MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ef075b94d673c947e48deaf797e045c7de4d98bd162157e0227f7d12b179ac2f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: ef075b94d673c947e48deaf797e045c7de4d98bd162157e0227f7d12b179ac2f
SHA3-384 hash: ca3e9b794f7a8d97c0d681364cc5987f6edbca15a3622c6b100824dcf82b5ebb29282ce4bb478861257fa49017babc05
SHA1 hash: 16598145bac05a3703f4569b78240238877652a2
MD5 hash: 3257a5b4fc7ab73cf26f96ebbd0b8440
humanhash: aspen-maine-early-lima
File name:bins.sh
Download: download sample
Signature Gafgyt
File size:1'660 bytes
First seen:2025-05-18 22:23:08 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:1KfkK25K8+MKHq5K8KrUKkKEK/UKAKwKQKH:1KfkK8KrMKK5K8KwKkKEKcKAKwKQKH
TLSH T1123193CB21E22A34AD75E97B32F54C04B9E5D08619D76F446EEC38E9808DE04B845F83
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://92.112.125.58/ntpdac07aeb09c924f589951face3bf81dd3eca77791c5d0b1218d3756e17d3865ee Gafgytgafgyt mirai opendir
http://92.112.125.58/sshdd7280bfadcacaf77b877056c0efac50c35e81dec28bd45dadaee10359c94eda2 Gafgytgafgyt mirai opendir
http://92.112.125.58/openssh47ed9b39f06a258f41ac1ddea574c1d6ae067d9cd1af1f1d199520b00901d2e0 Gafgytgafgyt mirai opendir
http://92.112.125.58/bash5d962a0513b3778e414c05dd3865164a2f6961da40bd2ad5114fcbb771232502 Gafgytgafgyt mirai opendir
http://92.112.125.58/tftp3ba562d90eb1c1211d3422fb08c9df24587e72d122dc81d4a13fe5f036a8a22c Gafgytgafgyt mirai opendir
http://92.112.125.58/wgetf2ac733613aff076d28c5a571a9c8913a476139d25e19d62543c16d76dfb1b64 Gafgytgafgyt mirai opendir
http://92.112.125.58/cron7aaffb7dc0ec68b3b907d677170b6cc446dfde40c84ec272fe3a92af29179dec Gafgytgafgyt mirai opendir
http://92.112.125.58/ftp393fc1c3544e23a604729f4f0c7c659884ec0f234bcf0514cfd0830efc2466ea Gafgytgafgyt mirai opendir
http://92.112.125.58/pftpc8458a2ed581e02504af58542ff63be078e9f9d1a70d30304d0da4a232b6dc1a Gafgytgafgyt mirai opendir
http://92.112.125.58/she7390f79b36d29ba64b78b9b07e30fced11c4da32f1d9abbf13114f2eb950a18 Gafgytgafgyt mirai opendir
http://92.112.125.58/n/an/an/a
http://92.112.125.58/apache2e7ac6850838d7389b40a6bd6ce568ff9d6a0531b91d388e8dcf39b2840bf150b Gafgytgafgyt mirai opendir
http://92.112.125.58/telnetdn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
103
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
lolbin remote
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-05-18 22:23:20 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh ef075b94d673c947e48deaf797e045c7de4d98bd162157e0227f7d12b179ac2f

(this sample)

  
Delivery method
Distributed via web download

Comments