MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14
SHA3-384 hash: 2c56a63332b2421dbbccc3993c263da2fe311d49d43e6a39e42f0db901adbd76c37590d33c08cf6c75e4ce02e1066574
SHA1 hash: 1e3605f5a7c3b0ed8dd0333660e9b43431f395bd
MD5 hash: 849b165f28ae8b1cebe0c7430f44aff3
humanhash: lion-undress-pluto-juliet
File name:Mozi.m
Download: download sample
Signature Gafgyt
File size:129'280 bytes
First seen:2021-02-07 04:18:44 UTC
Last seen:2021-05-05 09:59:03 UTC
File type: elf
MIME type:application/x-executable
ssdeep 3072:vDH1Y9gKmUr3SD+NQ39o+F1+AehjW6Bh1ciG1qp5oiM:vDV2zmUjGv39o+F1+NJj1G1qp5oiM
TLSH 2AC312072619C2CCD4C437B2171B9BBA8D17A23DBFE474DC80CBBAA2A97D192E513750
Reporter tolisec
Tags:gafgyt

Intelligence


File Origin
# of uploads :
6
# of downloads :
152
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
Linux.Trojan.Gafgyt
Status:
Malicious
First seen:
2019-09-01 12:14:26 UTC
AV detection:
20 of 28 (71.43%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

elf c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14

(this sample)

  
Delivery method
Distributed via web download

Comments