MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 96e60b3bda86907eea1dd9d0b9289efe3f8cf9a29cc02db2dcc633c3b4df69c9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 96e60b3bda86907eea1dd9d0b9289efe3f8cf9a29cc02db2dcc633c3b4df69c9
SHA3-384 hash: 8f86b6eded0d6c5450a5e59c8ec5452554407af05ba41f406250ed70efca84487b0caadf0c4cd92a0fad0fd9e0c517a0
SHA1 hash: 640d1daf2b29b10b8db19439652a3aa119b89fdf
MD5 hash: c0d8f2ddeec3b44085648848530b04f0
humanhash: west-avocado-comet-carolina
File name:massload
Download: download sample
Signature Gafgyt
File size:2'649 bytes
First seen:2026-03-23 20:26:45 UTC
Last seen:2026-03-24 07:19:09 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:rMpzaC56GPn80DaeFO/HSH9lCyF9BTSCbFPdtBi:r8+s6GPnRaeFTL9B1i
TLSH T1165138EA3ED13F33064ACF14E3210A9B210F96D49493CED8545D2ABBBC78484B458EB9
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://91.92.241.94/mipsfb8d32cf60ffe401f131332f3efbe2bad5195df1147cf365bf87b31f30eaab3b Gafgytelf gafgyt mips mirai ua-wget
http://91.92.241.94/mpsl09f2377db44da366ff372ddea275560b28c5d35acc0648122c7c91e36c2926b8 Miraielf mips mirai ua-wget
http://91.92.241.94/arm4e0579990cd6a7586888a7df83ed27ae9f271deeccb7b876d8ceb7691f5372263 Miraiarm elf mirai ua-wget
http://91.92.241.94/arm5fb748f01edf3fc082671d237b70125743342f06317101fb8af4b22266d2604d8 Miraiarm elf mirai ua-wget
http://91.92.241.94/arm75676739d342c9927c7159da02e50c9061e5fdbe7068a07f21b87d60dce42bd9f Miraiarm elf mirai ua-wget

Intelligence


File Origin
# of uploads :
265
# of downloads :
15
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox mirai
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=9817f89e-1600-0000-5e4a-989af20f0000 pid=4082 /usr/bin/sudo guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088 /tmp/sample.bin guuid=9817f89e-1600-0000-5e4a-989af20f0000 pid=4082->guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088 execve guuid=286aa0f6-1600-0000-5e4a-989a6d110000 pid=4461 /usr/bin/dash guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=286aa0f6-1600-0000-5e4a-989a6d110000 pid=4461 clone guuid=acb25ef7-1600-0000-5e4a-989a76110000 pid=4470 /usr/bin/cp write-file guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=acb25ef7-1600-0000-5e4a-989a76110000 pid=4470 execve guuid=b95ee1fb-1600-0000-5e4a-989a85110000 pid=4485 /usr/bin/chmod guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=b95ee1fb-1600-0000-5e4a-989a85110000 pid=4485 execve guuid=5c7b18fc-1600-0000-5e4a-989a89110000 pid=4489 /usr/bin/rm delete-file guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=5c7b18fc-1600-0000-5e4a-989a89110000 pid=4489 execve guuid=8dd76dfc-1600-0000-5e4a-989a8a110000 pid=4490 /usr/bin/rm delete-file guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=8dd76dfc-1600-0000-5e4a-989a8a110000 pid=4490 execve guuid=502515ff-1600-0000-5e4a-989a91110000 pid=4497 /usr/bin/wget net send-data write-file guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=502515ff-1600-0000-5e4a-989a91110000 pid=4497 execve guuid=1541b10d-1700-0000-5e4a-989ac1110000 pid=4545 /usr/bin/chmod guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=1541b10d-1700-0000-5e4a-989ac1110000 pid=4545 execve guuid=338ffa0d-1700-0000-5e4a-989ac2110000 pid=4546 /usr/bin/dash guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=338ffa0d-1700-0000-5e4a-989ac2110000 pid=4546 clone guuid=ed0ad00e-1700-0000-5e4a-989ac6110000 pid=4550 /usr/bin/wget net send-data write-file guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=ed0ad00e-1700-0000-5e4a-989ac6110000 pid=4550 execve guuid=81d8cd1b-1700-0000-5e4a-989aff110000 pid=4607 /usr/bin/chmod guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=81d8cd1b-1700-0000-5e4a-989aff110000 pid=4607 execve guuid=f1b41b1c-1700-0000-5e4a-989a03120000 pid=4611 /usr/bin/dash guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=f1b41b1c-1700-0000-5e4a-989a03120000 pid=4611 clone guuid=9e0ad21c-1700-0000-5e4a-989a08120000 pid=4616 /usr/bin/wget net send-data write-file guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=9e0ad21c-1700-0000-5e4a-989a08120000 pid=4616 execve guuid=8bb5fa27-1700-0000-5e4a-989a2c120000 pid=4652 /usr/bin/chmod guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=8bb5fa27-1700-0000-5e4a-989a2c120000 pid=4652 execve guuid=d5523d28-1700-0000-5e4a-989a30120000 pid=4656 /usr/bin/dash guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=d5523d28-1700-0000-5e4a-989a30120000 pid=4656 clone guuid=15870429-1700-0000-5e4a-989a35120000 pid=4661 /usr/bin/wget net send-data write-file guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=15870429-1700-0000-5e4a-989a35120000 pid=4661 execve guuid=faf21e34-1700-0000-5e4a-989a68120000 pid=4712 /usr/bin/chmod guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=faf21e34-1700-0000-5e4a-989a68120000 pid=4712 execve guuid=bb986f34-1700-0000-5e4a-989a69120000 pid=4713 /usr/bin/dash guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=bb986f34-1700-0000-5e4a-989a69120000 pid=4713 clone guuid=a3951235-1700-0000-5e4a-989a6d120000 pid=4717 /usr/bin/wget net send-data write-file guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=a3951235-1700-0000-5e4a-989a6d120000 pid=4717 execve guuid=f820d342-1700-0000-5e4a-989a9c120000 pid=4764 /usr/bin/chmod guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=f820d342-1700-0000-5e4a-989a9c120000 pid=4764 execve guuid=9fe61243-1700-0000-5e4a-989a9e120000 pid=4766 /usr/bin/dash guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=9fe61243-1700-0000-5e4a-989a9e120000 pid=4766 clone guuid=53089a43-1700-0000-5e4a-989aa2120000 pid=4770 /usr/bin/curl net send-data write-file guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=53089a43-1700-0000-5e4a-989aa2120000 pid=4770 execve guuid=ee4aee51-1700-0000-5e4a-989ade120000 pid=4830 /usr/bin/chmod guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=ee4aee51-1700-0000-5e4a-989ade120000 pid=4830 execve guuid=63b45252-1700-0000-5e4a-989ae0120000 pid=4832 /usr/bin/dash guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=63b45252-1700-0000-5e4a-989ae0120000 pid=4832 clone guuid=9cb21b53-1700-0000-5e4a-989ae4120000 pid=4836 /usr/bin/curl net send-data write-file guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=9cb21b53-1700-0000-5e4a-989ae4120000 pid=4836 execve guuid=30774362-1700-0000-5e4a-989a12130000 pid=4882 /usr/bin/chmod guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=30774362-1700-0000-5e4a-989a12130000 pid=4882 execve guuid=3753bb62-1700-0000-5e4a-989a14130000 pid=4884 /usr/bin/dash guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=3753bb62-1700-0000-5e4a-989a14130000 pid=4884 clone guuid=64b7aa63-1700-0000-5e4a-989a18130000 pid=4888 /usr/bin/curl net send-data write-file guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=64b7aa63-1700-0000-5e4a-989a18130000 pid=4888 execve guuid=b1608570-1700-0000-5e4a-989a3f130000 pid=4927 /usr/bin/chmod guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=b1608570-1700-0000-5e4a-989a3f130000 pid=4927 execve guuid=ee2ee370-1700-0000-5e4a-989a41130000 pid=4929 /usr/bin/dash guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=ee2ee370-1700-0000-5e4a-989a41130000 pid=4929 clone guuid=561ac971-1700-0000-5e4a-989a45130000 pid=4933 /usr/bin/curl net send-data write-file guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=561ac971-1700-0000-5e4a-989a45130000 pid=4933 execve guuid=bbe62480-1700-0000-5e4a-989a78130000 pid=4984 /usr/bin/chmod guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=bbe62480-1700-0000-5e4a-989a78130000 pid=4984 execve guuid=78216280-1700-0000-5e4a-989a7a130000 pid=4986 /usr/bin/dash guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=78216280-1700-0000-5e4a-989a7a130000 pid=4986 clone guuid=1d9ef180-1700-0000-5e4a-989a7e130000 pid=4990 /usr/bin/curl net send-data write-file guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=1d9ef180-1700-0000-5e4a-989a7e130000 pid=4990 execve guuid=bde23f8f-1700-0000-5e4a-989abb130000 pid=5051 /usr/bin/chmod guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=bde23f8f-1700-0000-5e4a-989abb130000 pid=5051 execve guuid=3e537a8f-1700-0000-5e4a-989abd130000 pid=5053 /usr/bin/dash guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=3e537a8f-1700-0000-5e4a-989abd130000 pid=5053 clone guuid=3785f68f-1700-0000-5e4a-989ac1130000 pid=5057 /usr/bin/busybox net send-data write-file guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=3785f68f-1700-0000-5e4a-989ac1130000 pid=5057 execve guuid=d0babfb1-1700-0000-5e4a-989a46140000 pid=5190 /usr/bin/chmod guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=d0babfb1-1700-0000-5e4a-989a46140000 pid=5190 execve guuid=58b3fcb1-1700-0000-5e4a-989a48140000 pid=5192 /usr/bin/dash guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=58b3fcb1-1700-0000-5e4a-989a48140000 pid=5192 clone guuid=08c54db3-1700-0000-5e4a-989a4f140000 pid=5199 /usr/bin/busybox net send-data write-file guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=08c54db3-1700-0000-5e4a-989a4f140000 pid=5199 execve guuid=54ddd9d6-1700-0000-5e4a-989a93140000 pid=5267 /usr/bin/chmod guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=54ddd9d6-1700-0000-5e4a-989a93140000 pid=5267 execve guuid=f77d37d7-1700-0000-5e4a-989a94140000 pid=5268 /usr/bin/dash guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=f77d37d7-1700-0000-5e4a-989a94140000 pid=5268 clone guuid=65e45ad8-1700-0000-5e4a-989a96140000 pid=5270 /usr/bin/busybox net send-data write-file guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=65e45ad8-1700-0000-5e4a-989a96140000 pid=5270 execve guuid=091a1efa-1700-0000-5e4a-989a9a140000 pid=5274 /usr/bin/chmod guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=091a1efa-1700-0000-5e4a-989a9a140000 pid=5274 execve guuid=67395dfa-1700-0000-5e4a-989a9b140000 pid=5275 /usr/bin/dash guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=67395dfa-1700-0000-5e4a-989a9b140000 pid=5275 clone guuid=bd5b78fb-1700-0000-5e4a-989a9d140000 pid=5277 /usr/bin/busybox net send-data write-file guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=bd5b78fb-1700-0000-5e4a-989a9d140000 pid=5277 execve guuid=01b56c1d-1800-0000-5e4a-989aa6140000 pid=5286 /usr/bin/chmod guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=01b56c1d-1800-0000-5e4a-989aa6140000 pid=5286 execve guuid=bc7fcb1d-1800-0000-5e4a-989aa7140000 pid=5287 /usr/bin/dash guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=bc7fcb1d-1800-0000-5e4a-989aa7140000 pid=5287 clone guuid=2d8e401f-1800-0000-5e4a-989aa9140000 pid=5289 /usr/bin/busybox net send-data write-file guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=2d8e401f-1800-0000-5e4a-989aa9140000 pid=5289 execve guuid=d26dee43-1800-0000-5e4a-989aaa140000 pid=5290 /usr/bin/chmod guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=d26dee43-1800-0000-5e4a-989aaa140000 pid=5290 execve guuid=75be3a44-1800-0000-5e4a-989aab140000 pid=5291 /usr/bin/dash guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=75be3a44-1800-0000-5e4a-989aab140000 pid=5291 clone guuid=d5e8e045-1800-0000-5e4a-989aad140000 pid=5293 /usr/bin/busybox send-data guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=d5e8e045-1800-0000-5e4a-989aad140000 pid=5293 execve guuid=7f5ff048-1b00-0000-5e4a-989ad5140000 pid=5333 /usr/bin/chmod guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=7f5ff048-1b00-0000-5e4a-989ad5140000 pid=5333 execve guuid=c0164049-1b00-0000-5e4a-989ad6140000 pid=5334 /usr/bin/dash guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=c0164049-1b00-0000-5e4a-989ad6140000 pid=5334 clone guuid=7489cb49-1b00-0000-5e4a-989ad8140000 pid=5336 /usr/bin/busybox send-data guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=7489cb49-1b00-0000-5e4a-989ad8140000 pid=5336 execve guuid=1c15e14c-1e00-0000-5e4a-989ad9140000 pid=5337 /usr/bin/chmod guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=1c15e14c-1e00-0000-5e4a-989ad9140000 pid=5337 execve guuid=ffd62a4d-1e00-0000-5e4a-989ada140000 pid=5338 /usr/bin/dash guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=ffd62a4d-1e00-0000-5e4a-989ada140000 pid=5338 clone guuid=61c1be4d-1e00-0000-5e4a-989adc140000 pid=5340 /usr/bin/busybox send-data guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=61c1be4d-1e00-0000-5e4a-989adc140000 pid=5340 execve guuid=68dde250-2100-0000-5e4a-989add140000 pid=5341 /usr/bin/chmod guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=68dde250-2100-0000-5e4a-989add140000 pid=5341 execve guuid=e8192c51-2100-0000-5e4a-989ade140000 pid=5342 /usr/bin/dash guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=e8192c51-2100-0000-5e4a-989ade140000 pid=5342 clone guuid=da85ba51-2100-0000-5e4a-989ae0140000 pid=5344 /usr/bin/busybox send-data guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=da85ba51-2100-0000-5e4a-989ae0140000 pid=5344 execve guuid=f918b254-2400-0000-5e4a-989ae1140000 pid=5345 /usr/bin/chmod guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=f918b254-2400-0000-5e4a-989ae1140000 pid=5345 execve guuid=69b3fa54-2400-0000-5e4a-989ae2140000 pid=5346 /usr/bin/dash guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=69b3fa54-2400-0000-5e4a-989ae2140000 pid=5346 clone guuid=5e358455-2400-0000-5e4a-989ae4140000 pid=5348 /usr/bin/busybox send-data guuid=bc0843a1-1600-0000-5e4a-989af80f0000 pid=4088->guuid=5e358455-2400-0000-5e4a-989ae4140000 pid=5348 execve guuid=95e2abf6-1600-0000-5e4a-989a6e110000 pid=4462 /usr/bin/cat guuid=286aa0f6-1600-0000-5e4a-989a6d110000 pid=4461->guuid=95e2abf6-1600-0000-5e4a-989a6e110000 pid=4462 execve guuid=0e52b3f6-1600-0000-5e4a-989a6f110000 pid=4463 /usr/bin/grep guuid=286aa0f6-1600-0000-5e4a-989a6d110000 pid=4461->guuid=0e52b3f6-1600-0000-5e4a-989a6f110000 pid=4463 execve guuid=7399b8f6-1600-0000-5e4a-989a70110000 pid=4464 /usr/bin/grep guuid=286aa0f6-1600-0000-5e4a-989a6d110000 pid=4461->guuid=7399b8f6-1600-0000-5e4a-989a70110000 pid=4464 execve guuid=fa86bcf6-1600-0000-5e4a-989a72110000 pid=4466 /usr/bin/grep guuid=286aa0f6-1600-0000-5e4a-989a6d110000 pid=4461->guuid=fa86bcf6-1600-0000-5e4a-989a72110000 pid=4466 execve guuid=1583c0f6-1600-0000-5e4a-989a73110000 pid=4467 /usr/bin/cut guuid=286aa0f6-1600-0000-5e4a-989a6d110000 pid=4461->guuid=1583c0f6-1600-0000-5e4a-989a73110000 pid=4467 execve 59a44c65-0739-58c2-b090-c9afea904369 91.92.241.94:80 guuid=502515ff-1600-0000-5e4a-989a91110000 pid=4497->59a44c65-0739-58c2-b090-c9afea904369 send: 131B guuid=ed0ad00e-1700-0000-5e4a-989ac6110000 pid=4550->59a44c65-0739-58c2-b090-c9afea904369 send: 131B guuid=9e0ad21c-1700-0000-5e4a-989a08120000 pid=4616->59a44c65-0739-58c2-b090-c9afea904369 send: 131B guuid=15870429-1700-0000-5e4a-989a35120000 pid=4661->59a44c65-0739-58c2-b090-c9afea904369 send: 131B guuid=a3951235-1700-0000-5e4a-989a6d120000 pid=4717->59a44c65-0739-58c2-b090-c9afea904369 send: 131B guuid=53089a43-1700-0000-5e4a-989aa2120000 pid=4770->59a44c65-0739-58c2-b090-c9afea904369 send: 80B guuid=9cb21b53-1700-0000-5e4a-989ae4120000 pid=4836->59a44c65-0739-58c2-b090-c9afea904369 send: 80B guuid=64b7aa63-1700-0000-5e4a-989a18130000 pid=4888->59a44c65-0739-58c2-b090-c9afea904369 send: 80B guuid=561ac971-1700-0000-5e4a-989a45130000 pid=4933->59a44c65-0739-58c2-b090-c9afea904369 send: 80B guuid=1d9ef180-1700-0000-5e4a-989a7e130000 pid=4990->59a44c65-0739-58c2-b090-c9afea904369 send: 80B 3b5d256f-1c73-5117-a101-dfc6b7ef2c42 91.92.241.94:21 guuid=3785f68f-1700-0000-5e4a-989ac1130000 pid=5057->3b5d256f-1c73-5117-a101-dfc6b7ef2c42 send: 78B b11d0f3d-b96d-5875-96a0-39a94021623e 91.92.241.94:37893 guuid=3785f68f-1700-0000-5e4a-989ac1130000 pid=5057->b11d0f3d-b96d-5875-96a0-39a94021623e con guuid=08c54db3-1700-0000-5e4a-989a4f140000 pid=5199->3b5d256f-1c73-5117-a101-dfc6b7ef2c42 send: 78B f8222edd-b6cd-5456-a4ad-8b126a551ad4 91.92.241.94:35991 guuid=08c54db3-1700-0000-5e4a-989a4f140000 pid=5199->f8222edd-b6cd-5456-a4ad-8b126a551ad4 con guuid=65e45ad8-1700-0000-5e4a-989a96140000 pid=5270->3b5d256f-1c73-5117-a101-dfc6b7ef2c42 send: 78B 80ed8869-5ecc-51c0-bed9-90b30bdb9c5a 91.92.241.94:41025 guuid=65e45ad8-1700-0000-5e4a-989a96140000 pid=5270->80ed8869-5ecc-51c0-bed9-90b30bdb9c5a con guuid=bd5b78fb-1700-0000-5e4a-989a9d140000 pid=5277->3b5d256f-1c73-5117-a101-dfc6b7ef2c42 send: 78B 0236a968-ab5d-5cd5-9f48-574a334e35ce 91.92.241.94:34365 guuid=bd5b78fb-1700-0000-5e4a-989a9d140000 pid=5277->0236a968-ab5d-5cd5-9f48-574a334e35ce con guuid=2d8e401f-1800-0000-5e4a-989aa9140000 pid=5289->3b5d256f-1c73-5117-a101-dfc6b7ef2c42 send: 78B 5a5dc477-139e-516d-a08f-11f1a992a79a 91.92.241.94:35169 guuid=2d8e401f-1800-0000-5e4a-989aa9140000 pid=5289->5a5dc477-139e-516d-a08f-11f1a992a79a con c064a359-6c73-5304-946c-32a9c49acc94 91.92.241.94:69 guuid=d5e8e045-1800-0000-5e4a-989aad140000 pid=5293->c064a359-6c73-5304-946c-32a9c49acc94 send: 252B guuid=7489cb49-1b00-0000-5e4a-989ad8140000 pid=5336->c064a359-6c73-5304-946c-32a9c49acc94 send: 252B guuid=61c1be4d-1e00-0000-5e4a-989adc140000 pid=5340->c064a359-6c73-5304-946c-32a9c49acc94 send: 252B guuid=da85ba51-2100-0000-5e4a-989ae0140000 pid=5344->c064a359-6c73-5304-946c-32a9c49acc94 send: 252B guuid=5e358455-2400-0000-5e4a-989ae4140000 pid=5348->c064a359-6c73-5304-946c-32a9c49acc94 send: 126B
Gathering data
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-23 21:38:58 UTC
File Type:
Text (Shell)
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 96e60b3bda86907eea1dd9d0b9289efe3f8cf9a29cc02db2dcc633c3b4df69c9

(this sample)

  
Delivery method
Distributed via web download

Comments