MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b45fbe5be5f75a665aa0501ac1b0d35da9b61e263a2898630ccf8affe5796d1b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: b45fbe5be5f75a665aa0501ac1b0d35da9b61e263a2898630ccf8affe5796d1b
SHA3-384 hash: 0b4535a72322bf264b195f1b3c8a7814ef52af7f6d3cd3b1a7e9721bb1c75ac28a4f93695be4073cbd2edf54ca98b080
SHA1 hash: c49557a716708090f5eef42e2b77e6b750b15c63
MD5 hash: 3a0e9738f47dc7db04e26851c9fa4569
humanhash: cardinal-freddie-solar-helium
File name:l
Download: download sample
Signature Gafgyt
File size:855 bytes
First seen:2025-04-27 18:32:15 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:QvQ53GFyZouqpY4p76sRqSsRqK2yqWyqH:QvQeuqpY4p76MqSMqKNqWyqH
TLSH T1C0118EF39908B9F0F6D6A06A76B78B99EDA590C71E070810EE7CC279DCACC14A454F80
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.148.37/msps7a2f1eaa22364619718c27b04a5ed545bdaa88cd3bc7e99676b2b618156ff698 Gafgytgafgyt
http://176.65.148.37/msslebc2000a12388d0c0037636eeca63affb1240414787786bfc27244b6027cb6af Gafgytgafgyt

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.9%
Tags:
trojan mirai agent virus
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2025-04-27 19:24:58 UTC
File Type:
Text (Shell)
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh b45fbe5be5f75a665aa0501ac1b0d35da9b61e263a2898630ccf8affe5796d1b

(this sample)

  
Delivery method
Distributed via web download

Comments