MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fc762805251333e8c824f3ed52e0171d2e24f06fe527fc43f3c2eb6dad20f15e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: fc762805251333e8c824f3ed52e0171d2e24f06fe527fc43f3c2eb6dad20f15e
SHA3-384 hash: db9d9ca2bbfbce3d42f70ed24a3c9e335c65a6cd9ed3be92120243a41456c8c145eef79e64fa00e32c94b31288cb8598
SHA1 hash: 6f1dad64e2d7655c5abf801fd3e759b359512d77
MD5 hash: 256c6c397c6dd849e0810d4b1d998771
humanhash: florida-florida-uranus-muppet
File name:bins.sh
Download: download sample
Signature Gafgyt
File size:924 bytes
First seen:2025-10-10 21:33:45 UTC
Last seen:2025-10-11 20:38:18 UTC
File type: sh
MIME type:text/plain
ssdeep 24:oqhCIede6eLgNDNFB3aT13K7d+M6+jpCJBCrdgd3:oqhCNND7BHZjPp7rdc3
TLSH T1AF11A7DE126468509026FA093361DC49F86AD2D766478B4F9DFC4EFEE0CCD28F012B85
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://5.253.86.21/GHfjfgvjn/an/aelf ua-wget
http://5.253.86.21/JIPJIPJjn/an/aelf ua-wget
http://5.253.86.21/jhUOHn/an/aelf ua-wget
http://5.253.86.21/RYrydryn/an/aelf ua-wget
http://5.253.86.21/UYyuyioyn/an/aelf ua-wget
http://5.253.86.21/XDzdfxzf1b37a8704c9441ad299d064a8e910ac528deb4efe1c6fb5c4478279f31828e63 Gafgytgafgyt opendir
http://5.253.86.21/JIPJuipjhn/an/aelf ua-wget
http://5.253.86.21/DFhxdhdfn/an/aelf ua-wget
http://5.253.86.21/FDFDHFCn/an/aelf ua-wget
http://5.253.86.21/FTUdftuin/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
43
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
text
First seen:
2025-10-10T19:48:00Z UTC
Last seen:
2025-10-10T20:02:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=dcb8ab84-1a00-0000-6fcc-db50200c0000 pid=3104 /usr/bin/sudo guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111 /tmp/sample.bin guuid=dcb8ab84-1a00-0000-6fcc-db50200c0000 pid=3104->guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111 execve guuid=c5940588-1a00-0000-6fcc-db502a0c0000 pid=3114 /usr/bin/wget net send-data guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=c5940588-1a00-0000-6fcc-db502a0c0000 pid=3114 execve guuid=cbde4b8e-1a00-0000-6fcc-db503a0c0000 pid=3130 /usr/bin/chmod guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=cbde4b8e-1a00-0000-6fcc-db503a0c0000 pid=3130 execve guuid=81f6b58e-1a00-0000-6fcc-db503c0c0000 pid=3132 /usr/bin/dash guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=81f6b58e-1a00-0000-6fcc-db503c0c0000 pid=3132 clone guuid=9ef0d28e-1a00-0000-6fcc-db503d0c0000 pid=3133 /usr/bin/rm guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=9ef0d28e-1a00-0000-6fcc-db503d0c0000 pid=3133 execve guuid=36132c8f-1a00-0000-6fcc-db503f0c0000 pid=3135 /usr/bin/wget net send-data guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=36132c8f-1a00-0000-6fcc-db503f0c0000 pid=3135 execve guuid=f2d57192-1a00-0000-6fcc-db50470c0000 pid=3143 /usr/bin/chmod guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=f2d57192-1a00-0000-6fcc-db50470c0000 pid=3143 execve guuid=afdcda92-1a00-0000-6fcc-db50490c0000 pid=3145 /usr/bin/dash guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=afdcda92-1a00-0000-6fcc-db50490c0000 pid=3145 clone guuid=d2aceb92-1a00-0000-6fcc-db504b0c0000 pid=3147 /usr/bin/rm guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=d2aceb92-1a00-0000-6fcc-db504b0c0000 pid=3147 execve guuid=5e542c93-1a00-0000-6fcc-db504c0c0000 pid=3148 /usr/bin/wget net send-data guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=5e542c93-1a00-0000-6fcc-db504c0c0000 pid=3148 execve guuid=48c5ee97-1a00-0000-6fcc-db50570c0000 pid=3159 /usr/bin/chmod guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=48c5ee97-1a00-0000-6fcc-db50570c0000 pid=3159 execve guuid=51fc3b98-1a00-0000-6fcc-db50590c0000 pid=3161 /usr/bin/dash guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=51fc3b98-1a00-0000-6fcc-db50590c0000 pid=3161 clone guuid=b7155498-1a00-0000-6fcc-db505a0c0000 pid=3162 /usr/bin/rm guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=b7155498-1a00-0000-6fcc-db505a0c0000 pid=3162 execve guuid=647fab98-1a00-0000-6fcc-db505c0c0000 pid=3164 /usr/bin/wget net send-data guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=647fab98-1a00-0000-6fcc-db505c0c0000 pid=3164 execve guuid=8a02d99b-1a00-0000-6fcc-db50600c0000 pid=3168 /usr/bin/chmod guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=8a02d99b-1a00-0000-6fcc-db50600c0000 pid=3168 execve guuid=8284519c-1a00-0000-6fcc-db50630c0000 pid=3171 /usr/bin/dash guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=8284519c-1a00-0000-6fcc-db50630c0000 pid=3171 clone guuid=acb3669c-1a00-0000-6fcc-db50640c0000 pid=3172 /usr/bin/rm guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=acb3669c-1a00-0000-6fcc-db50640c0000 pid=3172 execve guuid=fb51e49c-1a00-0000-6fcc-db50670c0000 pid=3175 /usr/bin/wget net send-data guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=fb51e49c-1a00-0000-6fcc-db50670c0000 pid=3175 execve guuid=732ca5a0-1a00-0000-6fcc-db50700c0000 pid=3184 /usr/bin/chmod guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=732ca5a0-1a00-0000-6fcc-db50700c0000 pid=3184 execve guuid=7ce2faa0-1a00-0000-6fcc-db50710c0000 pid=3185 /usr/bin/dash guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=7ce2faa0-1a00-0000-6fcc-db50710c0000 pid=3185 clone guuid=8fbe0da1-1a00-0000-6fcc-db50720c0000 pid=3186 /usr/bin/rm guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=8fbe0da1-1a00-0000-6fcc-db50720c0000 pid=3186 execve guuid=861154a1-1a00-0000-6fcc-db50740c0000 pid=3188 /usr/bin/wget net send-data write-file guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=861154a1-1a00-0000-6fcc-db50740c0000 pid=3188 execve guuid=a8ba0aa8-1a00-0000-6fcc-db507b0c0000 pid=3195 /usr/bin/chmod guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=a8ba0aa8-1a00-0000-6fcc-db507b0c0000 pid=3195 execve guuid=03fd52a8-1a00-0000-6fcc-db507c0c0000 pid=3196 /home/sandbox/XDzdfxzf net guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=03fd52a8-1a00-0000-6fcc-db507c0c0000 pid=3196 execve guuid=1909b8a9-1a00-0000-6fcc-db507f0c0000 pid=3199 /usr/bin/rm delete-file guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=1909b8a9-1a00-0000-6fcc-db507f0c0000 pid=3199 execve guuid=b37b0eaa-1a00-0000-6fcc-db50800c0000 pid=3200 /usr/bin/wget net send-data guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=b37b0eaa-1a00-0000-6fcc-db50800c0000 pid=3200 execve guuid=9674b6ad-1a00-0000-6fcc-db50810c0000 pid=3201 /usr/bin/chmod guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=9674b6ad-1a00-0000-6fcc-db50810c0000 pid=3201 execve guuid=ac6017ae-1a00-0000-6fcc-db50820c0000 pid=3202 /usr/bin/dash guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=ac6017ae-1a00-0000-6fcc-db50820c0000 pid=3202 clone guuid=629027ae-1a00-0000-6fcc-db50830c0000 pid=3203 /usr/bin/rm guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=629027ae-1a00-0000-6fcc-db50830c0000 pid=3203 execve guuid=0d0a82ae-1a00-0000-6fcc-db50840c0000 pid=3204 /usr/bin/wget net send-data guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=0d0a82ae-1a00-0000-6fcc-db50840c0000 pid=3204 execve guuid=d5ac01b4-1a00-0000-6fcc-db50850c0000 pid=3205 /usr/bin/chmod guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=d5ac01b4-1a00-0000-6fcc-db50850c0000 pid=3205 execve guuid=64495cb4-1a00-0000-6fcc-db50860c0000 pid=3206 /usr/bin/dash guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=64495cb4-1a00-0000-6fcc-db50860c0000 pid=3206 clone guuid=da8875b4-1a00-0000-6fcc-db50870c0000 pid=3207 /usr/bin/rm guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=da8875b4-1a00-0000-6fcc-db50870c0000 pid=3207 execve guuid=32f2c1b4-1a00-0000-6fcc-db50880c0000 pid=3208 /usr/bin/wget net send-data guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=32f2c1b4-1a00-0000-6fcc-db50880c0000 pid=3208 execve guuid=f9a4a4b7-1a00-0000-6fcc-db50890c0000 pid=3209 /usr/bin/chmod guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=f9a4a4b7-1a00-0000-6fcc-db50890c0000 pid=3209 execve guuid=023b24b8-1a00-0000-6fcc-db508b0c0000 pid=3211 /usr/bin/dash guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=023b24b8-1a00-0000-6fcc-db508b0c0000 pid=3211 clone guuid=f4b136b8-1a00-0000-6fcc-db508c0c0000 pid=3212 /usr/bin/rm guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=f4b136b8-1a00-0000-6fcc-db508c0c0000 pid=3212 execve guuid=58fdb9b8-1a00-0000-6fcc-db508d0c0000 pid=3213 /usr/bin/wget net send-data guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=58fdb9b8-1a00-0000-6fcc-db508d0c0000 pid=3213 execve guuid=3d2884bb-1a00-0000-6fcc-db50930c0000 pid=3219 /usr/bin/chmod guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=3d2884bb-1a00-0000-6fcc-db50930c0000 pid=3219 execve guuid=8bdecbbb-1a00-0000-6fcc-db50950c0000 pid=3221 /usr/bin/dash guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=8bdecbbb-1a00-0000-6fcc-db50950c0000 pid=3221 clone guuid=8c7dd7bb-1a00-0000-6fcc-db50960c0000 pid=3222 /usr/bin/rm guuid=964c9487-1a00-0000-6fcc-db50270c0000 pid=3111->guuid=8c7dd7bb-1a00-0000-6fcc-db50960c0000 pid=3222 execve 4ae8723e-9585-54ee-ab1f-aea28f023f45 5.253.86.21:80 guuid=c5940588-1a00-0000-6fcc-db502a0c0000 pid=3114->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 134B guuid=36132c8f-1a00-0000-6fcc-db503f0c0000 pid=3135->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 134B guuid=5e542c93-1a00-0000-6fcc-db504c0c0000 pid=3148->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 131B guuid=647fab98-1a00-0000-6fcc-db505c0c0000 pid=3164->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 133B guuid=fb51e49c-1a00-0000-6fcc-db50670c0000 pid=3175->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 134B guuid=861154a1-1a00-0000-6fcc-db50740c0000 pid=3188->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 134B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=03fd52a8-1a00-0000-6fcc-db507c0c0000 pid=3196->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=396f70a9-1a00-0000-6fcc-db507d0c0000 pid=3197 /home/sandbox/XDzdfxzf guuid=03fd52a8-1a00-0000-6fcc-db507c0c0000 pid=3196->guuid=396f70a9-1a00-0000-6fcc-db507d0c0000 pid=3197 clone guuid=9c187ba9-1a00-0000-6fcc-db507e0c0000 pid=3198 /home/sandbox/XDzdfxzf net zombie guuid=396f70a9-1a00-0000-6fcc-db507d0c0000 pid=3197->guuid=9c187ba9-1a00-0000-6fcc-db507e0c0000 pid=3198 clone f0d97fb7-0397-5b22-995a-c399d2108b29 5.253.86.21:23 guuid=9c187ba9-1a00-0000-6fcc-db507e0c0000 pid=3198->f0d97fb7-0397-5b22-995a-c399d2108b29 con guuid=b37b0eaa-1a00-0000-6fcc-db50800c0000 pid=3200->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 135B guuid=0d0a82ae-1a00-0000-6fcc-db50840c0000 pid=3204->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 134B guuid=32f2c1b4-1a00-0000-6fcc-db50880c0000 pid=3208->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 133B guuid=58fdb9b8-1a00-0000-6fcc-db508d0c0000 pid=3213->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 134B
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2025-10-10 21:35:48 UTC
File Type:
Text (Shell)
AV detection:
15 of 31 (48.39%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh fc762805251333e8c824f3ed52e0171d2e24f06fe527fc43f3c2eb6dad20f15e

(this sample)

  
Delivery method
Distributed via web download

Comments