VT-56dffc636aa06a4a6c000f8cc1692b5294f35fb890be81461e5ddcfd678e
high
📛 Threat Title
VirusTotal: 56dffc636aa06a4a6c000f8cc1692b5294f35fb890be81461e5ddcfd678e0b42
Description
VirusTotal verdict: 11 malicious / 0 suspicious of 75 engines. Suggested label: trojan.gafgyt.
Indicators of Compromise (2)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
56dffc636aa06a4a6c000f8cc1692b5294f35fb890be81461e5ddcfd678e0b42
VT 32 / 75
1 feed
IOC database
- Type
- hash_sha256
- Value
56dffc636aa06a4a6c000f8cc1692b5294f35fb890be81461e5ddcfd678e0b42- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- Unknown
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 32 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Backdoor:Linux/Gafgyt_AGen.IL |
| Arcabit | malicious | Trojan.Generic.D261BD89 |
| Avast | malicious | Other:Malware-gen [Trj] |
| AVG | malicious | Other:Malware-gen [Trj] |
| Avira | malicious | TR/Malware |
| BitDefender | malicious | Trojan.Generic.39959945 |
| CTX | malicious | elf.trojan.gafgyt |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.DDoS.2637 |
| Emsisoft | malicious | Trojan.Generic.39959945 (B) |
| ESET-NOD32 | malicious | Linux/Gafgyt.BSP trojan |
| F-Secure | malicious | Trojan.TR/Malware |
| Fortinet | malicious | Linux/Gafgyt_AGen.II!tr |
| GData | malicious | Trojan.Generic.39959945 |
| malicious | Detected |
|
| huorong | malicious | Trojan/Linux.Mirai.l!crit |
| Ikarus | malicious | Trojan.Linux.Gafgyt |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Gafgyt.bj |
| Kingsoft | malicious | Linux.Backdoor.Gafgyt.bj |
| Lionic | malicious | Trojan.Linux.Gafgyt.4!c |
| McAfeeD | malicious | ti!56DFFC636AA0 |
| Microsoft | malicious | Backdoor:Linux/Mirai!MSR |
| MicroWorld-eScan | malicious | Trojan.Generic.39959945 |
| Rising | malicious | Malware.Undefined!8.C (TFE:14:dXqhJLc5KjI) |
| Sangfor | malicious | Trojan.Linux.Mirai.Vz4k |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Trojan.Gen.NPE |
| TrendMicro | malicious | Trojan.Linux.GAFGYT.TL0101EF26ZZ |
| TrendMicro-HouseCall | malicious | Trojan.Linux.GAFGYT.TL0101EF26ZZ |
| Varist | malicious | E64/ABBackdoor.APME- |
| VIPRE | malicious | Trojan.Generic.39959945 |
Details From VirusTotal
Basic Properties
| MD5 | 415bb341906ae36f16d842466c001f4b |
| SHA-1 | 1535deacd449d016fdb39ded8b21a90342350f71 |
| SHA-256 | 56dffc636aa06a4a6c000f8cc1692b5294f35fb890be81461e5ddcfd678e0b42 |
| VHash | fa8717567470e1eaeba7511765fe150f |
| SSDEEP | 1536:5I0rNXsKxIgE9wDBmT8i1Jt7ZZ8OAIbxbm8/V1Wf1+gv/rmbpx69:ycxsKlBrA7P8Ol0nrm |
| TLSH | T141838D808C1DFCB3CBC6B47D4D480E50326B7CF42678D74A0A25668EDC49A586FE5BA7 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 64-bit LSB executable, ARM aarch64, version 1 (SYSV), statically linked, stripped |
| File size | 81.0 KB |
History
| First seen on VirusTotal | 2026-05-13 19:24 UTC |
| Last submission | 2026-05-13 19:24 UTC |
| Last analysis | 2026-05-15 16:27 UTC |
| Last modified on VirusTotal | 2026-05-15 18:36 UTC |
Known Names
56dffc636aa06a4a6c000f8cc1692b5294f35fb890be81461e5ddcfd678e0b42.elfbot.aarch64wsfo0b.exe
domain
trojan.gafgyt
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/trojan.gafgyt
IOC database
- Type
- domain
- Value
trojan.gafgyt- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat VT-56dffc636aa06a4a6c000f8cc1692b5294f35fb890be81461e5ddcfd678e
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/trojan.gafgyt
References (1)
-
VirusTotal report
VirusTotal verdict: 11 malicious / 0 suspicious of 75 engines. Suggested label: trojan.gafgyt.
Remediations (10)
-
web:blog.virustotal.com
The VirusTotal dataset, the backbone of the platform, structures artifact-related information into objects and represents relevant relationships between them, providing contextual links between various artifacts. This makes VirusTotal a valuable resource for threat research, enabling users to perform activities such as clustering artifacts related to specific threat actors or campaigns ...
-
web:docs.virustotal.com
Here are the key elements of VirusTotal reports. We'll look at a typical URL report first, then a typical report for files. The last two sections will focus on domain and IP address reports. URL Report Summary URL Report Details File Report Summary File Report Details Domain and IP address reports U…
-
web:docs.virustotal.com
Searching for IP address information VirusTotal runs its own passive DNS replication service, built by storing the DNS resolutions performed as we visit URLs and execute malware samples submitted by users. To retrieve the information we have on a given IP address, just type it into the search box.
-
web:en.wikipedia.org
VirusTotal is a website created by the Spanish security company Hispasec Sistemas. Launched in June 2004, it was acquired by Google in September 2012. [1][2][3] The company's ownership switched in January 2018 to Google Security Operations, a subsidiary of Google.
-
web:gtidocs.virustotal.com
How to perform file searches Google Threat Intelligence allows you to search through our dataset in order to identify files that match certain criteria (hash, antivirus detections, metadata, submission file names, file format structural properties, file size, etc.). We could say that it is pretty m…
-
web:www.cisa.gov
VirusTotal inspects items with over 70 antivirus scanners and URL/domain blocklisting services, in addition to a variety of tools, to extract signals from the studied content.
-
web:www.virustotal.com
VirusTotal Assistant Bot offers a platform for users to interact with VirusTotal's threat intelligence suite and explore artifact-related information effectively.
-
web:www.virustotal.com
VirusTotal is a free online service for scanning files and URLs for viruses, malware, and other malicious content using multiple antivirus solutions.
-
web:www.virustotal.com
VirusTotal is a free online tool for scanning files and URLs for viruses and malware using multiple antivirus solutions.
-
web:www.virustotal.com
VirusTotal is a free virus, malware and URL online scanning service. File checking is done with more than 40 antivirus solutions. Files and URLs can be sent via web interface upload, email API or making use of VirusTotal's browser extensions and desktop applications.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.