MALICIOUS — 9fca540b88a7ea5dc0890c567e844003cdc43977f4a93d7cdee8fdd7f91c2f4b.bin
MALICIOUS — 9fca540b88a7ea5dc0890c567e844003cdc43977f4a93d7cdee8fdd7f91c2f4b.bin is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Gafgyt family. 5 of 57 detection engines flagged it.
Identification
- SHA-256:
9fca540b88a7ea5dc0890c567e844003cdc43977f4a93d7cdee8fdd7f91c2f4b - SHA-1:
9c42e58b8a95872e53c9b5e015d062f22282ea35 - MD5:
0e6204070ea403d2f087a92ba46bb79c - ssdeep:
6144:SMGlBNMdLUFX26KAO65hWsRAqmgjvxK/Lr3rs749OXW:SlBNmUFHKAb5hWkmgjvxK/Lr3rs749Om - TLSH:
T148425A28BCA43781DD8BB44D4206B3EE5D69B77EE82BE60F8371DCA6405096F155022F - Submitted as: 9fca540b88a7ea5dc0890c567e844003cdc43977f4a93d7cdee8fdd7f91c2f4b.bin
- File type: elf · Size: 217737 bytes
- Verdict: malicious (100/100) · Family: Gafgyt
Source: MalShare · first seen 2026-09-07T19:05:18.627Z · SHA-256 verified
Detections (5 of 57 engines)
- ClamAV (daily): Unix.Trojan.Tsunami-6981155-0
- YARA: ESET research: IIS_Group10
- Microsoft Defender: Backdoor:Linux/DemonBot.Aa!MTB
- Emsisoft (Emergency Kit): Gen:Variant.Linux.Gafgyt.1
- Kaspersky (KVRT): HEUR:Backdoor.Linux.Gafgyt.dd
Why this verdict
The malicious score of 100/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Unix.Trojan.Tsunami-6981155-0 (rule
Unix.Trojan.Tsunami-6981155-0) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 1 finding(s) attributed to the sample across 1 technique(s), e.g. injected region in sample.bin (pid 707) (rule
linux.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - YARA: ESET research flagged IIS_Group10 (rule
IIS_Group10) - engine signal, weight 0.70, confidence 0.70 - Microsoft Defender flagged Backdoor:Linux/DemonBot.Aa!MTB (rule
Backdoor:Linux/DemonBot.Aa!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Linux.Gafgyt.1 (rule
Gen:Variant.Linux.Gafgyt.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Backdoor.Linux.Gafgyt.dd (rule
HEUR:Backdoor.Linux.Gafgyt.dd) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: http://fast.no/support/crawler.asp, http://www.billybobbot.com/crawler/, http://feedback.redkolibri.com/ - static signal, weight 0.35, confidence 0.60
- Contacted 2 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (11 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
395 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- ntp.ubuntu.com
- 131.123.40.104:4444 US · Kent · AS11050 Kent State University
- 131.123.40.104 US · Kent · AS11050 Kent State University
- 10.240.0.1
- 185.125.190.58
- ff02::2
- ff02::16
- ff02::1
- ff02::1:ff12:3456
- 255.255.255.255
Embedded URLs
- http://fast.no/support/crawler.asp
- http://www.billybobbot.com/crawler/
- http://feedback.redkolibri.com/
- http://www.baidu.com/search/spider.htm
- http://www.baidu.com/search/spider.html
Embedded domains
- fast.no
- www.thesubot.de
- www.billybobbot.com
- feedback.redkolibri.com
- www.baidu.com
- dayzddos.co
- lolololololdayzddos.co
- example.ulfheim.net
Embedded IP addresses
- 131.123.40.104
- 1.9.1.1
- 1.9.1.3
- 1.9.0.8
- 3.0.4.2
- 1.9.2.8
- 8.8.8.8
- 1.8.1.11
- 1.9.0.6
- 1.9.2.6
- 1.9.2.4
More Gafgyt samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report