🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 930de83919cf565a5e3779cb284eea971d3787d605cd68b8702e7097c1172d4b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: 930de83919cf565a5e3779cb284eea971d3787d605cd68b8702e7097c1172d4b
SHA3-384 hash: 40c11ff08622469f4f59e8788772c19211ecfeffa0cdca9683f1c6ff5e9049631d797d2c420b95abffb3c72924361109
SHA1 hash: 024cfb180037b542aaad41dd8330f0d797d34bc3
MD5 hash: a23e61b3d2822d367944ad0bb171348e
humanhash: muppet-saturn-india-arkansas
File name:jew.sh
Download: download sample
Signature Gafgyt
File size:1'648 bytes
First seen:2025-03-05 06:31:40 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vGZTfw+/0ohOJReJi/Nsqy11i7gNsqy1XXUUAJ:vGZ7w+8ohOJRsi/Nsqy11i7gNsqy1XXc
TLSH T17331DCDA216316F8ACD0FE573279894575E0F1CA54CAAF4CA8EC38F5429CE4C7404B93
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.148.10.136/jew.mips596c2174f15304ad6029db214b0f4b5ebb97552be7f9d9a170fe03bbc7c762c1 Gafgytgafgyt
http://45.148.10.136/jew.mpslb01c52cf964f0dc79b47c14cbe995eb8134c1de404ad7205554ea72afc7f9f0f Gafgytgafgyt
http://45.148.10.136/jew.sh43cd8f829bcf3c3242a369e5d364de494038cc3a1495c4562aa2179691a63376f Gafgytgafgyt
http://45.148.10.136/jew.x864273837b79c6626c5dd81ff49a38ddcc339b08ca5f0e29e04617e1f9457fd01a Gafgytgafgyt
http://45.148.10.136/jew.arm61379f22b0325522df4e2e52e011f107e3cbb65c82c9d3b39b1468856ce1d9a39 Gafgytgafgyt
http://45.148.10.136/jew.x3292feda0008629fc2031eefc7e940051bbf8fb9b1daf214c6eef033f8211fd688 Gafgytgafgyt
http://45.148.10.136/jew.ppc217e9be37888e8f1dfc24258133d14486f687930249ee2cdb22ac0ab07a3f04e Gafgytgafgyt
http://45.148.10.136/jew.i5867baf296fc930c9042e8517fa5e887ff845425a8b268583efec9c03005b52cbe8 Gafgytgafgyt
http://45.148.10.136/jew.m68k44ac81f6d2930c325820e624cbfcce93a13e6dbc2e9d3b5e4197420786034aeb Gafgytgafgyt
http://45.148.10.136/jew.arm41709b02971823ea8c5c5385764b96ef40f02fed09bde331cb7ff69463fc0a454 Gafgytgafgyt
http://45.148.10.136/jew.arm51709b02971823ea8c5c5385764b96ef40f02fed09bde331cb7ff69463fc0a454 Gafgytn/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
84
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.1%
Tags:
downloader agent virus
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Threat name:
Win32.Trojan.Gafgyt
Status:
Malicious
First seen:
2025-03-04 02:24:00 UTC
File Type:
Text (Shell)
AV detection:
25 of 38 (65.79%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 930de83919cf565a5e3779cb284eea971d3787d605cd68b8702e7097c1172d4b

(this sample)

  
Delivery method
Distributed via web download

Comments