MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d6ccc737f8f8195bd472e56d405f3dba28bb338e9f5a83814a84e43d3910f7a0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: d6ccc737f8f8195bd472e56d405f3dba28bb338e9f5a83814a84e43d3910f7a0
SHA3-384 hash: ddf5dae74a2573d4e1961a401114b410d221d66bbbe7dae8ce7073588d4319eb050a2d0bbab252f99e3959c79057b524
SHA1 hash: bb70543ac0347d3671740e76efc5453702e29d15
MD5 hash: 41b9b0496fc3c3ee4661dac83497b17e
humanhash: oscar-queen-utah-jersey
File name:g.sh
Download: download sample
Signature Gafgyt
File size:894 bytes
First seen:2025-11-29 10:43:09 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:gpb5GKBo/hseTX9hXZ1gYcq0ECQPeV242L8L7wEKfYxn:WHuScNtZG1q0/BVGo41Yxn
TLSH T15E11EB36E81DE820077A4098EE06A285FD2A89030F242933711CA0F0BF3C053A1BEF6D
TrID 69.9% (.SH) Linux/UNIX shell script (7000/1)
29.9% (.) Unix-like shebang (var.3) (gen) (3000/1)
0.0% (.PIC) Bio-Rad Image(s) bitmap (2/1)
Magika shell
Reporter juroots
Tags:gafgyt sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
32
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Verdict:
Unknown
File Type:
unix shell
First seen:
2025-11-29T11:07:00Z UTC
Last seen:
2025-11-30T08:47:00Z UTC
Hits:
~10
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments