MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9676aea60b4fbc50abaf49b824eca4fbb59b1ac12aa6e9501003a28eacdff910. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 9676aea60b4fbc50abaf49b824eca4fbb59b1ac12aa6e9501003a28eacdff910
SHA3-384 hash: 19364a4844c72ade9e70e4b8ca8d2c929a7b05436402ce187be5d1641a796001601f2081192fca4f3b254b91d9a12220
SHA1 hash: 1ead38c1dd775b787d4b4dbb003e63d4c0b949d6
MD5 hash: 5b60f21c4975138294704160e0a29e26
humanhash: equal-illinois-saturn-orange
File name:fx
Download: download sample
Signature Gafgyt
File size:1'320 bytes
First seen:2024-12-29 02:01:18 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:XwZ6wnWwfKRjwT6soe3eSsoe3ePe3efyoe3ed5Qe3eWve3e/e3Y:XwZ6wWwfajwT6meSme0efy7ed5eWUeEY
TLSH T12D21F6535A8C75F4B7CEA91AB6A38BDA58DDD09F3D430702E838C2EA7C805245A34F70
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://185.157.247.35/mpsl18c99e6db38118a4d50a0bca8dd475f700d3ff172a73fb6a48bdd599d4abae95 Gafgytelf gafgyt mirai
http://185.157.247.35/mips4fc73b02bd0cc4d44ee8da03ce5ab8b74fb67409fb223c3f36b06dc22dc0dd74 Gafgyt32-bit elf gafgyt mirai
http://185.157.247.35/arm7d2ea0eed1f82458ed76a956ca3fd1f72d1c1e29b40a6118d1e5f1e6d78418077 Miraielf mirai
http://185.157.247.35/arm2f66b28645b910c0fcb7a751e9a0dad86fd2be825d07f45dd6ab086ec2eeafc0 Mirai32-bit elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
103
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
97.4%
Tags:
trojan mirai agent virus
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug evasive
Result
Verdict:
UNKNOWN
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2024-12-29 03:02:23 UTC
File Type:
Text (Shell)
AV detection:
8 of 38 (21.05%)
Threat level:
  3/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 9676aea60b4fbc50abaf49b824eca4fbb59b1ac12aa6e9501003a28eacdff910

(this sample)

  
Delivery method
Distributed via web download

Comments