MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c108d3c038cdfa4d4ca6867af2314531bf5cef19a9dd81a582784aa9f82cfc8d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 5


Intelligence 5 IOCs YARA 2 File information Comments

SHA256 hash: c108d3c038cdfa4d4ca6867af2314531bf5cef19a9dd81a582784aa9f82cfc8d
SHA3-384 hash: ed0fe7f47604a3b8b31cb2f6d584df618e30454203e12e5c6797e4955bec4c4ab855263734c87ff48dfaf303f284a62c
SHA1 hash: 683a45fcd01ace2236ff7e441d0645486295c64c
MD5 hash: 1b3d2c42f35b860df5cae4bfd1833e8e
humanhash: neptune-october-finch-romeo
File name:sex.sh
Download: download sample
Signature Gafgyt
File size:1'587 bytes
First seen:2026-02-06 13:59:35 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:v02e+02V02Uc4k02Jas02902Es02Jb02ss02l02eO02qaF02SK02W:vrfP4kjb/T7bvMOLXo
TLSH T1183184EA21A10E716C96A92B72AF495479D4E5EB10CE6F886CEC3CF9548CE0470107A7
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:gafgyt sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.45.245.174/mipsf2cf9f6287dd6d972a186a754a2f76435bb5d7cc18d3230052caab1820be8ef7 Gafgytcensys elf gafgyt ua-wget
http://103.45.245.174/mipseln/an/aelf ua-wget
http://103.45.245.174/sh441061a2a00d12a372849fabcc1acb5e784cca814ee1f66bb9f9d5cf445b35827 Gafgytcensys elf gafgyt ua-wget
http://103.45.245.174/x86d7ea1d504dac74a1cd68ab5119680fd8a3abe6deecd99a8dfcc01476f0ebf611 Gafgytcensys elf gafgyt ua-wget
http://103.45.245.174/arm61n/an/aelf ua-wget
http://103.45.245.174/i686n/an/aelf ua-wget
http://103.45.245.174/ppc1d85c96135065004c0765d205230ce6c869ed4188bf3739364b8abcc14b87a21 Gafgytcensys elf gafgyt ua-wget
http://103.45.245.174/586ea4607df5ece1c539b4550699a31ada5dfa69cdf5e84dc6746c7a5c1ed1b62ef Gafgytcensys elf gafgyt ua-wget
http://103.45.245.174/m68k5559292bac8be104d9e8f8cc3a102072d98ac275d6756c9ee9c56a734c57f22d Gafgytcensys elf gafgyt ua-wget
http://103.45.245.174/dc90c1005ce769790abd349210202e4909dae7f0ffaa9d5acfc28d8f8d74495768 Gafgytcensys elf gafgyt ua-wget
http://103.45.245.174/dssa762b97dacec6d92e94272e1cddd7ae843315dab2469cb3d766ea968c046a4d3 Gafgytcensys elf gafgyt ua-wget
http://103.45.245.174/coe752485ade46b1becc7f3c0b9d92d958c89ba9f46be39270ead77a0ed761087d Gafgytcensys elf gafgyt ua-wget
http://103.45.245.174/scarn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
25
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Gathering data
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt botnet defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Detected Gafgyt variant
Gafgyt family
Gafgyt/Bashlite
Malware Config
C2 Extraction:
103.45.245.174:23
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh c108d3c038cdfa4d4ca6867af2314531bf5cef19a9dd81a582784aa9f82cfc8d

(this sample)

  
Delivery method
Distributed via web download

Comments