MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9d58c8da57d83083136f5bf2ca519d11bc3a503d643835fc515920958993cd9c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 9d58c8da57d83083136f5bf2ca519d11bc3a503d643835fc515920958993cd9c
SHA3-384 hash: 499e18942e9f29e3baf851bbb73094d58578aa28fe050f4493a2ef715afbc28fc95b897025bfa706c39ab907a5b54830
SHA1 hash: 501036f9483ad2a6b784735264a5b2463138254e
MD5 hash: a385351657f5ac0f46a7ff24feb6594f
humanhash: venus-seven-low-winner
File name:logsbins.sh
Download: download sample
Signature Gafgyt
File size:3'588 bytes
First seen:2025-10-07 22:36:40 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vI2rI0IYIQzIlxMlFIEIQIoIu3IUIoI4IFaIHsI2rI0IYIQzIlxMlFIEIQIoIu3S:vxR1dJJ9thBFt1ksxR1dJJ9thBFt1G
TLSH T126716ECB71721B342DE0E96B366A890475E0A08B54C79F956CEC39F940CDF847826EA7
Magika shell
Reporter abuse_ch
Tags:gafgyt sh
URLMalware sample (SHA256 hash)SignatureTags
http://78.142.229.12/sshd93d40417b1a60b8807eb9933218f71086601be047b341c779577bc21b8f0fc64 Miraielf gafgyt mirai ua-wget
http://78.142.229.12/telnetdf611f21467ae2f4f9cbc671e6f60022237821ba8771c8808962e5b03c1ea6258 Miraielf gafgyt mirai ua-wget
http://78.142.229.12/system4add06fd7831a8f85ac0fadb1f97c6a36848a6b1107d5551e3a570eed7ea366a Miraielf gafgyt mirai ua-wget
http://78.142.229.12/ssh37040becf8aa5878cf183ad4dc8adb408175628c59b5828cd5b9d3cc99a60b85 Miraielf gafgyt mirai ua-wget
http://78.142.229.12/dbus-daemon6fe013d0ceec620ce9e20c10c9041c67c8f9238cbf5132b456b74335eed03076 Miraielf gafgyt mirai ua-wget
http://78.142.229.12/cronfc928ba3b7fb408a933c9e4854e0e74bf7de5a815818fd085e53d8b7247e5705 Miraielf gafgyt mirai ua-wget
http://78.142.229.12/rsyslogdc5251e252d8b94dac5b525ded92b0777acad9120cbf9111b76fe982d1f22370c Gafgytelf gafgyt mirai ua-wget
http://78.142.229.12/getty0c06e226c8ed6b8ea93b8c6c25b336d0f00a19d908378ee51b57b2a7abc313c5 Gafgytelf gafgyt mirai ua-wget
http://78.142.229.12/katrina253323f9c6e8f52917123fff333aeb7740e249a642a444a8c30484eae5236ab3 Miraielf gafgyt mirai ua-wget
http://78.142.229.12/agetty6adac86bf0a67c68c36d72e1e5216da5ac92062f4c51ed20afc72f2d86bf385e Gafgytelf gafgyt mirai ua-wget
http://78.142.229.12/klogddfb966237322190a59784b6e5d2a1e2fa477db2f79ed1567c51fc6e9ed1588f5 Miraielf gafgyt mirai ua-wget
http://78.142.229.12/shd75cd4210b50f78eb246762b9bb8d83a5fcdd1aac47cbddda5af123fd55781b8 Miraielf gafgyt mirai ua-wget
http://78.142.229.12/sd77dfc766af0616f59fef98f8bc82767f4b76dabc3b24cbdabd4c5d3cbd70e3f Miraielf gafgyt mirai ua-wget
http://78.142.229.12/kworkern/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-07T19:46:00Z UTC
Last seen:
2025-10-07T20:15:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=89871a75-1900-0000-3a7d-bfa6b40f0000 pid=4020 /usr/bin/sudo guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032 /tmp/sample.bin guuid=89871a75-1900-0000-3a7d-bfa6b40f0000 pid=4020->guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032 execve guuid=c622b677-1900-0000-3a7d-bfa6c20f0000 pid=4034 /usr/bin/wget net send-data write-file guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=c622b677-1900-0000-3a7d-bfa6c20f0000 pid=4034 execve guuid=72a80980-1900-0000-3a7d-bfa6de0f0000 pid=4062 /usr/bin/chmod guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=72a80980-1900-0000-3a7d-bfa6de0f0000 pid=4062 execve guuid=87b14a80-1900-0000-3a7d-bfa6df0f0000 pid=4063 /usr/bin/bash guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=87b14a80-1900-0000-3a7d-bfa6df0f0000 pid=4063 clone guuid=b8381181-1900-0000-3a7d-bfa6e10f0000 pid=4065 /usr/bin/rm delete-file guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=b8381181-1900-0000-3a7d-bfa6e10f0000 pid=4065 execve guuid=3bc16081-1900-0000-3a7d-bfa6e40f0000 pid=4068 /usr/bin/wget net send-data write-file guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=3bc16081-1900-0000-3a7d-bfa6e40f0000 pid=4068 execve guuid=04518a8b-1900-0000-3a7d-bfa6fe0f0000 pid=4094 /usr/bin/chmod guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=04518a8b-1900-0000-3a7d-bfa6fe0f0000 pid=4094 execve guuid=4508e78b-1900-0000-3a7d-bfa6ff0f0000 pid=4095 /usr/bin/bash guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=4508e78b-1900-0000-3a7d-bfa6ff0f0000 pid=4095 clone guuid=e7b7818c-1900-0000-3a7d-bfa602100000 pid=4098 /usr/bin/rm delete-file guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=e7b7818c-1900-0000-3a7d-bfa602100000 pid=4098 execve guuid=7ae8e28c-1900-0000-3a7d-bfa603100000 pid=4099 /usr/bin/wget net send-data write-file guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=7ae8e28c-1900-0000-3a7d-bfa603100000 pid=4099 execve guuid=c8c6b192-1900-0000-3a7d-bfa616100000 pid=4118 /usr/bin/chmod guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=c8c6b192-1900-0000-3a7d-bfa616100000 pid=4118 execve guuid=4a3c0e93-1900-0000-3a7d-bfa619100000 pid=4121 /usr/bin/bash guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=4a3c0e93-1900-0000-3a7d-bfa619100000 pid=4121 clone guuid=7a3fc493-1900-0000-3a7d-bfa61b100000 pid=4123 /usr/bin/rm delete-file guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=7a3fc493-1900-0000-3a7d-bfa61b100000 pid=4123 execve guuid=bd042894-1900-0000-3a7d-bfa61d100000 pid=4125 /usr/bin/wget net send-data write-file guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=bd042894-1900-0000-3a7d-bfa61d100000 pid=4125 execve guuid=6e502b9a-1900-0000-3a7d-bfa638100000 pid=4152 /usr/bin/chmod guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=6e502b9a-1900-0000-3a7d-bfa638100000 pid=4152 execve guuid=90a5989a-1900-0000-3a7d-bfa63a100000 pid=4154 /tmp/ssh net guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=90a5989a-1900-0000-3a7d-bfa63a100000 pid=4154 execve guuid=aea01d9b-1900-0000-3a7d-bfa640100000 pid=4160 /usr/bin/rm delete-file guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=aea01d9b-1900-0000-3a7d-bfa640100000 pid=4160 execve guuid=90bf7a9b-1900-0000-3a7d-bfa643100000 pid=4163 /usr/bin/wget net send-data write-file guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=90bf7a9b-1900-0000-3a7d-bfa643100000 pid=4163 execve guuid=648ad6a1-1900-0000-3a7d-bfa656100000 pid=4182 /usr/bin/chmod guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=648ad6a1-1900-0000-3a7d-bfa656100000 pid=4182 execve guuid=289623a2-1900-0000-3a7d-bfa657100000 pid=4183 /usr/bin/bash guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=289623a2-1900-0000-3a7d-bfa657100000 pid=4183 clone guuid=d10fd3a2-1900-0000-3a7d-bfa65a100000 pid=4186 /usr/bin/rm delete-file guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=d10fd3a2-1900-0000-3a7d-bfa65a100000 pid=4186 execve guuid=d1fd21a3-1900-0000-3a7d-bfa65c100000 pid=4188 /usr/bin/wget net send-data write-file guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=d1fd21a3-1900-0000-3a7d-bfa65c100000 pid=4188 execve guuid=6dfa74a6-1900-0000-3a7d-bfa66e100000 pid=4206 /usr/bin/chmod guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=6dfa74a6-1900-0000-3a7d-bfa66e100000 pid=4206 execve guuid=32beb7a6-1900-0000-3a7d-bfa672100000 pid=4210 /usr/bin/bash guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=32beb7a6-1900-0000-3a7d-bfa672100000 pid=4210 clone guuid=7b26cba6-1900-0000-3a7d-bfa673100000 pid=4211 /usr/bin/rm delete-file guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=7b26cba6-1900-0000-3a7d-bfa673100000 pid=4211 execve guuid=81a906a7-1900-0000-3a7d-bfa677100000 pid=4215 /usr/bin/wget net send-data write-file guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=81a906a7-1900-0000-3a7d-bfa677100000 pid=4215 execve guuid=bdc574ac-1900-0000-3a7d-bfa68e100000 pid=4238 /usr/bin/chmod guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=bdc574ac-1900-0000-3a7d-bfa68e100000 pid=4238 execve guuid=f20bb3ac-1900-0000-3a7d-bfa692100000 pid=4242 /usr/bin/bash guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=f20bb3ac-1900-0000-3a7d-bfa692100000 pid=4242 clone guuid=073b75ad-1900-0000-3a7d-bfa697100000 pid=4247 /usr/bin/rm delete-file guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=073b75ad-1900-0000-3a7d-bfa697100000 pid=4247 execve guuid=dd05b7ad-1900-0000-3a7d-bfa699100000 pid=4249 /usr/bin/wget net send-data write-file guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=dd05b7ad-1900-0000-3a7d-bfa699100000 pid=4249 execve guuid=5f1957b3-1900-0000-3a7d-bfa6af100000 pid=4271 /usr/bin/chmod guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=5f1957b3-1900-0000-3a7d-bfa6af100000 pid=4271 execve guuid=ad20b1b3-1900-0000-3a7d-bfa6b1100000 pid=4273 /tmp/getty net guuid=a1915877-1900-0000-3a7d-bfa6c00f0000 pid=4032->guuid=ad20b1b3-1900-0000-3a7d-bfa6b1100000 pid=4273 execve fa5e6e18-6423-542e-b688-04184acfc2bd 78.142.229.12:80 guuid=c622b677-1900-0000-3a7d-bfa6c20f0000 pid=4034->fa5e6e18-6423-542e-b688-04184acfc2bd send: 132B guuid=3bc16081-1900-0000-3a7d-bfa6e40f0000 pid=4068->fa5e6e18-6423-542e-b688-04184acfc2bd send: 135B guuid=7ae8e28c-1900-0000-3a7d-bfa603100000 pid=4099->fa5e6e18-6423-542e-b688-04184acfc2bd send: 134B guuid=bd042894-1900-0000-3a7d-bfa61d100000 pid=4125->fa5e6e18-6423-542e-b688-04184acfc2bd send: 131B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=90a5989a-1900-0000-3a7d-bfa63a100000 pid=4154->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=cc8ee79a-1900-0000-3a7d-bfa63b100000 pid=4155 /tmp/ssh write-file zombie guuid=90a5989a-1900-0000-3a7d-bfa63a100000 pid=4154->guuid=cc8ee79a-1900-0000-3a7d-bfa63b100000 pid=4155 clone guuid=9edbef9a-1900-0000-3a7d-bfa63c100000 pid=4156 /tmp/ssh guuid=90a5989a-1900-0000-3a7d-bfa63a100000 pid=4154->guuid=9edbef9a-1900-0000-3a7d-bfa63c100000 pid=4156 clone guuid=d2f6f39a-1900-0000-3a7d-bfa63d100000 pid=4157 /tmp/ssh guuid=90a5989a-1900-0000-3a7d-bfa63a100000 pid=4154->guuid=d2f6f39a-1900-0000-3a7d-bfa63d100000 pid=4157 clone guuid=357b389b-1900-0000-3a7d-bfa641100000 pid=4161 /usr/bin/dash guuid=cc8ee79a-1900-0000-3a7d-bfa63b100000 pid=4155->guuid=357b389b-1900-0000-3a7d-bfa641100000 pid=4161 execve guuid=2c26f89f-1900-0000-3a7d-bfa652100000 pid=4178 /usr/bin/dash guuid=cc8ee79a-1900-0000-3a7d-bfa63b100000 pid=4155->guuid=2c26f89f-1900-0000-3a7d-bfa652100000 pid=4178 execve guuid=310e83a1-1900-0000-3a7d-bfa654100000 pid=4180 /usr/bin/dash guuid=cc8ee79a-1900-0000-3a7d-bfa63b100000 pid=4155->guuid=310e83a1-1900-0000-3a7d-bfa654100000 pid=4180 execve guuid=cef7aba2-1900-0000-3a7d-bfa659100000 pid=4185 /usr/bin/dash guuid=cc8ee79a-1900-0000-3a7d-bfa63b100000 pid=4155->guuid=cef7aba2-1900-0000-3a7d-bfa659100000 pid=4185 execve guuid=048d98a3-1900-0000-3a7d-bfa660100000 pid=4192 /usr/bin/dash guuid=cc8ee79a-1900-0000-3a7d-bfa63b100000 pid=4155->guuid=048d98a3-1900-0000-3a7d-bfa660100000 pid=4192 execve guuid=b1f88da4-1900-0000-3a7d-bfa662100000 pid=4194 /usr/bin/dash guuid=cc8ee79a-1900-0000-3a7d-bfa63b100000 pid=4155->guuid=b1f88da4-1900-0000-3a7d-bfa662100000 pid=4194 execve guuid=9ee08ba5-1900-0000-3a7d-bfa667100000 pid=4199 /usr/bin/dash guuid=cc8ee79a-1900-0000-3a7d-bfa63b100000 pid=4155->guuid=9ee08ba5-1900-0000-3a7d-bfa667100000 pid=4199 execve guuid=1ce772a6-1900-0000-3a7d-bfa66d100000 pid=4205 /usr/bin/dash guuid=cc8ee79a-1900-0000-3a7d-bfa63b100000 pid=4155->guuid=1ce772a6-1900-0000-3a7d-bfa66d100000 pid=4205 execve guuid=4bf9fa9a-1900-0000-3a7d-bfa63e100000 pid=4158 /tmp/ssh net send-data zombie guuid=d2f6f39a-1900-0000-3a7d-bfa63d100000 pid=4157->guuid=4bf9fa9a-1900-0000-3a7d-bfa63e100000 pid=4158 clone 6f711740-a9cc-5716-b8b7-a732833df8c0 176.65.139.133:65481 guuid=4bf9fa9a-1900-0000-3a7d-bfa63e100000 pid=4158->6f711740-a9cc-5716-b8b7-a732833df8c0 send: 9B guuid=0dc6829b-1900-0000-3a7d-bfa644100000 pid=4164 /usr/bin/pgrep guuid=357b389b-1900-0000-3a7d-bfa641100000 pid=4161->guuid=0dc6829b-1900-0000-3a7d-bfa644100000 pid=4164 execve guuid=90bf7a9b-1900-0000-3a7d-bfa643100000 pid=4163->fa5e6e18-6423-542e-b688-04184acfc2bd send: 139B guuid=735c75a0-1900-0000-3a7d-bfa653100000 pid=4179 /usr/bin/killall guuid=2c26f89f-1900-0000-3a7d-bfa652100000 pid=4178->guuid=735c75a0-1900-0000-3a7d-bfa653100000 pid=4179 execve guuid=b540b2a1-1900-0000-3a7d-bfa655100000 pid=4181 /usr/bin/killall guuid=310e83a1-1900-0000-3a7d-bfa654100000 pid=4180->guuid=b540b2a1-1900-0000-3a7d-bfa655100000 pid=4181 execve guuid=bcb7d8a2-1900-0000-3a7d-bfa65b100000 pid=4187 /usr/bin/killall guuid=cef7aba2-1900-0000-3a7d-bfa659100000 pid=4185->guuid=bcb7d8a2-1900-0000-3a7d-bfa65b100000 pid=4187 execve guuid=d1fd21a3-1900-0000-3a7d-bfa65c100000 pid=4188->fa5e6e18-6423-542e-b688-04184acfc2bd send: 132B guuid=a61ac7a3-1900-0000-3a7d-bfa661100000 pid=4193 /usr/bin/killall guuid=048d98a3-1900-0000-3a7d-bfa660100000 pid=4192->guuid=a61ac7a3-1900-0000-3a7d-bfa661100000 pid=4193 execve guuid=58b7bfa4-1900-0000-3a7d-bfa663100000 pid=4195 /usr/bin/killall guuid=b1f88da4-1900-0000-3a7d-bfa662100000 pid=4194->guuid=58b7bfa4-1900-0000-3a7d-bfa663100000 pid=4195 execve guuid=2eeab6a5-1900-0000-3a7d-bfa66b100000 pid=4203 /usr/bin/killall guuid=9ee08ba5-1900-0000-3a7d-bfa667100000 pid=4199->guuid=2eeab6a5-1900-0000-3a7d-bfa66b100000 pid=4203 execve guuid=81079aa6-1900-0000-3a7d-bfa671100000 pid=4209 /usr/bin/killall guuid=1ce772a6-1900-0000-3a7d-bfa66d100000 pid=4205->guuid=81079aa6-1900-0000-3a7d-bfa671100000 pid=4209 execve guuid=81a906a7-1900-0000-3a7d-bfa677100000 pid=4215->fa5e6e18-6423-542e-b688-04184acfc2bd send: 136B guuid=dd05b7ad-1900-0000-3a7d-bfa699100000 pid=4249->fa5e6e18-6423-542e-b688-04184acfc2bd send: 133B 51a46072-ca05-5ef4-a6ba-28d0e14febf8 0.0.0.0:65480 guuid=ad20b1b3-1900-0000-3a7d-bfa6b1100000 pid=4273->51a46072-ca05-5ef4-a6ba-28d0e14febf8 con
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-10-07 22:37:47 UTC
File Type:
Text (Shell)
AV detection:
25 of 38 (65.79%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt antivm botnet defense_evasion discovery linux
Behaviour
Writes file to tmp directory
Reads runtime system information
Changes its process name
Checks CPU configuration
Reads CPU attributes
Reads system network configuration
Enumerates running processes
Reads system routing table
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Writes memory of remote process
Detected Gafgyt variant
Gafgyt family
Gafgyt/Bashlite
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 9d58c8da57d83083136f5bf2ca519d11bc3a503d643835fc515920958993cd9c

(this sample)

  
Delivery method
Distributed via web download

Comments