MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bf48e8b383f1a1e5bf9d411419edaa35f3e5cba6375857d000a1888d3e4d6bae. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 6


Intelligence 6 IOCs YARA 3 File information Comments

SHA256 hash: bf48e8b383f1a1e5bf9d411419edaa35f3e5cba6375857d000a1888d3e4d6bae
SHA3-384 hash: a7c65a073d07fa88406e64127a403331b5459889c078f04a792becab25f651735363aefd5c0d663133f2ea6cd4e049b5
SHA1 hash: 13dbf6bd0fe0fcef98476e2cdbf14ad4f20db9aa
MD5 hash: fb68acf34b290751bcbfdb9c4e8040ef
humanhash: nevada-burger-moon-batman
File name:bins.sh
Download: download sample
Signature Gafgyt
File size:2'288 bytes
First seen:2026-01-20 14:49:58 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:v+bb0hE+boJdel+sk+PP+xLJ+Pb+L+xd+bUNuV+0MJ+f+HL+Y2+oH0oX:vS+9keWSCeOjWOQL72fH06
TLSH T12E41AE85A0A159B02EA4E8DF72694C8472C0D0D67CCA6FF41DFCB8E409ADE9478257C6
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:gafgyt sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
24
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=ccb761fa-1900-0000-893c-62b84b0c0000 pid=3147 /usr/bin/sudo guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155 /tmp/sample.bin guuid=ccb761fa-1900-0000-893c-62b84b0c0000 pid=3147->guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155 execve guuid=c3850ffe-1900-0000-893c-62b8540c0000 pid=3156 /usr/bin/wget net send-data write-file guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=c3850ffe-1900-0000-893c-62b8540c0000 pid=3156 execve guuid=e45d1a0f-1a00-0000-893c-62b8690c0000 pid=3177 /usr/bin/chmod guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=e45d1a0f-1a00-0000-893c-62b8690c0000 pid=3177 execve guuid=57552510-1a00-0000-893c-62b86a0c0000 pid=3178 /usr/bin/bash guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=57552510-1a00-0000-893c-62b86a0c0000 pid=3178 clone guuid=19845311-1a00-0000-893c-62b86c0c0000 pid=3180 /usr/bin/rm delete-file guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=19845311-1a00-0000-893c-62b86c0c0000 pid=3180 execve guuid=6494da11-1a00-0000-893c-62b86d0c0000 pid=3181 /usr/bin/wget net send-data write-file guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=6494da11-1a00-0000-893c-62b86d0c0000 pid=3181 execve guuid=fa672321-1a00-0000-893c-62b8780c0000 pid=3192 /usr/bin/chmod guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=fa672321-1a00-0000-893c-62b8780c0000 pid=3192 execve guuid=40d8c421-1a00-0000-893c-62b87a0c0000 pid=3194 /usr/bin/bash guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=40d8c421-1a00-0000-893c-62b87a0c0000 pid=3194 clone guuid=e1506022-1a00-0000-893c-62b87e0c0000 pid=3198 /usr/bin/rm delete-file guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=e1506022-1a00-0000-893c-62b87e0c0000 pid=3198 execve guuid=48faaa22-1a00-0000-893c-62b8800c0000 pid=3200 /usr/bin/wget net send-data write-file guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=48faaa22-1a00-0000-893c-62b8800c0000 pid=3200 execve guuid=667ff730-1a00-0000-893c-62b8970c0000 pid=3223 /usr/bin/chmod guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=667ff730-1a00-0000-893c-62b8970c0000 pid=3223 execve guuid=b58ae731-1a00-0000-893c-62b8980c0000 pid=3224 /usr/bin/bash guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=b58ae731-1a00-0000-893c-62b8980c0000 pid=3224 clone guuid=2ed6fe32-1a00-0000-893c-62b89a0c0000 pid=3226 /usr/bin/rm delete-file guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=2ed6fe32-1a00-0000-893c-62b89a0c0000 pid=3226 execve guuid=e9752534-1a00-0000-893c-62b89b0c0000 pid=3227 /usr/bin/wget net send-data write-file guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=e9752534-1a00-0000-893c-62b89b0c0000 pid=3227 execve guuid=f0a55444-1a00-0000-893c-62b8a80c0000 pid=3240 /usr/bin/chmod guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=f0a55444-1a00-0000-893c-62b8a80c0000 pid=3240 execve guuid=8480d144-1a00-0000-893c-62b8aa0c0000 pid=3242 /tmp/assailant.x86 guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=8480d144-1a00-0000-893c-62b8aa0c0000 pid=3242 execve guuid=12d71745-1a00-0000-893c-62b8af0c0000 pid=3247 /usr/bin/rm delete-file guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=12d71745-1a00-0000-893c-62b8af0c0000 pid=3247 execve guuid=a98ceb45-1a00-0000-893c-62b8b10c0000 pid=3249 /usr/bin/wget net send-data write-file guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=a98ceb45-1a00-0000-893c-62b8b10c0000 pid=3249 execve guuid=4f85a654-1a00-0000-893c-62b8c40c0000 pid=3268 /usr/bin/chmod guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=4f85a654-1a00-0000-893c-62b8c40c0000 pid=3268 execve guuid=7b8df954-1a00-0000-893c-62b8c50c0000 pid=3269 /usr/bin/bash guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=7b8df954-1a00-0000-893c-62b8c50c0000 pid=3269 clone guuid=87fae155-1a00-0000-893c-62b8c90c0000 pid=3273 /usr/bin/rm delete-file guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=87fae155-1a00-0000-893c-62b8c90c0000 pid=3273 execve guuid=f51f5756-1a00-0000-893c-62b8cb0c0000 pid=3275 /usr/bin/wget net send-data write-file guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=f51f5756-1a00-0000-893c-62b8cb0c0000 pid=3275 execve guuid=f836e465-1a00-0000-893c-62b8e00c0000 pid=3296 /usr/bin/chmod guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=f836e465-1a00-0000-893c-62b8e00c0000 pid=3296 execve guuid=d59b4d66-1a00-0000-893c-62b8e10c0000 pid=3297 /tmp/assailant.i686 guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=d59b4d66-1a00-0000-893c-62b8e10c0000 pid=3297 execve guuid=e19b9366-1a00-0000-893c-62b8e60c0000 pid=3302 /usr/bin/rm delete-file guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=e19b9366-1a00-0000-893c-62b8e60c0000 pid=3302 execve guuid=59d4e966-1a00-0000-893c-62b8e90c0000 pid=3305 /usr/bin/wget net send-data write-file guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=59d4e966-1a00-0000-893c-62b8e90c0000 pid=3305 execve guuid=2faf9d76-1a00-0000-893c-62b8070d0000 pid=3335 /usr/bin/chmod guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=2faf9d76-1a00-0000-893c-62b8070d0000 pid=3335 execve guuid=4566f776-1a00-0000-893c-62b8090d0000 pid=3337 /usr/bin/bash guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=4566f776-1a00-0000-893c-62b8090d0000 pid=3337 clone guuid=a32db277-1a00-0000-893c-62b80c0d0000 pid=3340 /usr/bin/rm delete-file guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=a32db277-1a00-0000-893c-62b80c0d0000 pid=3340 execve guuid=40adac78-1a00-0000-893c-62b80d0d0000 pid=3341 /usr/bin/wget net send-data write-file guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=40adac78-1a00-0000-893c-62b80d0d0000 pid=3341 execve guuid=0cce6e88-1a00-0000-893c-62b8250d0000 pid=3365 /usr/bin/chmod guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=0cce6e88-1a00-0000-893c-62b8250d0000 pid=3365 execve guuid=a921db88-1a00-0000-893c-62b8270d0000 pid=3367 /tmp/assailant.i586 guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=a921db88-1a00-0000-893c-62b8270d0000 pid=3367 execve guuid=d1053089-1a00-0000-893c-62b82d0d0000 pid=3373 /usr/bin/rm delete-file guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=d1053089-1a00-0000-893c-62b82d0d0000 pid=3373 execve guuid=75528e89-1a00-0000-893c-62b82e0d0000 pid=3374 /usr/bin/wget net send-data write-file guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=75528e89-1a00-0000-893c-62b82e0d0000 pid=3374 execve guuid=8367439a-1a00-0000-893c-62b83b0d0000 pid=3387 /usr/bin/chmod guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=8367439a-1a00-0000-893c-62b83b0d0000 pid=3387 execve guuid=4381c29a-1a00-0000-893c-62b83d0d0000 pid=3389 /usr/bin/bash guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=4381c29a-1a00-0000-893c-62b83d0d0000 pid=3389 clone guuid=d1ee9e9d-1a00-0000-893c-62b8430d0000 pid=3395 /usr/bin/rm delete-file guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=d1ee9e9d-1a00-0000-893c-62b8430d0000 pid=3395 execve guuid=2cc7059e-1a00-0000-893c-62b8450d0000 pid=3397 /usr/bin/wget net send-data write-file guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=2cc7059e-1a00-0000-893c-62b8450d0000 pid=3397 execve guuid=13ffe4ac-1a00-0000-893c-62b8630d0000 pid=3427 /usr/bin/chmod guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=13ffe4ac-1a00-0000-893c-62b8630d0000 pid=3427 execve guuid=34e650ad-1a00-0000-893c-62b8650d0000 pid=3429 /usr/bin/bash guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=34e650ad-1a00-0000-893c-62b8650d0000 pid=3429 clone guuid=c21f10ae-1a00-0000-893c-62b8690d0000 pid=3433 /usr/bin/rm delete-file guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=c21f10ae-1a00-0000-893c-62b8690d0000 pid=3433 execve guuid=c0af85ae-1a00-0000-893c-62b86b0d0000 pid=3435 /usr/bin/wget net send-data write-file guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=c0af85ae-1a00-0000-893c-62b86b0d0000 pid=3435 execve guuid=b2e1bbbe-1a00-0000-893c-62b8970d0000 pid=3479 /usr/bin/chmod guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=b2e1bbbe-1a00-0000-893c-62b8970d0000 pid=3479 execve guuid=583020bf-1a00-0000-893c-62b8990d0000 pid=3481 /usr/bin/bash guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=583020bf-1a00-0000-893c-62b8990d0000 pid=3481 clone guuid=d884f4bf-1a00-0000-893c-62b89d0d0000 pid=3485 /usr/bin/rm delete-file guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=d884f4bf-1a00-0000-893c-62b89d0d0000 pid=3485 execve guuid=de1769c0-1a00-0000-893c-62b89f0d0000 pid=3487 /usr/bin/wget net send-data write-file guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=de1769c0-1a00-0000-893c-62b89f0d0000 pid=3487 execve guuid=c452a8cf-1a00-0000-893c-62b8c30d0000 pid=3523 /usr/bin/chmod guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=c452a8cf-1a00-0000-893c-62b8c30d0000 pid=3523 execve guuid=654f19d0-1a00-0000-893c-62b8c60d0000 pid=3526 /usr/bin/bash guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=654f19d0-1a00-0000-893c-62b8c60d0000 pid=3526 clone guuid=e2d2d6d1-1a00-0000-893c-62b8cc0d0000 pid=3532 /usr/bin/rm delete-file guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=e2d2d6d1-1a00-0000-893c-62b8cc0d0000 pid=3532 execve guuid=ca2844d2-1a00-0000-893c-62b8ce0d0000 pid=3534 /usr/bin/wget net send-data write-file guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=ca2844d2-1a00-0000-893c-62b8ce0d0000 pid=3534 execve guuid=f3c9c7e1-1a00-0000-893c-62b8ec0d0000 pid=3564 /usr/bin/chmod guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=f3c9c7e1-1a00-0000-893c-62b8ec0d0000 pid=3564 execve guuid=6cbd30e2-1a00-0000-893c-62b8ee0d0000 pid=3566 /usr/bin/bash guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=6cbd30e2-1a00-0000-893c-62b8ee0d0000 pid=3566 clone guuid=392d54e3-1a00-0000-893c-62b8f30d0000 pid=3571 /usr/bin/rm delete-file guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=392d54e3-1a00-0000-893c-62b8f30d0000 pid=3571 execve guuid=880ccee3-1a00-0000-893c-62b8f50d0000 pid=3573 /usr/bin/wget net send-data guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=880ccee3-1a00-0000-893c-62b8f50d0000 pid=3573 execve guuid=ea9b02ea-1a00-0000-893c-62b8ff0d0000 pid=3583 /usr/bin/chmod guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=ea9b02ea-1a00-0000-893c-62b8ff0d0000 pid=3583 execve guuid=184268ea-1a00-0000-893c-62b8000e0000 pid=3584 /usr/bin/bash guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=184268ea-1a00-0000-893c-62b8000e0000 pid=3584 clone guuid=e9aa87ea-1a00-0000-893c-62b8010e0000 pid=3585 /usr/bin/rm guuid=b42a9dfd-1900-0000-893c-62b8530c0000 pid=3155->guuid=e9aa87ea-1a00-0000-893c-62b8010e0000 pid=3585 execve 65823f49-3a0a-570e-96d7-afa68525b959 178.16.52.166:80 guuid=c3850ffe-1900-0000-893c-62b8540c0000 pid=3156->65823f49-3a0a-570e-96d7-afa68525b959 send: 142B guuid=6494da11-1a00-0000-893c-62b86d0c0000 pid=3181->65823f49-3a0a-570e-96d7-afa68525b959 send: 142B guuid=48faaa22-1a00-0000-893c-62b8800c0000 pid=3200->65823f49-3a0a-570e-96d7-afa68525b959 send: 141B guuid=e9752534-1a00-0000-893c-62b89b0c0000 pid=3227->65823f49-3a0a-570e-96d7-afa68525b959 send: 141B guuid=59e6f644-1a00-0000-893c-62b8ab0c0000 pid=3243 /tmp/assailant.x86 guuid=8480d144-1a00-0000-893c-62b8aa0c0000 pid=3242->guuid=59e6f644-1a00-0000-893c-62b8ab0c0000 pid=3243 clone guuid=c859ff44-1a00-0000-893c-62b8ac0c0000 pid=3244 /tmp/assailant.x86 zombie guuid=59e6f644-1a00-0000-893c-62b8ab0c0000 pid=3243->guuid=c859ff44-1a00-0000-893c-62b8ac0c0000 pid=3244 clone guuid=fecd0745-1a00-0000-893c-62b8ad0c0000 pid=3245 /tmp/assailant.x86 guuid=c859ff44-1a00-0000-893c-62b8ac0c0000 pid=3244->guuid=fecd0745-1a00-0000-893c-62b8ad0c0000 pid=3245 clone guuid=9dca1845-1a00-0000-893c-62b8ae0c0000 pid=3246 /tmp/assailant.x86 net zombie guuid=c859ff44-1a00-0000-893c-62b8ac0c0000 pid=3244->guuid=9dca1845-1a00-0000-893c-62b8ae0c0000 pid=3246 clone 541343aa-57ed-5077-abaa-43455d6f904e 178.16.52.166:42516 guuid=9dca1845-1a00-0000-893c-62b8ae0c0000 pid=3246->541343aa-57ed-5077-abaa-43455d6f904e con guuid=118e5a6d-2200-0000-893c-62b8f7140000 pid=5367 /tmp/assailant.x86 net zombie guuid=9dca1845-1a00-0000-893c-62b8ae0c0000 pid=3246->guuid=118e5a6d-2200-0000-893c-62b8f7140000 pid=5367 clone guuid=a98ceb45-1a00-0000-893c-62b8b10c0000 pid=3249->65823f49-3a0a-570e-96d7-afa68525b959 send: 142B guuid=f51f5756-1a00-0000-893c-62b8cb0c0000 pid=3275->65823f49-3a0a-570e-96d7-afa68525b959 send: 142B guuid=d9cc7266-1a00-0000-893c-62b8e30c0000 pid=3299 /tmp/assailant.i686 guuid=d59b4d66-1a00-0000-893c-62b8e10c0000 pid=3297->guuid=d9cc7266-1a00-0000-893c-62b8e30c0000 pid=3299 clone guuid=f1b17e66-1a00-0000-893c-62b8e40c0000 pid=3300 /tmp/assailant.i686 guuid=d9cc7266-1a00-0000-893c-62b8e30c0000 pid=3299->guuid=f1b17e66-1a00-0000-893c-62b8e40c0000 pid=3300 clone guuid=347b9366-1a00-0000-893c-62b8e50c0000 pid=3301 /tmp/assailant.i686 guuid=f1b17e66-1a00-0000-893c-62b8e40c0000 pid=3300->guuid=347b9366-1a00-0000-893c-62b8e50c0000 pid=3301 clone guuid=03d99a66-1a00-0000-893c-62b8e70c0000 pid=3303 /tmp/assailant.i686 net zombie guuid=f1b17e66-1a00-0000-893c-62b8e40c0000 pid=3300->guuid=03d99a66-1a00-0000-893c-62b8e70c0000 pid=3303 clone guuid=03d99a66-1a00-0000-893c-62b8e70c0000 pid=3303->541343aa-57ed-5077-abaa-43455d6f904e con guuid=44a7bd8e-2200-0000-893c-62b8f8140000 pid=5368 /tmp/assailant.i686 net zombie guuid=03d99a66-1a00-0000-893c-62b8e70c0000 pid=3303->guuid=44a7bd8e-2200-0000-893c-62b8f8140000 pid=5368 clone guuid=59d4e966-1a00-0000-893c-62b8e90c0000 pid=3305->65823f49-3a0a-570e-96d7-afa68525b959 send: 141B guuid=40adac78-1a00-0000-893c-62b80d0d0000 pid=3341->65823f49-3a0a-570e-96d7-afa68525b959 send: 142B guuid=6ebaf788-1a00-0000-893c-62b8290d0000 pid=3369 /tmp/assailant.i586 guuid=a921db88-1a00-0000-893c-62b8270d0000 pid=3367->guuid=6ebaf788-1a00-0000-893c-62b8290d0000 pid=3369 clone guuid=67be0489-1a00-0000-893c-62b82a0d0000 pid=3370 /tmp/assailant.i586 guuid=6ebaf788-1a00-0000-893c-62b8290d0000 pid=3369->guuid=67be0489-1a00-0000-893c-62b82a0d0000 pid=3370 clone guuid=85a41589-1a00-0000-893c-62b82b0d0000 pid=3371 /tmp/assailant.i586 guuid=67be0489-1a00-0000-893c-62b82a0d0000 pid=3370->guuid=85a41589-1a00-0000-893c-62b82b0d0000 pid=3371 clone guuid=d4d11d89-1a00-0000-893c-62b82c0d0000 pid=3372 /tmp/assailant.i586 net zombie guuid=67be0489-1a00-0000-893c-62b82a0d0000 pid=3370->guuid=d4d11d89-1a00-0000-893c-62b82c0d0000 pid=3372 clone guuid=d4d11d89-1a00-0000-893c-62b82c0d0000 pid=3372->541343aa-57ed-5077-abaa-43455d6f904e con guuid=fc8c3fb1-2200-0000-893c-62b8f9140000 pid=5369 /tmp/assailant.i586 net zombie guuid=d4d11d89-1a00-0000-893c-62b82c0d0000 pid=3372->guuid=fc8c3fb1-2200-0000-893c-62b8f9140000 pid=5369 clone guuid=75528e89-1a00-0000-893c-62b82e0d0000 pid=3374->65823f49-3a0a-570e-96d7-afa68525b959 send: 142B guuid=2cc7059e-1a00-0000-893c-62b8450d0000 pid=3397->65823f49-3a0a-570e-96d7-afa68525b959 send: 143B guuid=c0af85ae-1a00-0000-893c-62b86b0d0000 pid=3435->65823f49-3a0a-570e-96d7-afa68525b959 send: 142B guuid=de1769c0-1a00-0000-893c-62b89f0d0000 pid=3487->65823f49-3a0a-570e-96d7-afa68525b959 send: 142B guuid=ca2844d2-1a00-0000-893c-62b8ce0d0000 pid=3534->65823f49-3a0a-570e-96d7-afa68525b959 send: 142B guuid=880ccee3-1a00-0000-893c-62b8f50d0000 pid=3573->65823f49-3a0a-570e-96d7-afa68525b959 send: 146B guuid=118e5a6d-2200-0000-893c-62b8f7140000 pid=5367->541343aa-57ed-5077-abaa-43455d6f904e con guuid=44a7bd8e-2200-0000-893c-62b8f8140000 pid=5368->541343aa-57ed-5077-abaa-43455d6f904e con guuid=fc8c3fb1-2200-0000-893c-62b8f9140000 pid=5369->541343aa-57ed-5077-abaa-43455d6f904e con
Gathering data
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt botnet defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
File and Directory Permissions Modification
Executes dropped EXE
Detected Gafgyt variant
Gafgyt family
Gafgyt/Bashlite
Malware Config
C2 Extraction:
178.16.52.166:42516
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh bf48e8b383f1a1e5bf9d411419edaa35f3e5cba6375857d000a1888d3e4d6bae

(this sample)

  
Delivery method
Distributed via web download

Comments