafgyt
File size:3'529 bytes
First seen:2024-09-28 08:52:01 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:1zFzT5zwztEgzNzJKu1DzizMIzGzhzu+zukzjz6ezJzTz+z0Kz4zfzRzvzYzCqoc:AU/+Zoj
TLSH T1FA7190DEE2442474CCC47D6AA4E0CBB4BD2FC2B13F32B799E8488B968947940BF11785
Magika shell
Reporter NDA0E
Tags:botnet dayzddos dedsec gafgyt KAITEN roze RyM sh unknown Vixaati Yakuza

Intelligence


File Origin
# of uploads :
1
# of downloads :
156
Origin country :
NL NL
Vendor Threat Intelligence
Verdict:
Malicious
Score:
90.2%
Tags:
Mirai
Verdict:
Malicious
Threat level:
  10/10
Confidence:
80%
Tags:
masquerade
Result
Verdict:
MALICIOUS
Threat name:
Script-Shell.Trojan.MiraiA
Status:
Malicious
First seen:
2024-09-28 07:57:02 UTC
File Type:
Text (Shell)
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt botnet defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Detected Gafgyt variant
Gafgyt/Bashlite
Malware Config
C2 Extraction:
185.82.202.195:4444
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 83494ed11fc33a848fd5c8d6fc92d92b9a5a4c712fc9ecfcdb84cef6271ea0bf

(this sample)

  
Delivery method
Distributed via web download

Comments