MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 deae2708d8822bb012c6b3a8f9193b6742a79b9d400c180b34102b69d2f65e5e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: deae2708d8822bb012c6b3a8f9193b6742a79b9d400c180b34102b69d2f65e5e
SHA3-384 hash: f9c1c027314296477100bd07b64758a730f9e27c65e916dd6825c2fef9e42a84e5537d3170890715caa986638d94a0fd
SHA1 hash: 00cd82755c00a27f8f05115673cb1dc362fce2cf
MD5 hash: ac582efd21baf1806e3faa8b43d21b80
humanhash: north-kitten-romeo-fanta
File name:t
Download: download sample
Signature Gafgyt
File size:518 bytes
First seen:2025-01-20 21:17:10 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:H+J26HHXkYxtEYq/dB9EsrF14UdHKUDoK8kYHdGPU:esyHXRvO/ZrMU3o39GPU
TLSH T15AF059949893352E60B948DC852A4005EB0451AB6A5809047EDE39775FBCD21B50A2B9
Magika shell
Reporter abuse_ch
Tags:gafgyt sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
108
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Verdict:
Malicious
Labled as:
Trojan[Downloader]/Shell.Agent
Result
Verdict:
UNKNOWN
Threat name:
Script.Trojan.Multiverze
Status:
Malicious
First seen:
2025-01-20 21:12:01 UTC
File Type:
Text (Shell)
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh deae2708d8822bb012c6b3a8f9193b6742a79b9d400c180b34102b69d2f65e5e

(this sample)

Comments