MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 03bf8b6610e81d015f5e0e6023281b232b8d32e8510cef333f9f9eb8af1b4bde. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 03bf8b6610e81d015f5e0e6023281b232b8d32e8510cef333f9f9eb8af1b4bde
SHA3-384 hash: b3d4c5630fb20dbdafb56feae37f45139fdd465696396c94914e745bc33adc569a759aaff3d6ec6a0ea7bbfff75e462c
SHA1 hash: 2c260624e6ed3233a43a3b65e6171878087f1fbb
MD5 hash: fb069c04329d34c178e9b286ef844732
humanhash: quebec-helium-yellow-oregon
File name:cat.sh
Download: download sample
File size:1'433 bytes
First seen:2026-02-17 17:12:59 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:TAl2atCr2Qdgyufm1B4ZNO47ONnfWkMznYFf410+3EC404KtSdSd:TA8atcfdgzfmf4ZE47an+FznYFf410+3
TLSH T14421F4EE589588F2010DCE6AFA71D75850CC8BEFB85B2F42D9D8ACF19E91D05B034B15
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
50
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Gathering data
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
bash lolbin
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.cx
Status:
terminated
Behavior Graph:
%3 guuid=8632921f-1800-0000-1cff-7923dc050000 pid=1500 /usr/bin/sudo guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507 /tmp/sample.bin guuid=8632921f-1800-0000-1cff-7923dc050000 pid=1500->guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507 execve guuid=6b744922-1800-0000-1cff-7923e5050000 pid=1509 /usr/bin/wget net send-data write-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=6b744922-1800-0000-1cff-7923e5050000 pid=1509 execve guuid=b66be95f-1800-0000-1cff-79238d060000 pid=1677 /usr/bin/curl net send-data write-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=b66be95f-1800-0000-1cff-79238d060000 pid=1677 execve guuid=227bd09f-1800-0000-1cff-7923ff060000 pid=1791 /usr/bin/chmod guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=227bd09f-1800-0000-1cff-7923ff060000 pid=1791 execve guuid=51b147a0-1800-0000-1cff-792300070000 pid=1792 /home/sandbox/x86_64 guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=51b147a0-1800-0000-1cff-792300070000 pid=1792 execve guuid=9f89a3a0-1800-0000-1cff-792302070000 pid=1794 /usr/bin/rm delete-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=9f89a3a0-1800-0000-1cff-792302070000 pid=1794 execve guuid=d5a917a1-1800-0000-1cff-792304070000 pid=1796 /usr/bin/wget net send-data write-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=d5a917a1-1800-0000-1cff-792304070000 pid=1796 execve guuid=792bdad5-1800-0000-1cff-79237b070000 pid=1915 /usr/bin/curl net send-data write-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=792bdad5-1800-0000-1cff-79237b070000 pid=1915 execve guuid=63e91f0d-1900-0000-1cff-7923ce070000 pid=1998 /usr/bin/chmod guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=63e91f0d-1900-0000-1cff-7923ce070000 pid=1998 execve guuid=162a8d0d-1900-0000-1cff-7923d0070000 pid=2000 /usr/bin/bash guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=162a8d0d-1900-0000-1cff-7923d0070000 pid=2000 clone guuid=a99dbc0f-1900-0000-1cff-7923d5070000 pid=2005 /usr/bin/rm delete-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=a99dbc0f-1900-0000-1cff-7923d5070000 pid=2005 execve guuid=54151110-1900-0000-1cff-7923d6070000 pid=2006 /usr/bin/wget net send-data write-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=54151110-1900-0000-1cff-7923d6070000 pid=2006 execve guuid=d9c6e33d-1900-0000-1cff-792339080000 pid=2105 /usr/bin/curl net send-data write-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=d9c6e33d-1900-0000-1cff-792339080000 pid=2105 execve guuid=f78e5d76-1900-0000-1cff-7923ca080000 pid=2250 /usr/bin/chmod guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=f78e5d76-1900-0000-1cff-7923ca080000 pid=2250 execve guuid=6bb7a376-1900-0000-1cff-7923cb080000 pid=2251 /usr/bin/bash guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=6bb7a376-1900-0000-1cff-7923cb080000 pid=2251 clone guuid=76a10778-1900-0000-1cff-7923d0080000 pid=2256 /usr/bin/rm delete-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=76a10778-1900-0000-1cff-7923d0080000 pid=2256 execve guuid=92eafa7c-1900-0000-1cff-7923d2080000 pid=2258 /usr/bin/wget net send-data write-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=92eafa7c-1900-0000-1cff-7923d2080000 pid=2258 execve guuid=b676b6b0-1900-0000-1cff-792335090000 pid=2357 /usr/bin/curl net send-data write-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=b676b6b0-1900-0000-1cff-792335090000 pid=2357 execve guuid=2cc9a5ea-1900-0000-1cff-7923ab090000 pid=2475 /usr/bin/chmod guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=2cc9a5ea-1900-0000-1cff-7923ab090000 pid=2475 execve guuid=010f14eb-1900-0000-1cff-7923ad090000 pid=2477 /usr/bin/bash guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=010f14eb-1900-0000-1cff-7923ad090000 pid=2477 clone guuid=c26e3ded-1900-0000-1cff-7923b5090000 pid=2485 /usr/bin/rm delete-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=c26e3ded-1900-0000-1cff-7923b5090000 pid=2485 execve guuid=8f02afed-1900-0000-1cff-7923b8090000 pid=2488 /usr/bin/wget net send-data write-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=8f02afed-1900-0000-1cff-7923b8090000 pid=2488 execve guuid=e6f74c23-1a00-0000-1cff-7923360a0000 pid=2614 /usr/bin/curl net send-data write-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=e6f74c23-1a00-0000-1cff-7923360a0000 pid=2614 execve guuid=a9a9ca62-1a00-0000-1cff-7923d60a0000 pid=2774 /usr/bin/chmod guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=a9a9ca62-1a00-0000-1cff-7923d60a0000 pid=2774 execve guuid=41ea1763-1a00-0000-1cff-7923d80a0000 pid=2776 /home/sandbox/i686 guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=41ea1763-1a00-0000-1cff-7923d80a0000 pid=2776 execve guuid=e0024d63-1a00-0000-1cff-7923da0a0000 pid=2778 /usr/bin/rm delete-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=e0024d63-1a00-0000-1cff-7923da0a0000 pid=2778 execve guuid=72dbc563-1a00-0000-1cff-7923dc0a0000 pid=2780 /usr/bin/wget net send-data write-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=72dbc563-1a00-0000-1cff-7923dc0a0000 pid=2780 execve guuid=2a188b97-1a00-0000-1cff-79232f0b0000 pid=2863 /usr/bin/curl net send-data write-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=2a188b97-1a00-0000-1cff-79232f0b0000 pid=2863 execve guuid=18a8a2cd-1a00-0000-1cff-7923860b0000 pid=2950 /usr/bin/chmod guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=18a8a2cd-1a00-0000-1cff-7923860b0000 pid=2950 execve guuid=ba0b0fce-1a00-0000-1cff-7923870b0000 pid=2951 /usr/bin/bash guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=ba0b0fce-1a00-0000-1cff-7923870b0000 pid=2951 clone guuid=1109c8ce-1a00-0000-1cff-79238a0b0000 pid=2954 /usr/bin/rm delete-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=1109c8ce-1a00-0000-1cff-79238a0b0000 pid=2954 execve guuid=4a140ccf-1a00-0000-1cff-79238c0b0000 pid=2956 /usr/bin/wget net send-data write-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=4a140ccf-1a00-0000-1cff-79238c0b0000 pid=2956 execve guuid=b6be900a-1b00-0000-1cff-79230b0c0000 pid=3083 /usr/bin/curl net send-data write-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=b6be900a-1b00-0000-1cff-79230b0c0000 pid=3083 execve guuid=3ad5a242-1b00-0000-1cff-7923860c0000 pid=3206 /usr/bin/chmod guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=3ad5a242-1b00-0000-1cff-7923860c0000 pid=3206 execve guuid=53821843-1b00-0000-1cff-7923870c0000 pid=3207 /usr/bin/bash guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=53821843-1b00-0000-1cff-7923870c0000 pid=3207 clone guuid=cd195044-1b00-0000-1cff-7923890c0000 pid=3209 /usr/bin/rm delete-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=cd195044-1b00-0000-1cff-7923890c0000 pid=3209 execve guuid=234ee550-1b00-0000-1cff-79238a0c0000 pid=3210 /usr/bin/wget net send-data write-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=234ee550-1b00-0000-1cff-79238a0c0000 pid=3210 execve guuid=c56c4a85-1b00-0000-1cff-7923ba0c0000 pid=3258 /usr/bin/curl net send-data write-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=c56c4a85-1b00-0000-1cff-7923ba0c0000 pid=3258 execve guuid=f3cf72c0-1b00-0000-1cff-79231b0d0000 pid=3355 /usr/bin/chmod guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=f3cf72c0-1b00-0000-1cff-79231b0d0000 pid=3355 execve guuid=49ebd5c0-1b00-0000-1cff-79231c0d0000 pid=3356 /usr/bin/bash guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=49ebd5c0-1b00-0000-1cff-79231c0d0000 pid=3356 clone guuid=565781c1-1b00-0000-1cff-79231f0d0000 pid=3359 /usr/bin/rm delete-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=565781c1-1b00-0000-1cff-79231f0d0000 pid=3359 execve guuid=97dac9d0-1b00-0000-1cff-7923250d0000 pid=3365 /usr/bin/wget net send-data write-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=97dac9d0-1b00-0000-1cff-7923250d0000 pid=3365 execve guuid=c1b99a0d-1c00-0000-1cff-79238d0d0000 pid=3469 /usr/bin/curl net send-data write-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=c1b99a0d-1c00-0000-1cff-79238d0d0000 pid=3469 execve guuid=877dad4a-1c00-0000-1cff-7923140e0000 pid=3604 /usr/bin/chmod guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=877dad4a-1c00-0000-1cff-7923140e0000 pid=3604 execve guuid=28161a4b-1c00-0000-1cff-7923150e0000 pid=3605 /usr/bin/bash guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=28161a4b-1c00-0000-1cff-7923150e0000 pid=3605 clone guuid=85282c4c-1c00-0000-1cff-79231a0e0000 pid=3610 /usr/bin/rm delete-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=85282c4c-1c00-0000-1cff-79231a0e0000 pid=3610 execve guuid=0330ad4c-1c00-0000-1cff-79231b0e0000 pid=3611 /usr/bin/wget net send-data write-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=0330ad4c-1c00-0000-1cff-79231b0e0000 pid=3611 execve guuid=0963fa89-1c00-0000-1cff-7923d00e0000 pid=3792 /usr/bin/curl net send-data write-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=0963fa89-1c00-0000-1cff-7923d00e0000 pid=3792 execve guuid=159ad4c8-1c00-0000-1cff-7923900f0000 pid=3984 /usr/bin/chmod guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=159ad4c8-1c00-0000-1cff-7923900f0000 pid=3984 execve guuid=9b043ac9-1c00-0000-1cff-7923920f0000 pid=3986 /usr/bin/bash guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=9b043ac9-1c00-0000-1cff-7923920f0000 pid=3986 clone guuid=e75df6c9-1c00-0000-1cff-7923950f0000 pid=3989 /usr/bin/rm delete-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=e75df6c9-1c00-0000-1cff-7923950f0000 pid=3989 execve guuid=d5a873d7-1c00-0000-1cff-7923b20f0000 pid=4018 /usr/bin/wget net send-data write-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=d5a873d7-1c00-0000-1cff-7923b20f0000 pid=4018 execve guuid=c8100d16-1d00-0000-1cff-792377100000 pid=4215 /usr/bin/curl net send-data write-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=c8100d16-1d00-0000-1cff-792377100000 pid=4215 execve guuid=297d614d-1d00-0000-1cff-79232c110000 pid=4396 /usr/bin/chmod guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=297d614d-1d00-0000-1cff-79232c110000 pid=4396 execve guuid=a979be4d-1d00-0000-1cff-79232e110000 pid=4398 /usr/bin/bash guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=a979be4d-1d00-0000-1cff-79232e110000 pid=4398 clone guuid=feaab54e-1d00-0000-1cff-792333110000 pid=4403 /usr/bin/rm delete-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=feaab54e-1d00-0000-1cff-792333110000 pid=4403 execve guuid=b1f5fe4e-1d00-0000-1cff-792334110000 pid=4404 /usr/bin/wget net send-data write-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=b1f5fe4e-1d00-0000-1cff-792334110000 pid=4404 execve guuid=c9928674-1d00-0000-1cff-7923c1110000 pid=4545 /usr/bin/curl net send-data write-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=c9928674-1d00-0000-1cff-7923c1110000 pid=4545 execve guuid=262d4fc9-1d00-0000-1cff-79237b120000 pid=4731 /usr/bin/chmod guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=262d4fc9-1d00-0000-1cff-79237b120000 pid=4731 execve guuid=7922b5c9-1d00-0000-1cff-79237d120000 pid=4733 /usr/bin/bash guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=7922b5c9-1d00-0000-1cff-79237d120000 pid=4733 clone guuid=ef68ebca-1d00-0000-1cff-792384120000 pid=4740 /usr/bin/rm delete-file guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=ef68ebca-1d00-0000-1cff-792384120000 pid=4740 execve guuid=fa663acb-1d00-0000-1cff-792387120000 pid=4743 /usr/bin/bash zombie guuid=3314d921-1800-0000-1cff-7923e3050000 pid=1507->guuid=fa663acb-1d00-0000-1cff-792387120000 pid=4743 clone 3615a721-482b-529f-8629-91d00c8ecbda 172.86.114.147:80 guuid=6b744922-1800-0000-1cff-7923e5050000 pid=1509->3615a721-482b-529f-8629-91d00c8ecbda send: 135B guuid=b66be95f-1800-0000-1cff-79238d060000 pid=1677->3615a721-482b-529f-8629-91d00c8ecbda send: 84B guuid=bcc291a0-1800-0000-1cff-792301070000 pid=1793 /home/sandbox/x86_64 net write-file zombie guuid=51b147a0-1800-0000-1cff-792300070000 pid=1792->guuid=bcc291a0-1800-0000-1cff-792301070000 pid=1793 clone b073fe87-9890-5da3-8993-46d9b6b951c9 172.86.114.147:1150 guuid=bcc291a0-1800-0000-1cff-792301070000 pid=1793->b073fe87-9890-5da3-8993-46d9b6b951c9 con guuid=bcc291a0-1800-0000-1cff-792301070000 pid=1795 /home/sandbox/x86_64 guuid=bcc291a0-1800-0000-1cff-792301070000 pid=1793->guuid=bcc291a0-1800-0000-1cff-792301070000 pid=1795 clone guuid=d5a917a1-1800-0000-1cff-792304070000 pid=1796->3615a721-482b-529f-8629-91d00c8ecbda send: 136B guuid=792bdad5-1800-0000-1cff-79237b070000 pid=1915->3615a721-482b-529f-8629-91d00c8ecbda send: 85B guuid=54151110-1900-0000-1cff-7923d6070000 pid=2006->3615a721-482b-529f-8629-91d00c8ecbda send: 134B guuid=d9c6e33d-1900-0000-1cff-792339080000 pid=2105->3615a721-482b-529f-8629-91d00c8ecbda send: 83B guuid=92eafa7c-1900-0000-1cff-7923d2080000 pid=2258->3615a721-482b-529f-8629-91d00c8ecbda send: 132B guuid=b676b6b0-1900-0000-1cff-792335090000 pid=2357->3615a721-482b-529f-8629-91d00c8ecbda send: 81B guuid=8f02afed-1900-0000-1cff-7923b8090000 pid=2488->3615a721-482b-529f-8629-91d00c8ecbda send: 133B guuid=e6f74c23-1a00-0000-1cff-7923360a0000 pid=2614->3615a721-482b-529f-8629-91d00c8ecbda send: 82B guuid=f9c84063-1a00-0000-1cff-7923d90a0000 pid=2777 /home/sandbox/i686 delete-file net write-file zombie guuid=41ea1763-1a00-0000-1cff-7923d80a0000 pid=2776->guuid=f9c84063-1a00-0000-1cff-7923d90a0000 pid=2777 clone guuid=f9c84063-1a00-0000-1cff-7923d90a0000 pid=2777->b073fe87-9890-5da3-8993-46d9b6b951c9 con guuid=f9c84063-1a00-0000-1cff-7923d90a0000 pid=2779 /home/sandbox/i686 guuid=f9c84063-1a00-0000-1cff-7923d90a0000 pid=2777->guuid=f9c84063-1a00-0000-1cff-7923d90a0000 pid=2779 clone guuid=72dbc563-1a00-0000-1cff-7923dc0a0000 pid=2780->3615a721-482b-529f-8629-91d00c8ecbda send: 133B guuid=2a188b97-1a00-0000-1cff-79232f0b0000 pid=2863->3615a721-482b-529f-8629-91d00c8ecbda send: 82B guuid=4a140ccf-1a00-0000-1cff-79238c0b0000 pid=2956->3615a721-482b-529f-8629-91d00c8ecbda send: 133B guuid=b6be900a-1b00-0000-1cff-79230b0c0000 pid=3083->3615a721-482b-529f-8629-91d00c8ecbda send: 82B guuid=234ee550-1b00-0000-1cff-79238a0c0000 pid=3210->3615a721-482b-529f-8629-91d00c8ecbda send: 135B guuid=c56c4a85-1b00-0000-1cff-7923ba0c0000 pid=3258->3615a721-482b-529f-8629-91d00c8ecbda send: 84B guuid=97dac9d0-1b00-0000-1cff-7923250d0000 pid=3365->3615a721-482b-529f-8629-91d00c8ecbda send: 138B guuid=c1b99a0d-1c00-0000-1cff-79238d0d0000 pid=3469->3615a721-482b-529f-8629-91d00c8ecbda send: 87B guuid=0330ad4c-1c00-0000-1cff-79231b0e0000 pid=3611->3615a721-482b-529f-8629-91d00c8ecbda send: 134B guuid=0963fa89-1c00-0000-1cff-7923d00e0000 pid=3792->3615a721-482b-529f-8629-91d00c8ecbda send: 83B guuid=d5a873d7-1c00-0000-1cff-7923b20f0000 pid=4018->3615a721-482b-529f-8629-91d00c8ecbda send: 132B guuid=c8100d16-1d00-0000-1cff-792377100000 pid=4215->3615a721-482b-529f-8629-91d00c8ecbda send: 81B guuid=b1f5fe4e-1d00-0000-1cff-792334110000 pid=4404->3615a721-482b-529f-8629-91d00c8ecbda send: 132B guuid=c9928674-1d00-0000-1cff-7923c1110000 pid=4545->3615a721-482b-529f-8629-91d00c8ecbda send: 81B
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2026-02-17 17:04:19 UTC
File Type:
Text (Shell)
AV detection:
9 of 36 (25.00%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 03bf8b6610e81d015f5e0e6023281b232b8d32e8510cef333f9f9eb8af1b4bde

(this sample)

Comments