MALICIOUS — 04d788870638c10c73140fc9a00cefb7217e1ed6e9ff25468e87e5e3a2cf9c75.elf
MALICIOUS — 04d788870638c10c73140fc9a00cefb7217e1ed6e9ff25468e87e5e3a2cf9c75.elf is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Gafgyt family. 6 of 53 detection engines flagged it.
Identification
- SHA-256:
04d788870638c10c73140fc9a00cefb7217e1ed6e9ff25468e87e5e3a2cf9c75 - SHA-1:
2e0d519960e65f87d085922c0f8387238657d833 - MD5:
16d2205bdf9d9696118fa2cddf5481ef - ssdeep:
768:mYJIB87dgopXz9qP8kz299Ya7TS/0rzBFfKal0:9JIB87dgoRqPhGD7T40r3Rl0 - TLSH:
T18F2EF175825F4455C578699A003EB3ADD6BB3831D620046C90ADA7CBBF042DF836F8AC - Submitted as: 04d788870638c10c73140fc9a00cefb7217e1ed6e9ff25468e87e5e3a2cf9c75.elf
- File type: elf · Size: 29856 bytes
- Verdict: malicious (100/100) · Family: Gafgyt
Source: MalwareBazaar · first seen 2026-07-30T00:00:00.000Z · SHA-256 verified
Detections (6 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Unix.Trojan.Mirai-7775260-0
- YARA: Stratosphere IPS: STRATO_Malicious_UserAgent
- Microsoft Defender: DDoS:Linux/Gafgyt.YA!MTB
- Emsisoft (Emergency Kit): Trojan.Linux.Generic.192355
- Kaspersky (KVRT): HEUR:Exploit.Linux.CVE-2017-17215.a
Why this verdict
The malicious score of 100/100 is the fusion of 11 weighted signals:
- ClamAV (daily) flagged Unix.Trojan.Mirai-7775260-0 (rule
Unix.Trojan.Mirai-7775260-0) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 4 finding(s), e.g. injected region in a (pid 671) (rule
linux.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged DDoS:Linux/Gafgyt.YA!MTB (rule
DDoS:Linux/Gafgyt.YA!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Linux.Generic.192355 (rule
Trojan.Linux.Generic.192355) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Exploit.Linux.CVE-2017-17215.a (rule
HEUR:Exploit.Linux.CVE-2017-17215.a) - engine signal, weight 0.55, confidence 0.85 - 1 IDS alert(s): ThreatLens dynamic-DNS C2 lookup (duckdns) - network signal, weight 0.50, confidence 0.80
- YARA: Stratosphere IPS flagged STRATO_Malicious_UserAgent (rule
STRATO_Malicious_UserAgent) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://upx.sf.net - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 997 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
874 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- ntp.ubuntu.com
- fuckme69.duckdns.org
- desktop-hsgcbep._dosvc._tcp.local
- 192.99.16.52:45999 CA · Vaudreuil-Dorion · AS16276 OVH Hosting, Inc.
- 166.5.135.53 US · AS4155 USDA-1 - USDA, US
- 197.29.135.53
- 70.163.134.53
- 1.40.1.12 AU · Sydney · AS4804 OPTUS INTERNET - RETAIL
- 197.187.134.53 TZ · Airtel Tanzania
- 87.169.116.58
- 156.48.193.12 GB · ICE-2017
- 210.82.31.11
- 197.111.178.58 ZA · Cell C (Pty) Ltd
- 79.232.58.60
- 41.138.223.11
- 19.14.230.142 US · Ford Motor Company
- 197.198.250.10 EG · AS36992 ETISALAT MISR
- 91.113.232.176
- 117.106.124.214 CN · AS4847 CNIX-AP - China Networks Inter-Exchange, CN
- 75.151.134.162
Dropped files
- tmp_tmp.j4ffMhz3S9 -
ab35f6c8ff897772c5fff0daed575fe3948b494d1ef1fe4c89b2bb45dca63dec
Embedded URLs
- http://upx.sf.net
Embedded domains
- upx.sf.net
- fuckme69.duckdns.org
Embedded IP addresses
- 166.5.135.53
- 197.29.135.53
- 70.163.134.53
- 1.40.1.12
- 197.187.134.53
- 87.169.116.58
- 156.48.193.12
- 210.82.31.11
- 197.111.178.58
- 79.232.58.60
- 41.138.223.11
- 19.14.230.142
- 197.198.250.10
- 91.113.232.176
- 117.106.124.214
- 75.151.134.162
- 197.78.103.137
- 156.105.40.176
- 197.191.60.92
- 156.221.183.218
- 61.124.222.33
- 166.17.34.195
- 197.207.71.162
- 41.91.18.209
- 197.119.4.254
More Gafgyt samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report