MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f1880667151a13eb689e5c1b2318b3c8ecce80315b40c4f89f30bcdc8c680bfa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: f1880667151a13eb689e5c1b2318b3c8ecce80315b40c4f89f30bcdc8c680bfa
SHA3-384 hash: 08e1e42904259b28bad89d22b2e72eceb783f29e0724fa52a294fd1b1ccddcdb468faeaa09a406e376e8e26034be56d5
SHA1 hash: 31d9e410b69c5b084959e077bbe3e1671e7f396e
MD5 hash: 0e66f137d4b4e306f31880fdfc1e4b92
humanhash: violet-washington-purple-ten
File name:Sakura.sh
Download: download sample
Signature Gafgyt
File size:2'098 bytes
First seen:2025-09-06 19:49:06 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vSad8jS9ttQdMSEYS7RS57SST6SQCScISnL1SV5NScISHxSGT:vDd8j+ttQdMdYmRa7PT6bCFI0B25NFIo
TLSH T1FF4127D711A20BF32D91E937326954C0F5D09196A4C69F4ABADC7CE448BEDEC68447C3
Magika shell
Reporter abuse_ch
Tags:gafgyt sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.170.245.23/m-i.p-s.Sakurab41a141a47a814a7bd994e912fc03bdf5fa79305902443c346f805b563575bcc Gafgytelf gafgyt ua-wget
http://45.170.245.23/m-p.s-l.Sakura68641d8a30aab4113cd52f6b55ca7d80e2e46227c034912647bc448cbd1a0530 Gafgytelf gafgyt ua-wget
http://45.170.245.23/s-h.4-.Sakura11c5dc3af21d70bbd180585286cc6c575b13531982647d0818ab8789f70b70b7 Gafgytelf gafgyt ua-wget
http://45.170.245.23/x-8.6-.Sakuraea34bcef8faf9279994a6ae4b99e7ac3e3a3d9af8973e5162f979b33a206a0f3 Gafgytelf gafgyt ua-wget
http://45.170.245.23/a-r.m-6.Sakurad656cb948d29b282e895536ada6ef7432617ec2e3da7fe1a44f91b075b8a348b Gafgytelf gafgyt ua-wget
http://45.170.245.23/x-3.2-.Sakuraedaffffc4170552035f1c299b8cca11e8ddac1d45b120dd69ad8195b01d7f1d8 Gafgytelf gafgyt ua-wget
http://45.170.245.23/a-r.m-7.Sakura67cd9ade9860af165de29dc08bd70af13b7888eed85ffa43c35df2fcf4a9d473 Gafgytelf gafgyt ua-wget
http://45.170.245.23/p-p.c-.Sakura60efa56c6afd73e1cae8a7a9986ed4f03f0f0a17317eb9b0c354763fffaad0be Gafgytelf gafgyt ua-wget
http://45.170.245.23/i-5.8-6.Sakura288c0cf5ca444faccb9643278a77c6f89577cb7bcd87bc27c006822af47494be Gafgytelf gafgyt ua-wget
http://45.170.245.23/m-6.8-k.Sakurad1cff4d398e38e17c0e368628436107a03aa1f345da354181104687e26313168 Gafgytelf gafgyt ua-wget
http://45.170.245.23/a-r.m-4.Sakura60efa56c6afd73e1cae8a7a9986ed4f03f0f0a17317eb9b0c354763fffaad0be Gafgytelf gafgyt ua-wget
http://45.170.245.23/a-r.m-5.Sakuraaafde5a93ad631683791e7d2af5bc1ece72c0c3c5ba05ceab75170173d7c2f8e Gafgytelf gafgyt ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
36
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-06T17:33:00Z UTC
Last seen:
2025-09-06T17:33:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=9fa18efa-1600-0000-14d0-ada19e0c0000 pid=3230 /usr/bin/sudo guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235 /tmp/sample.bin guuid=9fa18efa-1600-0000-14d0-ada19e0c0000 pid=3230->guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235 execve guuid=71c672fc-1600-0000-14d0-ada1a60c0000 pid=3238 /usr/bin/wget net send-data write-file guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=71c672fc-1600-0000-14d0-ada1a60c0000 pid=3238 execve guuid=28d91f29-1700-0000-14d0-ada1ee0c0000 pid=3310 /usr/bin/chmod guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=28d91f29-1700-0000-14d0-ada1ee0c0000 pid=3310 execve guuid=0f2e7129-1700-0000-14d0-ada1f00c0000 pid=3312 /usr/bin/bash guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=0f2e7129-1700-0000-14d0-ada1f00c0000 pid=3312 clone guuid=3eeb1e2a-1700-0000-14d0-ada1f40c0000 pid=3316 /usr/bin/rm delete-file guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=3eeb1e2a-1700-0000-14d0-ada1f40c0000 pid=3316 execve guuid=c4697c2a-1700-0000-14d0-ada1f60c0000 pid=3318 /usr/bin/wget net send-data write-file guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=c4697c2a-1700-0000-14d0-ada1f60c0000 pid=3318 execve guuid=22fec955-1700-0000-14d0-ada1430d0000 pid=3395 /usr/bin/chmod guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=22fec955-1700-0000-14d0-ada1430d0000 pid=3395 execve guuid=93585356-1700-0000-14d0-ada1450d0000 pid=3397 /usr/bin/bash guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=93585356-1700-0000-14d0-ada1450d0000 pid=3397 clone guuid=039f3c57-1700-0000-14d0-ada1490d0000 pid=3401 /usr/bin/rm delete-file guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=039f3c57-1700-0000-14d0-ada1490d0000 pid=3401 execve guuid=525ec357-1700-0000-14d0-ada14c0d0000 pid=3404 /usr/bin/wget net send-data write-file guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=525ec357-1700-0000-14d0-ada14c0d0000 pid=3404 execve guuid=e08e247b-1700-0000-14d0-ada1920d0000 pid=3474 /usr/bin/chmod guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=e08e247b-1700-0000-14d0-ada1920d0000 pid=3474 execve guuid=1f4a9f7b-1700-0000-14d0-ada1940d0000 pid=3476 /usr/bin/bash guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=1f4a9f7b-1700-0000-14d0-ada1940d0000 pid=3476 clone guuid=863fa37c-1700-0000-14d0-ada1980d0000 pid=3480 /usr/bin/rm delete-file guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=863fa37c-1700-0000-14d0-ada1980d0000 pid=3480 execve guuid=0d9a1e7d-1700-0000-14d0-ada19a0d0000 pid=3482 /usr/bin/wget net send-data write-file guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=0d9a1e7d-1700-0000-14d0-ada19a0d0000 pid=3482 execve guuid=d77004a9-1700-0000-14d0-ada1e20d0000 pid=3554 /usr/bin/chmod guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=d77004a9-1700-0000-14d0-ada1e20d0000 pid=3554 execve guuid=8f0288a9-1700-0000-14d0-ada1e40d0000 pid=3556 /tmp/x-8.6-.Sakura net guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=8f0288a9-1700-0000-14d0-ada1e40d0000 pid=3556 execve guuid=d5f2e2a9-1700-0000-14d0-ada1e80d0000 pid=3560 /usr/bin/rm delete-file guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=d5f2e2a9-1700-0000-14d0-ada1e80d0000 pid=3560 execve guuid=942e6caa-1700-0000-14d0-ada1ea0d0000 pid=3562 /usr/bin/wget net send-data write-file guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=942e6caa-1700-0000-14d0-ada1ea0d0000 pid=3562 execve guuid=63ed9cd6-1700-0000-14d0-ada13a0e0000 pid=3642 /usr/bin/chmod guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=63ed9cd6-1700-0000-14d0-ada13a0e0000 pid=3642 execve guuid=886421d7-1700-0000-14d0-ada13e0e0000 pid=3646 /usr/bin/bash guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=886421d7-1700-0000-14d0-ada13e0e0000 pid=3646 clone guuid=2ba82fd8-1700-0000-14d0-ada1420e0000 pid=3650 /usr/bin/rm delete-file guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=2ba82fd8-1700-0000-14d0-ada1420e0000 pid=3650 execve guuid=bf42b3d8-1700-0000-14d0-ada1440e0000 pid=3652 /usr/bin/wget net send-data write-file guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=bf42b3d8-1700-0000-14d0-ada1440e0000 pid=3652 execve guuid=5eade9fb-1700-0000-14d0-ada1890e0000 pid=3721 /usr/bin/chmod guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=5eade9fb-1700-0000-14d0-ada1890e0000 pid=3721 execve guuid=f3cc62fc-1700-0000-14d0-ada18b0e0000 pid=3723 /tmp/x-3.2-.Sakura net guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=f3cc62fc-1700-0000-14d0-ada18b0e0000 pid=3723 execve guuid=15a918fe-1700-0000-14d0-ada1940e0000 pid=3732 /usr/bin/rm delete-file guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=15a918fe-1700-0000-14d0-ada1940e0000 pid=3732 execve guuid=ba858cfe-1700-0000-14d0-ada1960e0000 pid=3734 /usr/bin/wget net send-data write-file guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=ba858cfe-1700-0000-14d0-ada1960e0000 pid=3734 execve guuid=e7b77a22-1800-0000-14d0-ada1150f0000 pid=3861 /usr/bin/chmod guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=e7b77a22-1800-0000-14d0-ada1150f0000 pid=3861 execve guuid=cf690723-1800-0000-14d0-ada1190f0000 pid=3865 /usr/bin/bash guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=cf690723-1800-0000-14d0-ada1190f0000 pid=3865 clone guuid=99e45425-1800-0000-14d0-ada1220f0000 pid=3874 /usr/bin/rm delete-file guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=99e45425-1800-0000-14d0-ada1220f0000 pid=3874 execve guuid=c646a525-1800-0000-14d0-ada1240f0000 pid=3876 /usr/bin/wget net send-data write-file guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=c646a525-1800-0000-14d0-ada1240f0000 pid=3876 execve guuid=f1fff450-1800-0000-14d0-ada1890f0000 pid=3977 /usr/bin/chmod guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=f1fff450-1800-0000-14d0-ada1890f0000 pid=3977 execve guuid=a9f36751-1800-0000-14d0-ada18b0f0000 pid=3979 /usr/bin/bash guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=a9f36751-1800-0000-14d0-ada18b0f0000 pid=3979 clone guuid=7ee6b653-1800-0000-14d0-ada18e0f0000 pid=3982 /usr/bin/rm delete-file guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=7ee6b653-1800-0000-14d0-ada18e0f0000 pid=3982 execve guuid=78de1354-1800-0000-14d0-ada1920f0000 pid=3986 /usr/bin/wget net send-data write-file guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=78de1354-1800-0000-14d0-ada1920f0000 pid=3986 execve guuid=9810747f-1800-0000-14d0-ada101100000 pid=4097 /usr/bin/chmod guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=9810747f-1800-0000-14d0-ada101100000 pid=4097 execve guuid=5152ef7f-1800-0000-14d0-ada103100000 pid=4099 /usr/bin/bash guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=5152ef7f-1800-0000-14d0-ada103100000 pid=4099 clone guuid=679ee080-1800-0000-14d0-ada107100000 pid=4103 /usr/bin/rm delete-file guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=679ee080-1800-0000-14d0-ada107100000 pid=4103 execve guuid=64d94b81-1800-0000-14d0-ada109100000 pid=4105 /usr/bin/wget net send-data write-file guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=64d94b81-1800-0000-14d0-ada109100000 pid=4105 execve guuid=0ff7dbac-1800-0000-14d0-ada163100000 pid=4195 /usr/bin/chmod guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=0ff7dbac-1800-0000-14d0-ada163100000 pid=4195 execve guuid=7fec57ad-1800-0000-14d0-ada165100000 pid=4197 /usr/bin/bash guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=7fec57ad-1800-0000-14d0-ada165100000 pid=4197 clone guuid=77ea00af-1800-0000-14d0-ada16a100000 pid=4202 /usr/bin/rm delete-file guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=77ea00af-1800-0000-14d0-ada16a100000 pid=4202 execve guuid=946181af-1800-0000-14d0-ada16b100000 pid=4203 /usr/bin/wget net send-data write-file guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=946181af-1800-0000-14d0-ada16b100000 pid=4203 execve guuid=cc973cdd-1800-0000-14d0-ada1ec100000 pid=4332 /usr/bin/chmod guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=cc973cdd-1800-0000-14d0-ada1ec100000 pid=4332 execve guuid=a9e8c6dd-1800-0000-14d0-ada1ee100000 pid=4334 /usr/bin/bash guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=a9e8c6dd-1800-0000-14d0-ada1ee100000 pid=4334 clone guuid=435124e0-1800-0000-14d0-ada1f9100000 pid=4345 /usr/bin/rm delete-file guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=435124e0-1800-0000-14d0-ada1f9100000 pid=4345 execve guuid=fe0778e0-1800-0000-14d0-ada1fb100000 pid=4347 /usr/bin/wget net send-data write-file guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=fe0778e0-1800-0000-14d0-ada1fb100000 pid=4347 execve guuid=fdf75e0d-1900-0000-14d0-ada174110000 pid=4468 /usr/bin/chmod guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=fdf75e0d-1900-0000-14d0-ada174110000 pid=4468 execve guuid=5959db0d-1900-0000-14d0-ada176110000 pid=4470 /usr/bin/bash guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=5959db0d-1900-0000-14d0-ada176110000 pid=4470 clone guuid=97ccf70e-1900-0000-14d0-ada17a110000 pid=4474 /usr/bin/rm delete-file guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=97ccf70e-1900-0000-14d0-ada17a110000 pid=4474 execve guuid=e658850f-1900-0000-14d0-ada17b110000 pid=4475 /usr/bin/wget net send-data write-file guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=e658850f-1900-0000-14d0-ada17b110000 pid=4475 execve guuid=b76c323b-1900-0000-14d0-ada1de110000 pid=4574 /usr/bin/chmod guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=b76c323b-1900-0000-14d0-ada1de110000 pid=4574 execve guuid=1c81bc3b-1900-0000-14d0-ada1e2110000 pid=4578 /usr/bin/bash guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=1c81bc3b-1900-0000-14d0-ada1e2110000 pid=4578 clone guuid=5e800c3d-1900-0000-14d0-ada1e7110000 pid=4583 /usr/bin/rm delete-file guuid=d4d826fc-1600-0000-14d0-ada1a30c0000 pid=3235->guuid=5e800c3d-1900-0000-14d0-ada1e7110000 pid=4583 execve 86c1f747-ffa2-5949-868d-04c681a17fda 45.170.245.23:80 guuid=71c672fc-1600-0000-14d0-ada1a60c0000 pid=3238->86c1f747-ffa2-5949-868d-04c681a17fda send: 142B guuid=c4697c2a-1700-0000-14d0-ada1f60c0000 pid=3318->86c1f747-ffa2-5949-868d-04c681a17fda send: 142B guuid=525ec357-1700-0000-14d0-ada14c0d0000 pid=3404->86c1f747-ffa2-5949-868d-04c681a17fda send: 141B guuid=0d9a1e7d-1700-0000-14d0-ada19a0d0000 pid=3482->86c1f747-ffa2-5949-868d-04c681a17fda send: 141B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=8f0288a9-1700-0000-14d0-ada1e40d0000 pid=3556->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9b12c7a9-1700-0000-14d0-ada1e60d0000 pid=3558 /tmp/x-8.6-.Sakura guuid=8f0288a9-1700-0000-14d0-ada1e40d0000 pid=3556->guuid=9b12c7a9-1700-0000-14d0-ada1e60d0000 pid=3558 clone guuid=fc30d0a9-1700-0000-14d0-ada1e70d0000 pid=3559 /tmp/x-8.6-.Sakura net send-data zombie guuid=9b12c7a9-1700-0000-14d0-ada1e60d0000 pid=3558->guuid=fc30d0a9-1700-0000-14d0-ada1e70d0000 pid=3559 clone 2d6db176-9145-5e3e-9093-bb8175cb01a7 45.170.245.23:12345 guuid=fc30d0a9-1700-0000-14d0-ada1e70d0000 pid=3559->2d6db176-9145-5e3e-9093-bb8175cb01a7 send: 65B guuid=942e6caa-1700-0000-14d0-ada1ea0d0000 pid=3562->86c1f747-ffa2-5949-868d-04c681a17fda send: 142B guuid=bf42b3d8-1700-0000-14d0-ada1440e0000 pid=3652->86c1f747-ffa2-5949-868d-04c681a17fda send: 141B guuid=f3cc62fc-1700-0000-14d0-ada18b0e0000 pid=3723->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b4cd00fe-1700-0000-14d0-ada1920e0000 pid=3730 /tmp/x-3.2-.Sakura guuid=f3cc62fc-1700-0000-14d0-ada18b0e0000 pid=3723->guuid=b4cd00fe-1700-0000-14d0-ada1920e0000 pid=3730 clone guuid=b0c408fe-1700-0000-14d0-ada1930e0000 pid=3731 /tmp/x-3.2-.Sakura net send-data zombie guuid=b4cd00fe-1700-0000-14d0-ada1920e0000 pid=3730->guuid=b0c408fe-1700-0000-14d0-ada1930e0000 pid=3731 clone guuid=b0c408fe-1700-0000-14d0-ada1930e0000 pid=3731->2d6db176-9145-5e3e-9093-bb8175cb01a7 send: 12545B guuid=ba858cfe-1700-0000-14d0-ada1960e0000 pid=3734->86c1f747-ffa2-5949-868d-04c681a17fda send: 142B guuid=c646a525-1800-0000-14d0-ada1240f0000 pid=3876->86c1f747-ffa2-5949-868d-04c681a17fda send: 141B guuid=78de1354-1800-0000-14d0-ada1920f0000 pid=3986->86c1f747-ffa2-5949-868d-04c681a17fda send: 142B guuid=64d94b81-1800-0000-14d0-ada109100000 pid=4105->86c1f747-ffa2-5949-868d-04c681a17fda send: 142B guuid=946181af-1800-0000-14d0-ada16b100000 pid=4203->86c1f747-ffa2-5949-868d-04c681a17fda send: 141B guuid=fe0778e0-1800-0000-14d0-ada1fb100000 pid=4347->86c1f747-ffa2-5949-868d-04c681a17fda send: 142B guuid=e658850f-1900-0000-14d0-ada17b110000 pid=4475->86c1f747-ffa2-5949-868d-04c681a17fda send: 142B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-09-06 19:55:48 UTC
File Type:
Text (Shell)
AV detection:
25 of 38 (65.79%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt botnet defense_evasion discovery linux
Behaviour
Writes file to tmp directory
Reads system network configuration
Reads system routing table
File and Directory Permissions Modification
Executes dropped EXE
Detected Gafgyt variant
Gafgyt family
Gafgyt/Bashlite
Malware Config
C2 Extraction:
45.170.245.23:12345
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh f1880667151a13eb689e5c1b2318b3c8ecce80315b40c4f89f30bcdc8c680bfa

(this sample)

  
Delivery method
Distributed via web download

Comments