MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c2b15fdd2e7a3a4e6f191fe4d416e0b2a0e3e3e51717df672b69db7d5a338d04. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: c2b15fdd2e7a3a4e6f191fe4d416e0b2a0e3e3e51717df672b69db7d5a338d04
SHA3-384 hash: 75a560779fd7a73deaf303e774bfc2d880676bafb34183058e09fe04a9377d79bd66881ec76e0283171fd574b6965fa0
SHA1 hash: 4159116007f4f547db6e2b019bf05fd40258e0b5
MD5 hash: 90b0bedb3d6c7a1197804c3b930ec9d5
humanhash: speaker-butter-yellow-alpha
File name:arm7
Download: download sample
Signature Gafgyt
File size:33'992 bytes
First seen:2025-01-03 06:46:10 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 768:ybynQDiQwHW2kJKoC+9mU5pvSMONQd/i7VbJe0n1weC:y+nPHW2Pc9mU5pvSMO+d/i7VbwF
TLSH T145E22B4AFD419F11D4D0217EFEAF524D33331B68E2EB3202AE106B246B8AD5E0F76955
telfhash t130f049318604acd966c49017b04e3542fd2262ea3abd384673fbec8d69328b15112a9c
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf gafgyt mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
104
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Runs as daemon
Connection attempt
Receives data from a server
Opens a port
Sends data to a server
Creating a file
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
arm
Packer:
not packed
Botnet:
unknown
Number of open files:
0
Number of processes launched:
1
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
no suspicious findings
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Result
Verdict:
UNKNOWN
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Linux.Trojan.Mirai
Status:
Malicious
First seen:
2025-01-03 03:21:35 UTC
File Type:
ELF32 Little (Exe)
AV detection:
14 of 23 (60.87%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

elf c2b15fdd2e7a3a4e6f191fe4d416e0b2a0e3e3e51717df672b69db7d5a338d04

(this sample)

  
Delivery method
Distributed via web download

Comments