MALICIOUS — 30c7d351e70323915566d2bb648b4313c9722b34252929a8c7050f6495ae14fc.bin
MALICIOUS — 30c7d351e70323915566d2bb648b4313c9722b34252929a8c7050f6495ae14fc.bin is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Gafgyt family. 5 of 56 detection engines flagged it.
Identification
- SHA-256:
30c7d351e70323915566d2bb648b4313c9722b34252929a8c7050f6495ae14fc - SHA-1:
93f946913eda21f51819c414292bdbdb96750103 - MD5:
77a41fe98558fe16e5eb8a7a85673fc7 - ssdeep:
6144:1EPs11tKvsAB5hVe5rUmqmNjUGsBY7XbkJqh9Zn:d1CB5hVe5rRqmNjUGsBY7XbkJqh9Zn - TLSH:
T17E46B61FF3A2130BE5F46405152355CD67E236CDA67C98AB027332BE20B991F2D1CA66 - Submitted as: 30c7d351e70323915566d2bb648b4313c9722b34252929a8c7050f6495ae14fc.bin
- File type: elf · Size: 304889 bytes
- Verdict: malicious (100/100) · Family: Gafgyt
Source: MalShare · first seen 2026-09-07T19:05:18.627Z · SHA-256 verified
Detections (5 of 56 engines)
- ClamAV (daily): Unix.Trojan.Tsunami-6981155-0
- YARA: ESET research: IIS_Group10
- Microsoft Defender: Backdoor:Linux/DemonBot.Aa!MTB
- Emsisoft (Emergency Kit): Gen:Variant.Linux.Gafgyt.1
- Kaspersky (KVRT): HEUR:Backdoor.Linux.Gafgyt.dd
Why this verdict
The malicious score of 100/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Unix.Trojan.Tsunami-6981155-0 (rule
Unix.Trojan.Tsunami-6981155-0) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 1 finding(s) attributed to the sample across 1 technique(s), e.g. injected region in sample.bin (pid 693) (rule
linux.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - YARA: ESET research flagged IIS_Group10 (rule
IIS_Group10) - engine signal, weight 0.70, confidence 0.70 - Microsoft Defender flagged Backdoor:Linux/DemonBot.Aa!MTB (rule
Backdoor:Linux/DemonBot.Aa!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Linux.Gafgyt.1 (rule
Gen:Variant.Linux.Gafgyt.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Backdoor.Linux.Gafgyt.dd (rule
HEUR:Backdoor.Linux.Gafgyt.dd) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: http://fast.no/support/crawler.asp, http://www.billybobbot.com/crawler/, http://feedback.redkolibri.com/ - static signal, weight 0.35, confidence 0.60
- Contacted 2 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (11 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
261 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- ntp.ubuntu.com
- 131.123.40.104:4444 US · Kent · AS11050 Kent State University
- 127.243.172.180
- 127.243.186.40
- 131.123.40.104 US · Kent · AS11050 Kent State University
- 10.240.0.1
- 185.125.190.58
- ff02::1
- ff02::2
- ff02::16
- ff02::1:ff12:3456
- 255.255.255.255
Embedded URLs
- http://fast.no/support/crawler.asp
- http://www.billybobbot.com/crawler/
- http://feedback.redkolibri.com/
- http://www.baidu.com/search/spider.htm
- http://www.baidu.com/search/spider.html
Embedded domains
- fast.no
- www.thesubot.de
- www.billybobbot.com
- feedback.redkolibri.com
- www.baidu.com
- dayzddos.co
- lolololololdayzddos.co
- example.ulfheim.net
Embedded IP addresses
- 131.123.40.104
- 1.9.1.1
- 1.9.1.3
- 1.9.0.8
- 3.0.4.2
- 1.9.2.8
- 8.8.8.8
- 1.8.1.11
- 1.9.0.6
- 1.9.2.6
- 1.9.2.4
More Gafgyt samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report