MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f3cde3780136aa469649c5028c4eb3262738579140d03448c618c7ca50cfd7db. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 7


Intelligence 7 IOCs YARA 3 File information Comments

SHA256 hash: f3cde3780136aa469649c5028c4eb3262738579140d03448c618c7ca50cfd7db
SHA3-384 hash: bac0e0f9b2ce23ddfd93e845ed6f2d08fee53e2d3afeacdfda37be8a458c020c7b879dd6493ded3c42f5ef1fcdf8df65
SHA1 hash: 9e4f57b1b0c2da1601b5f02b1272ff78fcfb34fd
MD5 hash: 6972d3d62253c486b78ab5a4ba17584b
humanhash: low-freddie-double-equal
File name:bins.sh
Download: download sample
Signature Gafgyt
File size:1'816 bytes
First seen:2026-01-18 19:20:26 UTC
Last seen:2026-01-18 22:30:37 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vSQL+xarHKhdJGI3OA5I3rsysRswssrI32d:vSu+xarHKhrGGOA5Gr1ofBrI32d
TLSH T1B83145EBE4614DBD3F54A91732E5461434E098A658FEDF37ACEC34E5019CE8CA4C2693
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:gafgyt sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.211.218.101/yakuza.mipsb3ca938ef13b0b0320df7a2248af9bc639f732d809ca2b56997af6ebfe2ea34b GafgytDEU elf gafgyt geofenced ua-wget
http://103.211.218.101/yakuza.mpsl2202c7e3b4f89af0f31f2d2c453e200ec320490d7327ce10a877ac6731b0ccff GafgytDEU elf gafgyt geofenced ua-wget
http://103.211.218.101/yakuza.sh490dedd325d5be13d2cb48f31ae13f1a8161770ccd9603c0c46320e10551c3d6d GafgytDEU elf gafgyt geofenced ua-wget
http://103.211.218.101/yakuza.x865f5421cb72d0c879831ad58b1f073817c976cc8c68c9bba0a95f98065e379d7b GafgytDEU elf gafgyt geofenced ua-wget
http://103.211.218.101/yakuza.arm6dfed6a8212392e7e55b8ba709fdc6eb154a0002785b275e605688a78ce67619b GafgytDEU elf gafgyt geofenced ua-wget
http://103.211.218.101/yakuza.x3223e3354e499b6cb514c01d1e56b9f7c2954f9fe38eaca10649a04d41726f0775 GafgytDEU elf gafgyt geofenced ua-wget
http://103.211.218.101/yakuza.ppc490735ee8f6e61fab8c608d35b9c434c8f4f7060552769584ff6ca519cbafe89 GafgytDEU elf gafgyt geofenced ua-wget
http://103.211.218.101/yakuza.i58677e2ed4ee4e8b7c84175b494c0ee4def2cddbd395408ef3f87d58863c8a79e00 GafgytDEU elf gafgyt geofenced ua-wget
http://103.211.218.101/yakuza.m68k68cf0ff1b76f0f73b0ab2de921ca6bc2d149655f9dc80fcdfe4fe644482683fc GafgytDEU elf gafgyt geofenced ua-wget
http://103.211.218.101/yakuza.arm4ec775aa17230edba71083a13a9823164ab7f4f6b57688e59218f6bed178cdf0f GafgytDEU elf gafgyt geofenced ua-wget
http://103.211.218.101/yakuza.arm5n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
29
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=a2eefbe3-1a00-0000-fa8a-0298740b0000 pid=2932 /usr/bin/sudo guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934 /tmp/sample.bin guuid=a2eefbe3-1a00-0000-fa8a-0298740b0000 pid=2932->guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934 execve guuid=8d0c5ce7-1a00-0000-fa8a-0298770b0000 pid=2935 /usr/bin/wget net send-data write-file guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=8d0c5ce7-1a00-0000-fa8a-0298770b0000 pid=2935 execve guuid=0ca96a24-1b00-0000-fa8a-0298ed0b0000 pid=3053 /usr/bin/chmod guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=0ca96a24-1b00-0000-fa8a-0298ed0b0000 pid=3053 execve guuid=950cd424-1b00-0000-fa8a-0298ef0b0000 pid=3055 /usr/bin/bash guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=950cd424-1b00-0000-fa8a-0298ef0b0000 pid=3055 clone guuid=486bb525-1b00-0000-fa8a-0298f30b0000 pid=3059 /usr/bin/rm delete-file guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=486bb525-1b00-0000-fa8a-0298f30b0000 pid=3059 execve guuid=ec991c26-1b00-0000-fa8a-0298f60b0000 pid=3062 /usr/bin/wget net send-data write-file guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=ec991c26-1b00-0000-fa8a-0298f60b0000 pid=3062 execve guuid=43aab762-1b00-0000-fa8a-0298760c0000 pid=3190 /usr/bin/chmod guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=43aab762-1b00-0000-fa8a-0298760c0000 pid=3190 execve guuid=771b3263-1b00-0000-fa8a-0298770c0000 pid=3191 /usr/bin/bash guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=771b3263-1b00-0000-fa8a-0298770c0000 pid=3191 clone guuid=28810c66-1b00-0000-fa8a-0298790c0000 pid=3193 /usr/bin/rm delete-file guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=28810c66-1b00-0000-fa8a-0298790c0000 pid=3193 execve guuid=747bbc66-1b00-0000-fa8a-02987a0c0000 pid=3194 /usr/bin/wget net send-data write-file guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=747bbc66-1b00-0000-fa8a-02987a0c0000 pid=3194 execve guuid=245dd8a0-1b00-0000-fa8a-0298b40c0000 pid=3252 /usr/bin/chmod guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=245dd8a0-1b00-0000-fa8a-0298b40c0000 pid=3252 execve guuid=2b4f6ca1-1b00-0000-fa8a-0298b50c0000 pid=3253 /usr/bin/bash guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=2b4f6ca1-1b00-0000-fa8a-0298b50c0000 pid=3253 clone guuid=606983a3-1b00-0000-fa8a-0298b70c0000 pid=3255 /usr/bin/rm delete-file guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=606983a3-1b00-0000-fa8a-0298b70c0000 pid=3255 execve guuid=98fadfa3-1b00-0000-fa8a-0298b80c0000 pid=3256 /usr/bin/wget net send-data write-file guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=98fadfa3-1b00-0000-fa8a-0298b80c0000 pid=3256 execve guuid=dfff63f1-1b00-0000-fa8a-02983a0d0000 pid=3386 /usr/bin/chmod guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=dfff63f1-1b00-0000-fa8a-02983a0d0000 pid=3386 execve guuid=e9e6d1f1-1b00-0000-fa8a-02983b0d0000 pid=3387 /tmp/yakuza.x86 guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=e9e6d1f1-1b00-0000-fa8a-02983b0d0000 pid=3387 execve guuid=365302f2-1b00-0000-fa8a-0298400d0000 pid=3392 /usr/bin/rm delete-file guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=365302f2-1b00-0000-fa8a-0298400d0000 pid=3392 execve guuid=13d45bf2-1b00-0000-fa8a-0298410d0000 pid=3393 /usr/bin/wget net send-data write-file guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=13d45bf2-1b00-0000-fa8a-0298410d0000 pid=3393 execve guuid=a4e2851f-1c00-0000-fa8a-0298b00d0000 pid=3504 /usr/bin/chmod guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=a4e2851f-1c00-0000-fa8a-0298b00d0000 pid=3504 execve guuid=a426e61f-1c00-0000-fa8a-0298b20d0000 pid=3506 /usr/bin/bash guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=a426e61f-1c00-0000-fa8a-0298b20d0000 pid=3506 clone guuid=bc2ce320-1c00-0000-fa8a-0298b70d0000 pid=3511 /usr/bin/rm delete-file guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=bc2ce320-1c00-0000-fa8a-0298b70d0000 pid=3511 execve guuid=df654521-1c00-0000-fa8a-0298b90d0000 pid=3513 /usr/bin/wget net send-data write-file guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=df654521-1c00-0000-fa8a-0298b90d0000 pid=3513 execve guuid=fba44145-1c00-0000-fa8a-0298040e0000 pid=3588 /usr/bin/chmod guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=fba44145-1c00-0000-fa8a-0298040e0000 pid=3588 execve guuid=314ecc45-1c00-0000-fa8a-0298070e0000 pid=3591 /tmp/yakuza.x32 guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=314ecc45-1c00-0000-fa8a-0298070e0000 pid=3591 execve guuid=284a7146-1c00-0000-fa8a-02980f0e0000 pid=3599 /usr/bin/rm delete-file guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=284a7146-1c00-0000-fa8a-02980f0e0000 pid=3599 execve guuid=d17ccc46-1c00-0000-fa8a-0298100e0000 pid=3600 /usr/bin/wget net send-data write-file guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=d17ccc46-1c00-0000-fa8a-0298100e0000 pid=3600 execve guuid=56942074-1c00-0000-fa8a-0298760e0000 pid=3702 /usr/bin/chmod guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=56942074-1c00-0000-fa8a-0298760e0000 pid=3702 execve guuid=31918074-1c00-0000-fa8a-0298770e0000 pid=3703 /usr/bin/bash guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=31918074-1c00-0000-fa8a-0298770e0000 pid=3703 clone guuid=233ca475-1c00-0000-fa8a-0298790e0000 pid=3705 /usr/bin/rm delete-file guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=233ca475-1c00-0000-fa8a-0298790e0000 pid=3705 execve guuid=3cae1b76-1c00-0000-fa8a-02987a0e0000 pid=3706 /usr/bin/wget net send-data write-file guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=3cae1b76-1c00-0000-fa8a-02987a0e0000 pid=3706 execve guuid=b6c4bb9e-1c00-0000-fa8a-0298f40e0000 pid=3828 /usr/bin/chmod guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=b6c4bb9e-1c00-0000-fa8a-0298f40e0000 pid=3828 execve guuid=cde6119f-1c00-0000-fa8a-0298f60e0000 pid=3830 /tmp/yakuza.i586 guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=cde6119f-1c00-0000-fa8a-0298f60e0000 pid=3830 execve guuid=394d509f-1c00-0000-fa8a-0298fc0e0000 pid=3836 /usr/bin/rm delete-file guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=394d509f-1c00-0000-fa8a-0298fc0e0000 pid=3836 execve guuid=ebdba69f-1c00-0000-fa8a-0298fe0e0000 pid=3838 /usr/bin/wget net send-data write-file guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=ebdba69f-1c00-0000-fa8a-0298fe0e0000 pid=3838 execve guuid=6c1318da-1c00-0000-fa8a-0298a50f0000 pid=4005 /usr/bin/chmod guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=6c1318da-1c00-0000-fa8a-0298a50f0000 pid=4005 execve guuid=13b870da-1c00-0000-fa8a-0298a70f0000 pid=4007 /usr/bin/bash guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=13b870da-1c00-0000-fa8a-0298a70f0000 pid=4007 clone guuid=aefa40db-1c00-0000-fa8a-0298ab0f0000 pid=4011 /usr/bin/rm delete-file guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=aefa40db-1c00-0000-fa8a-0298ab0f0000 pid=4011 execve guuid=3f4f87db-1c00-0000-fa8a-0298ae0f0000 pid=4014 /usr/bin/wget net send-data write-file guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=3f4f87db-1c00-0000-fa8a-0298ae0f0000 pid=4014 execve guuid=48e8050c-1d00-0000-fa8a-029843100000 pid=4163 /usr/bin/chmod guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=48e8050c-1d00-0000-fa8a-029843100000 pid=4163 execve guuid=c444610c-1d00-0000-fa8a-029845100000 pid=4165 /usr/bin/bash guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=c444610c-1d00-0000-fa8a-029845100000 pid=4165 clone guuid=acaf100d-1d00-0000-fa8a-029847100000 pid=4167 /usr/bin/rm delete-file guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=acaf100d-1d00-0000-fa8a-029847100000 pid=4167 execve guuid=719d6c0d-1d00-0000-fa8a-029848100000 pid=4168 /usr/bin/wget net send-data write-file guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=719d6c0d-1d00-0000-fa8a-029848100000 pid=4168 execve guuid=4b309947-1d00-0000-fa8a-029809110000 pid=4361 /usr/bin/chmod guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=4b309947-1d00-0000-fa8a-029809110000 pid=4361 execve guuid=977efc47-1d00-0000-fa8a-02980a110000 pid=4362 /usr/bin/bash guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=977efc47-1d00-0000-fa8a-02980a110000 pid=4362 clone guuid=97578c49-1d00-0000-fa8a-02980f110000 pid=4367 /usr/bin/rm delete-file guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=97578c49-1d00-0000-fa8a-02980f110000 pid=4367 execve guuid=cbc3db49-1d00-0000-fa8a-029810110000 pid=4368 /usr/bin/wget net send-data guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=cbc3db49-1d00-0000-fa8a-029810110000 pid=4368 execve guuid=7c87a05d-1d00-0000-fa8a-029858110000 pid=4440 /usr/bin/chmod guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=7c87a05d-1d00-0000-fa8a-029858110000 pid=4440 execve guuid=e2ebed5d-1d00-0000-fa8a-02985a110000 pid=4442 /usr/bin/bash guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=e2ebed5d-1d00-0000-fa8a-02985a110000 pid=4442 clone guuid=fb100a5e-1d00-0000-fa8a-02985b110000 pid=4443 /usr/bin/rm guuid=e94dc4e6-1a00-0000-fa8a-0298760b0000 pid=2934->guuid=fb100a5e-1d00-0000-fa8a-02985b110000 pid=4443 execve 7b0d3e68-3404-5349-aa2d-de9e9dd9fd4c 103.211.218.101:80 guuid=8d0c5ce7-1a00-0000-fa8a-0298770b0000 pid=2935->7b0d3e68-3404-5349-aa2d-de9e9dd9fd4c send: 141B guuid=ec991c26-1b00-0000-fa8a-0298f60b0000 pid=3062->7b0d3e68-3404-5349-aa2d-de9e9dd9fd4c send: 141B guuid=747bbc66-1b00-0000-fa8a-02987a0c0000 pid=3194->7b0d3e68-3404-5349-aa2d-de9e9dd9fd4c send: 140B guuid=98fadfa3-1b00-0000-fa8a-0298b80c0000 pid=3256->7b0d3e68-3404-5349-aa2d-de9e9dd9fd4c send: 140B guuid=1544e9f1-1b00-0000-fa8a-02983c0d0000 pid=3388 /tmp/yakuza.x86 guuid=e9e6d1f1-1b00-0000-fa8a-02983b0d0000 pid=3387->guuid=1544e9f1-1b00-0000-fa8a-02983c0d0000 pid=3388 clone guuid=e411f0f1-1b00-0000-fa8a-02983d0d0000 pid=3389 /tmp/yakuza.x86 zombie guuid=1544e9f1-1b00-0000-fa8a-02983c0d0000 pid=3388->guuid=e411f0f1-1b00-0000-fa8a-02983d0d0000 pid=3389 clone guuid=62cafcf1-1b00-0000-fa8a-02983f0d0000 pid=3391 /tmp/yakuza.x86 net zombie guuid=e411f0f1-1b00-0000-fa8a-02983d0d0000 pid=3389->guuid=62cafcf1-1b00-0000-fa8a-02983f0d0000 pid=3391 clone fddcfd21-97bd-5f51-9415-03b210fd9508 103.211.218.101:23 guuid=62cafcf1-1b00-0000-fa8a-02983f0d0000 pid=3391->fddcfd21-97bd-5f51-9415-03b210fd9508 con guuid=45fdae18-2400-0000-fa8a-0298dd150000 pid=5597 /tmp/yakuza.x86 net zombie guuid=62cafcf1-1b00-0000-fa8a-02983f0d0000 pid=3391->guuid=45fdae18-2400-0000-fa8a-0298dd150000 pid=5597 clone guuid=13d45bf2-1b00-0000-fa8a-0298410d0000 pid=3393->7b0d3e68-3404-5349-aa2d-de9e9dd9fd4c send: 141B guuid=df654521-1c00-0000-fa8a-0298b90d0000 pid=3513->7b0d3e68-3404-5349-aa2d-de9e9dd9fd4c send: 140B guuid=3ca6f545-1c00-0000-fa8a-0298080e0000 pid=3592 /tmp/yakuza.x32 guuid=314ecc45-1c00-0000-fa8a-0298070e0000 pid=3591->guuid=3ca6f545-1c00-0000-fa8a-0298080e0000 pid=3592 clone guuid=5924ff45-1c00-0000-fa8a-0298090e0000 pid=3593 /tmp/yakuza.x32 guuid=3ca6f545-1c00-0000-fa8a-0298080e0000 pid=3592->guuid=5924ff45-1c00-0000-fa8a-0298090e0000 pid=3593 clone guuid=f6a81746-1c00-0000-fa8a-02980c0e0000 pid=3596 /tmp/yakuza.x32 net zombie guuid=5924ff45-1c00-0000-fa8a-0298090e0000 pid=3593->guuid=f6a81746-1c00-0000-fa8a-02980c0e0000 pid=3596 clone guuid=f6a81746-1c00-0000-fa8a-02980c0e0000 pid=3596->fddcfd21-97bd-5f51-9415-03b210fd9508 con guuid=46780b6e-2400-0000-fa8a-0298de150000 pid=5598 /tmp/yakuza.x32 net zombie guuid=f6a81746-1c00-0000-fa8a-02980c0e0000 pid=3596->guuid=46780b6e-2400-0000-fa8a-0298de150000 pid=5598 clone guuid=d17ccc46-1c00-0000-fa8a-0298100e0000 pid=3600->7b0d3e68-3404-5349-aa2d-de9e9dd9fd4c send: 140B guuid=3cae1b76-1c00-0000-fa8a-02987a0e0000 pid=3706->7b0d3e68-3404-5349-aa2d-de9e9dd9fd4c send: 141B guuid=d8822c9f-1c00-0000-fa8a-0298f80e0000 pid=3832 /tmp/yakuza.i586 guuid=cde6119f-1c00-0000-fa8a-0298f60e0000 pid=3830->guuid=d8822c9f-1c00-0000-fa8a-0298f80e0000 pid=3832 clone guuid=0297339f-1c00-0000-fa8a-0298f90e0000 pid=3833 /tmp/yakuza.i586 guuid=d8822c9f-1c00-0000-fa8a-0298f80e0000 pid=3832->guuid=0297339f-1c00-0000-fa8a-0298f90e0000 pid=3833 clone guuid=c1ad3e9f-1c00-0000-fa8a-0298fb0e0000 pid=3835 /tmp/yakuza.i586 net zombie guuid=0297339f-1c00-0000-fa8a-0298f90e0000 pid=3833->guuid=c1ad3e9f-1c00-0000-fa8a-0298fb0e0000 pid=3835 clone guuid=c1ad3e9f-1c00-0000-fa8a-0298fb0e0000 pid=3835->fddcfd21-97bd-5f51-9415-03b210fd9508 con guuid=416537c7-2400-0000-fa8a-0298df150000 pid=5599 /tmp/yakuza.i586 net zombie guuid=c1ad3e9f-1c00-0000-fa8a-0298fb0e0000 pid=3835->guuid=416537c7-2400-0000-fa8a-0298df150000 pid=5599 clone guuid=ebdba69f-1c00-0000-fa8a-0298fe0e0000 pid=3838->7b0d3e68-3404-5349-aa2d-de9e9dd9fd4c send: 141B guuid=3f4f87db-1c00-0000-fa8a-0298ae0f0000 pid=4014->7b0d3e68-3404-5349-aa2d-de9e9dd9fd4c send: 140B guuid=719d6c0d-1d00-0000-fa8a-029848100000 pid=4168->7b0d3e68-3404-5349-aa2d-de9e9dd9fd4c send: 141B guuid=cbc3db49-1d00-0000-fa8a-029810110000 pid=4368->7b0d3e68-3404-5349-aa2d-de9e9dd9fd4c send: 141B guuid=45fdae18-2400-0000-fa8a-0298dd150000 pid=5597->fddcfd21-97bd-5f51-9415-03b210fd9508 con guuid=46780b6e-2400-0000-fa8a-0298de150000 pid=5598->fddcfd21-97bd-5f51-9415-03b210fd9508 con guuid=416537c7-2400-0000-fa8a-0298df150000 pid=5599->fddcfd21-97bd-5f51-9415-03b210fd9508 con
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2026-01-18 12:05:19 UTC
File Type:
Text (Shell)
AV detection:
24 of 36 (66.67%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt botnet defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
File and Directory Permissions Modification
Executes dropped EXE
Detected Gafgyt variant
Gafgyt family
Gafgyt/Bashlite
Malware Config
C2 Extraction:
103.211.218.101:23
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh f3cde3780136aa469649c5028c4eb3262738579140d03448c618c7ca50cfd7db

(this sample)

  
Delivery method
Distributed via web download

Comments