MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ca5811dfdb2892d0c01c317f33364c7a4511c4a270f9f8cddafdeb86caeb387b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: ca5811dfdb2892d0c01c317f33364c7a4511c4a270f9f8cddafdeb86caeb387b
SHA3-384 hash: 81a3df33147b3e048a1b5fc7f4f9dc23f525f2429a4ef6527640941b2127d201b8546a8877227a5e188047278956b1ec
SHA1 hash: ab252e0a5cc76f15cd8148f8cc8161897a4efeea
MD5 hash: 3e5bef3451c7ec7686a8f3e5d701fda0
humanhash: victor-october-missouri-cola
File name:rondo.mips
Download: download sample
Signature Gafgyt
File size:162'016 bytes
First seen:2025-12-24 12:07:58 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 1536:Z1i77Qeg5bHPfNDVOKK0t05Cao/vTqeGHwdovUmRsZ8quF9zFAzEXRgguuZRHcxo:07SHV9ZXoYAGguuZRHcGoxFpjEcrYf
TLSH T1C8F3A60E6E214F7DF36C833447B74F75A65EB3DA12E1C685E2BCE2112E60249252F768
telfhash t1872191680db917a4762a6c5d491deb67d2a335df3e056c338e11d81eeb69f835d20c0c
Magika elf
Reporter abuse_ch
Tags:elf gafgyt

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
masquerade
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=18006f55-1800-0000-3939-a2f30b080000 pid=2059 /usr/bin/sudo guuid=684fc257-1800-0000-3939-a2f30e080000 pid=2062 /tmp/sample.bin guuid=18006f55-1800-0000-3939-a2f30b080000 pid=2059->guuid=684fc257-1800-0000-3939-a2f30e080000 pid=2062 execve
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Linux.Backdoor.Gafgyt
Status:
Malicious
First seen:
2025-12-24 12:08:18 UTC
File Type:
ELF32 Big (Exe)
AV detection:
7 of 36 (19.44%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
System Network Configuration Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

elf ca5811dfdb2892d0c01c317f33364c7a4511c4a270f9f8cddafdeb86caeb387b

(this sample)

  
Delivery method
Distributed via web download

Comments