MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aeb615f18972cbd4bf1bf0ba337c2918a062714f5f504728f06cfd04d83e01fe. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: aeb615f18972cbd4bf1bf0ba337c2918a062714f5f504728f06cfd04d83e01fe
SHA3-384 hash: c4d27939e4fa173c4d7553a41897fe4bc6a8431cf19e84d09bde2a6267ee6fbc69c56d909ffa97384fd37117e862897b
SHA1 hash: 5131c6f1011364598f244c3f06e08019c4f97ea4
MD5 hash: b62f866e8bf28907aec43a72dcf78b86
humanhash: blue-mockingbird-nineteen-london
File name:buf
Download: download sample
Signature Gafgyt
File size:196 bytes
First seen:2025-03-11 08:46:38 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 3:LWwhRFWl009GBzSE8KT1yYdDnDWwhRFWl0tWTBzSE8VDQZxXIdDv:LWl00kbT1yYBnDWl0wKMXXIBv
TLSH T119D0C7694CA57E60C048BDBD3A674F1F504843CD259B0B4C58D500A6E48AA52F94E904
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://185.142.53.43/mipsa6e6162e308e8d0c1c076657166e45c34f692030fd3078bf74e04d1bc1a61f2f Gafgyt32-bit elf gafgyt
http://185.142.53.43/mpslf6156dc0fd65261579373182072bb820b6e26ca0f1c06cb9e4da0b04e0fdf913 Gafgytelf gafgyt ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Result
Verdict:
UNKNOWN
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh aeb615f18972cbd4bf1bf0ba337c2918a062714f5f504728f06cfd04d83e01fe

(this sample)

  
Delivery method
Distributed via web download

Comments