MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b5eec555aa0e07b1af33a0ec195a3fb195e1543339d22305fffbfa7e6a7b4381. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: b5eec555aa0e07b1af33a0ec195a3fb195e1543339d22305fffbfa7e6a7b4381
SHA3-384 hash: 9ab7ca39a96acb42c59eadbd0e33bcbe6a357ca8cac3603f7b5535366e99de0e1d08d0dddc8bd307ffedfaf598a75e1d
SHA1 hash: ed46c62595dfe74fb43def201f347aabcf4b5620
MD5 hash: ea4e85e35d0a051c1b7e317111e082d0
humanhash: tango-butter-thirteen-georgia
File name:Sakura.sh
Download: download sample
Signature Gafgyt
File size:2'111 bytes
First seen:2026-06-05 11:05:23 UTC
Last seen:2026-06-07 18:44:59 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vp/d8jpCttQdMppYpyRpm7pDT6pnCpJIpAL1pC5NpJIpwxpZT:v9d8jsttQdMbYkR47RT6BCzIGBs5NzIe
TLSH T13B412BD710924BF36CA5D83732798480B5D1919694CA6F0AAEDC3CE58CBFDECA844786
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter BlinkzSec
Tags:gafgyt
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139.151/m-i.p-s.Sakurae66bf0e1b28c66db32a286a64ee6b2ed5927d9a8409ed0ceefb65d8f54c8ebd1 Miraielf ua-wget
http://176.65.139.151/m-p.s-l.Sakuraa77fbe4323b4ea439a6ee5de75f779da6a15e9085e9f78bb8931718d2ca25af5 Gafgytelf ua-wget
http://176.65.139.151/s-h.4-.Sakuran/an/aelf ua-wget
http://176.65.139.151/x-8.6-.Sakura81755282bb9bd9bf3fa1028531dff49a7d5b2c6535e800e24b727411492dd34e Miraielf ua-wget
http://176.65.139.151/a-r.m-6.Sakura3ea9e6978f6b9e79669f6eb35009c19069068be28f49910e59dd7bf0e26a35f9 Gafgytelf ua-wget
http://176.65.139.151/x-3.2-.Sakuran/an/aelf ua-wget
http://176.65.139.151/a-r.m-7.Sakuraf0102d8f4a3a7ba6e1bbbfa7657a14058aa5a1bf855a08a775e458ce5cf1a4f7 Gafgytelf ua-wget
http://176.65.139.151/p-p.c-.Sakuran/an/aelf ua-wget
http://176.65.139.151/i-5.8-6.Sakura02c40d22521d34af2844b7ca15fa213cd27787423573a408a71fb445c91f9a1c Miraielf ua-wget
http://176.65.139.151/m-6.8-k.Sakurae58aa90b2033031f393276706e63d83cd42764263a8e004eda380ba19377f55d Gafgytelf ua-wget
http://176.65.139.151/a-r.m-4.Sakuran/an/aelf ua-wget
http://176.65.139.151/a-r.m-5.Sakuran/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
4
# of downloads :
57
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-05T08:13:00Z UTC
Last seen:
2026-06-07T08:17:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=3e6c8a74-1a00-0000-b852-9f93aa0a0000 pid=2730 /usr/bin/sudo guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733 /tmp/sample.bin guuid=3e6c8a74-1a00-0000-b852-9f93aa0a0000 pid=2730->guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733 execve guuid=86d6c277-1a00-0000-b852-9f93ae0a0000 pid=2734 /usr/bin/wget net send-data write-file guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=86d6c277-1a00-0000-b852-9f93ae0a0000 pid=2734 execve guuid=36566394-1a00-0000-b852-9f93d70a0000 pid=2775 /usr/bin/chmod guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=36566394-1a00-0000-b852-9f93d70a0000 pid=2775 execve guuid=0288f594-1a00-0000-b852-9f93d80a0000 pid=2776 /usr/bin/bash guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=0288f594-1a00-0000-b852-9f93d80a0000 pid=2776 clone guuid=95733696-1a00-0000-b852-9f93da0a0000 pid=2778 /usr/bin/rm delete-file guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=95733696-1a00-0000-b852-9f93da0a0000 pid=2778 execve guuid=6c91d196-1a00-0000-b852-9f93db0a0000 pid=2779 /usr/bin/wget net send-data write-file guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=6c91d196-1a00-0000-b852-9f93db0a0000 pid=2779 execve guuid=6268f59d-1a00-0000-b852-9f93eb0a0000 pid=2795 /usr/bin/chmod guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=6268f59d-1a00-0000-b852-9f93eb0a0000 pid=2795 execve guuid=213f4c9e-1a00-0000-b852-9f93ee0a0000 pid=2798 /usr/bin/bash guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=213f4c9e-1a00-0000-b852-9f93ee0a0000 pid=2798 clone guuid=f4dff99e-1a00-0000-b852-9f93f10a0000 pid=2801 /usr/bin/rm delete-file guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=f4dff99e-1a00-0000-b852-9f93f10a0000 pid=2801 execve guuid=4b314e9f-1a00-0000-b852-9f93f30a0000 pid=2803 /usr/bin/wget net send-data guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=4b314e9f-1a00-0000-b852-9f93f30a0000 pid=2803 execve guuid=58cdefa6-1a00-0000-b852-9f93fe0a0000 pid=2814 /usr/bin/chmod guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=58cdefa6-1a00-0000-b852-9f93fe0a0000 pid=2814 execve guuid=d64e6ca7-1a00-0000-b852-9f93000b0000 pid=2816 /usr/bin/bash guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=d64e6ca7-1a00-0000-b852-9f93000b0000 pid=2816 clone guuid=7cbe83a7-1a00-0000-b852-9f93010b0000 pid=2817 /usr/bin/rm guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=7cbe83a7-1a00-0000-b852-9f93010b0000 pid=2817 execve guuid=cef1d5a7-1a00-0000-b852-9f93030b0000 pid=2819 /usr/bin/wget net send-data write-file guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=cef1d5a7-1a00-0000-b852-9f93030b0000 pid=2819 execve guuid=c2f15ab3-1a00-0000-b852-9f93220b0000 pid=2850 /usr/bin/chmod guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=c2f15ab3-1a00-0000-b852-9f93220b0000 pid=2850 execve guuid=29a1a0b3-1a00-0000-b852-9f93230b0000 pid=2851 /tmp/x-8.6-.Sakura net guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=29a1a0b3-1a00-0000-b852-9f93230b0000 pid=2851 execve guuid=25cdd9b3-1a00-0000-b852-9f93270b0000 pid=2855 /usr/bin/rm delete-file guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=25cdd9b3-1a00-0000-b852-9f93270b0000 pid=2855 execve guuid=4f2a2bb4-1a00-0000-b852-9f93280b0000 pid=2856 /usr/bin/wget net send-data write-file guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=4f2a2bb4-1a00-0000-b852-9f93280b0000 pid=2856 execve guuid=75da20bb-1a00-0000-b852-9f93370b0000 pid=2871 /usr/bin/chmod guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=75da20bb-1a00-0000-b852-9f93370b0000 pid=2871 execve guuid=8b7472bb-1a00-0000-b852-9f93390b0000 pid=2873 /usr/bin/bash guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=8b7472bb-1a00-0000-b852-9f93390b0000 pid=2873 clone guuid=a22507bc-1a00-0000-b852-9f933d0b0000 pid=2877 /usr/bin/rm delete-file guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=a22507bc-1a00-0000-b852-9f933d0b0000 pid=2877 execve guuid=c1f082bc-1a00-0000-b852-9f933f0b0000 pid=2879 /usr/bin/wget net send-data guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=c1f082bc-1a00-0000-b852-9f933f0b0000 pid=2879 execve guuid=5fa6aec4-1a00-0000-b852-9f93510b0000 pid=2897 /usr/bin/chmod guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=5fa6aec4-1a00-0000-b852-9f93510b0000 pid=2897 execve guuid=b56c0ec5-1a00-0000-b852-9f93530b0000 pid=2899 /usr/bin/bash guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=b56c0ec5-1a00-0000-b852-9f93530b0000 pid=2899 clone guuid=817829c5-1a00-0000-b852-9f93540b0000 pid=2900 /usr/bin/rm guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=817829c5-1a00-0000-b852-9f93540b0000 pid=2900 execve guuid=7071c8c5-1a00-0000-b852-9f93550b0000 pid=2901 /usr/bin/wget net send-data write-file guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=7071c8c5-1a00-0000-b852-9f93550b0000 pid=2901 execve guuid=d2b226ce-1a00-0000-b852-9f935c0b0000 pid=2908 /usr/bin/chmod guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=d2b226ce-1a00-0000-b852-9f935c0b0000 pid=2908 execve guuid=a4c772ce-1a00-0000-b852-9f935e0b0000 pid=2910 /usr/bin/bash guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=a4c772ce-1a00-0000-b852-9f935e0b0000 pid=2910 clone guuid=c83c55cf-1a00-0000-b852-9f93600b0000 pid=2912 /usr/bin/rm delete-file guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=c83c55cf-1a00-0000-b852-9f93600b0000 pid=2912 execve guuid=b590c4cf-1a00-0000-b852-9f93610b0000 pid=2913 /usr/bin/wget net send-data write-file guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=b590c4cf-1a00-0000-b852-9f93610b0000 pid=2913 execve guuid=f941801a-1b00-0000-b852-9f930e0c0000 pid=3086 /usr/bin/chmod guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=f941801a-1b00-0000-b852-9f930e0c0000 pid=3086 execve guuid=8f8deb1a-1b00-0000-b852-9f93100c0000 pid=3088 /tmp/p-p.c-.Sakura net guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=8f8deb1a-1b00-0000-b852-9f93100c0000 pid=3088 execve guuid=0cc5651c-1b00-0000-b852-9f93170c0000 pid=3095 /usr/bin/rm delete-file guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=0cc5651c-1b00-0000-b852-9f93170c0000 pid=3095 execve guuid=0ff5af1c-1b00-0000-b852-9f93180c0000 pid=3096 /usr/bin/wget net send-data write-file guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=0ff5af1c-1b00-0000-b852-9f93180c0000 pid=3096 execve guuid=9f483c2a-1b00-0000-b852-9f93320c0000 pid=3122 /usr/bin/chmod guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=9f483c2a-1b00-0000-b852-9f93320c0000 pid=3122 execve guuid=d78aa62a-1b00-0000-b852-9f93340c0000 pid=3124 /usr/bin/bash guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=d78aa62a-1b00-0000-b852-9f93340c0000 pid=3124 clone guuid=58807a2b-1b00-0000-b852-9f93380c0000 pid=3128 /usr/bin/rm delete-file guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=58807a2b-1b00-0000-b852-9f93380c0000 pid=3128 execve guuid=f903e92b-1b00-0000-b852-9f933a0c0000 pid=3130 /usr/bin/wget net send-data write-file guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=f903e92b-1b00-0000-b852-9f933a0c0000 pid=3130 execve guuid=288a5339-1b00-0000-b852-9f93540c0000 pid=3156 /usr/bin/chmod guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=288a5339-1b00-0000-b852-9f93540c0000 pid=3156 execve guuid=031aa439-1b00-0000-b852-9f93560c0000 pid=3158 /usr/bin/bash guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=031aa439-1b00-0000-b852-9f93560c0000 pid=3158 clone guuid=66256b3a-1b00-0000-b852-9f935a0c0000 pid=3162 /usr/bin/rm delete-file guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=66256b3a-1b00-0000-b852-9f935a0c0000 pid=3162 execve guuid=0a58f63a-1b00-0000-b852-9f935c0c0000 pid=3164 /usr/bin/wget net send-data write-file guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=0a58f63a-1b00-0000-b852-9f935c0c0000 pid=3164 execve guuid=8b8db440-1b00-0000-b852-9f93660c0000 pid=3174 /usr/bin/chmod guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=8b8db440-1b00-0000-b852-9f93660c0000 pid=3174 execve guuid=3f810841-1b00-0000-b852-9f93670c0000 pid=3175 /tmp/p-p.c-.Sakura net guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=3f810841-1b00-0000-b852-9f93670c0000 pid=3175 execve guuid=74914e42-1b00-0000-b852-9f936d0c0000 pid=3181 /usr/bin/rm delete-file guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=74914e42-1b00-0000-b852-9f936d0c0000 pid=3181 execve guuid=537fa942-1b00-0000-b852-9f936f0c0000 pid=3183 /usr/bin/wget net send-data guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=537fa942-1b00-0000-b852-9f936f0c0000 pid=3183 execve guuid=073ba44a-1b00-0000-b852-9f93720c0000 pid=3186 /usr/bin/chmod guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=073ba44a-1b00-0000-b852-9f93720c0000 pid=3186 execve guuid=e289f64a-1b00-0000-b852-9f93730c0000 pid=3187 /usr/bin/bash guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=e289f64a-1b00-0000-b852-9f93730c0000 pid=3187 clone guuid=7a200b4b-1b00-0000-b852-9f93740c0000 pid=3188 /usr/bin/rm guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=7a200b4b-1b00-0000-b852-9f93740c0000 pid=3188 execve guuid=3a7e704b-1b00-0000-b852-9f93750c0000 pid=3189 /usr/bin/wget net send-data guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=3a7e704b-1b00-0000-b852-9f93750c0000 pid=3189 execve guuid=bfd1764f-1b00-0000-b852-9f93760c0000 pid=3190 /usr/bin/chmod guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=bfd1764f-1b00-0000-b852-9f93760c0000 pid=3190 execve guuid=6a59ee4f-1b00-0000-b852-9f93770c0000 pid=3191 /usr/bin/bash guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=6a59ee4f-1b00-0000-b852-9f93770c0000 pid=3191 clone guuid=60a01350-1b00-0000-b852-9f93780c0000 pid=3192 /usr/bin/rm guuid=39de3177-1a00-0000-b852-9f93ad0a0000 pid=2733->guuid=60a01350-1b00-0000-b852-9f93780c0000 pid=3192 execve d8573c2f-cf90-5a27-9fe5-e4e7b2e399e8 176.65.139.151:80 guuid=86d6c277-1a00-0000-b852-9f93ae0a0000 pid=2734->d8573c2f-cf90-5a27-9fe5-e4e7b2e399e8 send: 143B guuid=6c91d196-1a00-0000-b852-9f93db0a0000 pid=2779->d8573c2f-cf90-5a27-9fe5-e4e7b2e399e8 send: 143B guuid=4b314e9f-1a00-0000-b852-9f93f30a0000 pid=2803->d8573c2f-cf90-5a27-9fe5-e4e7b2e399e8 send: 142B guuid=cef1d5a7-1a00-0000-b852-9f93030b0000 pid=2819->d8573c2f-cf90-5a27-9fe5-e4e7b2e399e8 send: 142B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=29a1a0b3-1a00-0000-b852-9f93230b0000 pid=2851->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6e2ec3b3-1a00-0000-b852-9f93240b0000 pid=2852 /tmp/x-8.6-.Sakura guuid=29a1a0b3-1a00-0000-b852-9f93230b0000 pid=2851->guuid=6e2ec3b3-1a00-0000-b852-9f93240b0000 pid=2852 clone guuid=a969c8b3-1a00-0000-b852-9f93250b0000 pid=2853 /tmp/x-8.6-.Sakura net send-data zombie guuid=6e2ec3b3-1a00-0000-b852-9f93240b0000 pid=2852->guuid=a969c8b3-1a00-0000-b852-9f93250b0000 pid=2853 clone a0238b33-7601-588a-bba9-974ab4ab49a6 176.65.139.151:12345 guuid=a969c8b3-1a00-0000-b852-9f93250b0000 pid=2853->a0238b33-7601-588a-bba9-974ab4ab49a6 send: 65B guuid=4f2a2bb4-1a00-0000-b852-9f93280b0000 pid=2856->d8573c2f-cf90-5a27-9fe5-e4e7b2e399e8 send: 143B guuid=c1f082bc-1a00-0000-b852-9f933f0b0000 pid=2879->d8573c2f-cf90-5a27-9fe5-e4e7b2e399e8 send: 142B guuid=7071c8c5-1a00-0000-b852-9f93550b0000 pid=2901->d8573c2f-cf90-5a27-9fe5-e4e7b2e399e8 send: 143B guuid=b590c4cf-1a00-0000-b852-9f93610b0000 pid=2913->d8573c2f-cf90-5a27-9fe5-e4e7b2e399e8 send: 142B guuid=8f8deb1a-1b00-0000-b852-9f93100c0000 pid=3088->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3370461c-1b00-0000-b852-9f93140c0000 pid=3092 /tmp/p-p.c-.Sakura guuid=8f8deb1a-1b00-0000-b852-9f93100c0000 pid=3088->guuid=3370461c-1b00-0000-b852-9f93140c0000 pid=3092 clone guuid=8fbb521c-1b00-0000-b852-9f93150c0000 pid=3093 /tmp/p-p.c-.Sakura net send-data zombie guuid=3370461c-1b00-0000-b852-9f93140c0000 pid=3092->guuid=8fbb521c-1b00-0000-b852-9f93150c0000 pid=3093 clone guuid=8fbb521c-1b00-0000-b852-9f93150c0000 pid=3093->a0238b33-7601-588a-bba9-974ab4ab49a6 send: 48490B guuid=0ff5af1c-1b00-0000-b852-9f93180c0000 pid=3096->d8573c2f-cf90-5a27-9fe5-e4e7b2e399e8 send: 143B guuid=f903e92b-1b00-0000-b852-9f933a0c0000 pid=3130->d8573c2f-cf90-5a27-9fe5-e4e7b2e399e8 send: 143B guuid=0a58f63a-1b00-0000-b852-9f935c0c0000 pid=3164->d8573c2f-cf90-5a27-9fe5-e4e7b2e399e8 send: 142B guuid=3f810841-1b00-0000-b852-9f93670c0000 pid=3175->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2ca93342-1b00-0000-b852-9f936b0c0000 pid=3179 /tmp/p-p.c-.Sakura guuid=3f810841-1b00-0000-b852-9f93670c0000 pid=3175->guuid=2ca93342-1b00-0000-b852-9f936b0c0000 pid=3179 clone guuid=e4563b42-1b00-0000-b852-9f936c0c0000 pid=3180 /tmp/p-p.c-.Sakura net send-data zombie guuid=2ca93342-1b00-0000-b852-9f936b0c0000 pid=3179->guuid=e4563b42-1b00-0000-b852-9f936c0c0000 pid=3180 clone guuid=e4563b42-1b00-0000-b852-9f936c0c0000 pid=3180->a0238b33-7601-588a-bba9-974ab4ab49a6 send: 56550B guuid=537fa942-1b00-0000-b852-9f936f0c0000 pid=3183->d8573c2f-cf90-5a27-9fe5-e4e7b2e399e8 send: 143B guuid=3a7e704b-1b00-0000-b852-9f93750c0000 pid=3189->d8573c2f-cf90-5a27-9fe5-e4e7b2e399e8 send: 143B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2026-06-05 11:04:33 UTC
File Type:
Text (Shell)
AV detection:
17 of 24 (70.83%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt botnet defense_evasion discovery linux
Behaviour
Writes file to tmp directory
Reads system network configuration
Reads system routing table
File and Directory Permissions Modification
Executes dropped EXE
Detected Gafgyt variant
Family: Gafgyt/Bashlite
Malware Config
C2 Extraction:
176.65.139.151:12345
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh b5eec555aa0e07b1af33a0ec195a3fb195e1543339d22305fffbfa7e6a7b4381

(this sample)

  
Delivery method
Distributed via web download

Comments