MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d02a342e53cd98fe331a475c772199ca55896d254cf1d39571c2d92721a9705d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: d02a342e53cd98fe331a475c772199ca55896d254cf1d39571c2d92721a9705d
SHA3-384 hash: e26aa8b51d8572507188ee0dafd9f389012837fa7f327857b39f53a287bc14f2d5049e969f3f390c7965edb3d301b9ff
SHA1 hash: cd4865323b5229b1edd5255a7039a854615ff1e7
MD5 hash: 4ed7e2d356ef7d2e1ceb9a84012486c8
humanhash: blue-earth-kansas-uranus
File name:poc
Download: download sample
Signature Gafgyt
File size:312 bytes
First seen:2025-09-14 11:38:24 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 6:L6FixSBuJrfFF9nSBmrfFF9nSBaFVJrfFF9nSB9FPrfFFj:SBQrfFzSBmrfFzSBaFPrfFzSB9FPrfFB
TLSH T1ADE017EF58DA7890C029C909B35318C461CBC2C674F69F6AD9FC5CB5488FE687055F89
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://158.94.209.216/ui68651138a0bdded7b065ea2286c581f9b14fe17d904d71aa5cea763b67fb8083b42 Miraielf mirai ua-wget
http://158.94.209.216/uppc9571006c74e39888a4a2709e87109120ce44b627498ee298c4242def6f3680c4 Miraielf mirai ua-wget
http://158.94.209.216/umips204694442ce29b4de5a53ac66e3ee7e4bde91ea779981f8ab86b97a23078bfdc Gafgytelf gafgyt
http://158.94.209.216/umpsl12c372364b5aa742ea607ed72288b85614f9bfe17f0fe683e882a53841ac67e6 Gafgytelf gafgyt

Intelligence


File Origin
# of uploads :
1
# of downloads :
33
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-14T08:51:00Z UTC
Last seen:
2025-09-14T08:51:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.a
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Document-HTML.Downloader.Heuristic
Status:
Malicious
First seen:
2025-09-14 11:30:05 UTC
File Type:
Text (Shell)
AV detection:
8 of 38 (21.05%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh d02a342e53cd98fe331a475c772199ca55896d254cf1d39571c2d92721a9705d

(this sample)

  
Delivery method
Distributed via web download

Comments