MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c678bdfbd02821bc30461784a98a72baf31e1ce409197f170a7d37126bb398e9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: c678bdfbd02821bc30461784a98a72baf31e1ce409197f170a7d37126bb398e9
SHA3-384 hash: 110026f1a39a1f3aa826b17d430c0f5ff839a3890878cfd2df83b0ce071320f02d9b0f60922797110ad5152c0150c053
SHA1 hash: e30e03ab7fbb048c51605698c50284311a84a5a9
MD5 hash: 9c1515a4ae9c26d93935bd48272badf8
humanhash: nitrogen-autumn-july-xray
File name:meow.sh
Download: download sample
Signature Gafgyt
File size:160 bytes
First seen:2025-04-27 21:11:51 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 3:LMFPMqQpIPFYFbFj0NDSHXfxKjEhLgMFPMqQpI8JFYhFj0NDSHXfxKjEh0:LMFPeIPFobR3vxCEaMFPeIYFYhR3vxCr
TLSH T100C012CA5A4092200B025848A2B2C830A8A1C2CC10888608AACB083BA8A86007828AC7
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://46.29.235.158/gmips3387785a975cf1e2e0a65360ea825a5f4f2ea2f544104f44736fd1cab38584cd Gafgytcensys elf gafgyt mirai ua-wget
http://46.29.235.158/gmpsl03c576ab7425edfe7ac00e82a7926074196e2a11e44bc1f1f5b7a348004b9979 Gafgytcensys elf gafgyt mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
lolbin remote
Threat name:
Script.Downloader.Heuristic
Status:
Malicious
First seen:
2025-04-27 21:12:08 UTC
File Type:
Text (Python)
AV detection:
4 of 24 (16.67%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh c678bdfbd02821bc30461784a98a72baf31e1ce409197f170a7d37126bb398e9

(this sample)

  
Delivery method
Distributed via web download

Comments