MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e97d38896f7a0020edbe5753dd7b3e154857caebc31cee880e083ca7f16ea79a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: e97d38896f7a0020edbe5753dd7b3e154857caebc31cee880e083ca7f16ea79a
SHA3-384 hash: 0e6ddb89e4a476eaa79a81595088298d4db37f504d83e621b9b51c759ae03455593f1accf7e185c77feb5e9b360144bd
SHA1 hash: 3533cb6612c9a472f87c4efff5844e3edeac455b
MD5 hash: cfbfd14f3c20ab1968036a2ee60c6fb7
humanhash: bacon-ten-may-enemy
File name:giga.sh
Download: download sample
Signature Gafgyt
File size:242 bytes
First seen:2025-05-17 08:34:10 UTC
Last seen:2025-05-17 20:09:12 UTC
File type: sh
MIME type:text/plain
ssdeep 6:LMFFEZqjGkNYC/PamRDMFFEZmapLkNYCzXkG:oSZqqkNYuamKSZmadkNYqkG
TLSH T15BD0C9EEDA766831C002BD4C9BA2DF586006D4E337573F88958C0DA68798FE0F4919C8
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.188.82.240/skid.mips4baa8232e960916b0718f13163b3cfc72ea98a4dfbe92308ead25ca308a353ff Gafgytelf gafgyt ua-wget
http://103.188.82.240/skid.arm79af6d65181a6f3a7d75443586c298a27904083ee7a931a8d4601625fc4ca016f Miraielf mirai

Intelligence


File Origin
# of uploads :
2
# of downloads :
82
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
94.9%
Tags:
downloader mirai agent hype
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Threat name:
Text.Browser.Generic
Status:
Suspicious
First seen:
2025-05-17 08:35:18 UTC
File Type:
Text (Shell)
AV detection:
2 of 24 (8.33%)
Threat level:
  4/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh e97d38896f7a0020edbe5753dd7b3e154857caebc31cee880e083ca7f16ea79a

(this sample)

  
Delivery method
Distributed via web download

Comments