s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

VT-56dffc636aa06a4a6c000f8cc1692b5294f35fb890be81461e5ddcfd678e high

📛 Threat Title

VirusTotal: 56dffc636aa06a4a6c000f8cc1692b5294f35fb890be81461e5ddcfd678e0b42

Category: ioc First seen: Last updated:

Description

VirusTotal verdict: 11 malicious / 0 suspicious of 75 engines. Suggested label: trojan.gafgyt.

Indicators of Compromise (2)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 56dffc636aa06a4a6c000f8cc1692b5294f35fb890be81461e5ddcfd678e0b42 VT 32 / 75 1 feed

IOC database

Type
hash_sha256
Value
56dffc636aa06a4a6c000f8cc1692b5294f35fb890be81461e5ddcfd678e0b42
First seen
Last seen
Attached to this threat
Appears in
3 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Flagged by 32 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious Backdoor:Linux/Gafgyt_AGen.IL
Arcabit malicious Trojan.Generic.D261BD89
Avast malicious Other:Malware-gen [Trj]
AVG malicious Other:Malware-gen [Trj]
Avira malicious TR/Malware
BitDefender malicious Trojan.Generic.39959945
CTX malicious elf.trojan.gafgyt
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.DDoS.2637
Emsisoft malicious Trojan.Generic.39959945 (B)
ESET-NOD32 malicious Linux/Gafgyt.BSP trojan
F-Secure malicious Trojan.TR/Malware
Fortinet malicious Linux/Gafgyt_AGen.II!tr
GData malicious Trojan.Generic.39959945
Google malicious Detected
huorong malicious Trojan/Linux.Mirai.l!crit
Ikarus malicious Trojan.Linux.Gafgyt
Kaspersky malicious HEUR:Backdoor.Linux.Gafgyt.bj
Kingsoft malicious Linux.Backdoor.Gafgyt.bj
Lionic malicious Trojan.Linux.Gafgyt.4!c
McAfeeD malicious ti!56DFFC636AA0
Microsoft malicious Backdoor:Linux/Mirai!MSR
MicroWorld-eScan malicious Trojan.Generic.39959945
Rising malicious Malware.Undefined!8.C (TFE:14:dXqhJLc5KjI)
Sangfor malicious Trojan.Linux.Mirai.Vz4k
SentinelOne malicious Static AI - Malicious ELF
Sophos malicious Mal/Generic-S
Symantec malicious Trojan.Gen.NPE
TrendMicro malicious Trojan.Linux.GAFGYT.TL0101EF26ZZ
TrendMicro-HouseCall malicious Trojan.Linux.GAFGYT.TL0101EF26ZZ
Varist malicious E64/ABBackdoor.APME-
VIPRE malicious Trojan.Generic.39959945

Details From VirusTotal

Basic Properties
MD5415bb341906ae36f16d842466c001f4b
SHA-11535deacd449d016fdb39ded8b21a90342350f71
SHA-25656dffc636aa06a4a6c000f8cc1692b5294f35fb890be81461e5ddcfd678e0b42
VHashfa8717567470e1eaeba7511765fe150f
SSDEEP1536:5I0rNXsKxIgE9wDBmT8i1Jt7ZZ8OAIbxbm8/V1Wf1+gv/rmbpx69:ycxsKlBrA7P8Ol0nrm
TLSHT141838D808C1DFCB3CBC6B47D4D480E50326B7CF42678D74A0A25668EDC49A586FE5BA7
File typeELF
File type tagelf
MagicELF 64-bit LSB executable, ARM aarch64, version 1 (SYSV), statically linked, stripped
File size81.0 KB
History
First seen on VirusTotal2026-05-13 19:24 UTC
Last submission2026-05-13 19:24 UTC
Last analysis2026-05-15 16:27 UTC
Last modified on VirusTotal2026-05-15 18:36 UTC
Known Names
  • 56dffc636aa06a4a6c000f8cc1692b5294f35fb890be81461e5ddcfd678e0b42.elf
  • bot.aarch64
  • wsfo0b.exe
domain trojan.gafgyt VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/trojan.gafgyt

IOC database

Type
domain
Value
trojan.gafgyt
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat VT-56dffc636aa06a4a6c000f8cc1692b5294f35fb890be81461e5ddcfd678e

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/trojan.gafgyt

References (1)

  • VirusTotal report

    VirusTotal verdict: 11 malicious / 0 suspicious of 75 engines. Suggested label: trojan.gafgyt.

Remediations (10)

  • web:blog.virustotal.com

    The VirusTotal dataset, the backbone of the platform, structures artifact-related information into objects and represents relevant relationships between them, providing contextual links between various artifacts. This makes VirusTotal a valuable resource for threat research, enabling users to perform activities such as clustering artifacts related to specific threat actors or campaigns ...

  • web:docs.virustotal.com

    Here are the key elements of VirusTotal reports. We'll look at a typical URL report first, then a typical report for files. The last two sections will focus on domain and IP address reports. URL Report Summary URL Report Details File Report Summary File Report Details Domain and IP address reports U…

  • web:docs.virustotal.com

    Searching for IP address information VirusTotal runs its own passive DNS replication service, built by storing the DNS resolutions performed as we visit URLs and execute malware samples submitted by users. To retrieve the information we have on a given IP address, just type it into the search box.

  • web:en.wikipedia.org

    VirusTotal is a website created by the Spanish security company Hispasec Sistemas. Launched in June 2004, it was acquired by Google in September 2012. [1][2][3] The company's ownership switched in January 2018 to Google Security Operations, a subsidiary of Google.

  • web:gtidocs.virustotal.com

    How to perform file searches Google Threat Intelligence allows you to search through our dataset in order to identify files that match certain criteria (hash, antivirus detections, metadata, submission file names, file format structural properties, file size, etc.). We could say that it is pretty m…

  • web:www.cisa.gov

    VirusTotal inspects items with over 70 antivirus scanners and URL/domain blocklisting services, in addition to a variety of tools, to extract signals from the studied content.

  • web:www.virustotal.com

    VirusTotal Assistant Bot offers a platform for users to interact with VirusTotal's threat intelligence suite and explore artifact-related information effectively.

  • web:www.virustotal.com

    VirusTotal is a free online service for scanning files and URLs for viruses, malware, and other malicious content using multiple antivirus solutions.

  • web:www.virustotal.com

    VirusTotal is a free online tool for scanning files and URLs for viruses and malware using multiple antivirus solutions.

  • web:www.virustotal.com

    VirusTotal is a free virus, malware and URL online scanning service. File checking is done with more than 40 antivirus solutions. Files and URLs can be sent via web interface upload, email API or making use of VirusTotal's browser extensions and desktop applications.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.