MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f8d17d3c1ccd40d0e9097ee366e264adb3a4e906c8af1c73c08651cd75bfcd5b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: f8d17d3c1ccd40d0e9097ee366e264adb3a4e906c8af1c73c08651cd75bfcd5b
SHA3-384 hash: 997e2a24b5add8f1a077bc8d940779f60ee815b56b696e8343e3d1ff5da4cd5a8e8480cd7f6d6542fd61e9e49a98f955
SHA1 hash: db116c890c4154f7c65e6f1439240cb7411f6f1e
MD5 hash: 18c3b37f1e1e02bcf7b54807263b20e5
humanhash: cold-december-virginia-massachusetts
File name:g.sh
Download: download sample
Signature Gafgyt
File size:379 bytes
First seen:2025-05-07 17:27:18 UTC
Last seen:2025-05-08 11:49:59 UTC
File type: sh
MIME type:text/plain
ssdeep 6:ebgfr3w5/KjUAFjbKTRUCOGjFIcMgFuIcMgNLaFQ/TIcMzFuIcMzaGpQ3FQi:3rWKIw+9UCFjecMg7cMgcfcMz7cMzNpo
TLSH T1D2E068DD64E0F92090812ED3B324893ABEC6CA4A65C00E5880CE2473D80CC2CB6D9E77
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.149.29.68/gmips08a64007c9c4ea40fbad510fcb172bfb9fccfb56bfc5fec5e470069776c42553 Gafgytcensys elf gafgyt ua-wget
http://103.149.29.68/gmpsl619fe32d388a495a0d238e85d0eac6408f81a680bace689d9e6b5378d82086e0 Gafgytcensys elf gafgyt ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
85
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh f8d17d3c1ccd40d0e9097ee366e264adb3a4e906c8af1c73c08651cd75bfcd5b

(this sample)

  
Delivery method
Distributed via web download

Comments