MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2cd23e785cb5acabe267d70bbfa609ede5a5d11a3ff1b8c3d9710aa334cc23ed. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 2cd23e785cb5acabe267d70bbfa609ede5a5d11a3ff1b8c3d9710aa334cc23ed
SHA3-384 hash: 6646b57f391cb1f3ab8ea80caed79c323905c147603c9f4b21f4b28add22a1f0eb1cca14650db24f26c022722949fbfd
SHA1 hash: 659cc5fdde81814fc325a47cafd1d24415a211d7
MD5 hash: 24a57d6a045061507b898bac63759943
humanhash: green-one-emma-earth
File name:android.sh
Download: download sample
File size:967 bytes
First seen:2026-05-14 21:56:04 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:FckEorcDO4Y0orcHaorcoborcfxdlGiorcPVXIiorcAborcONOorcEmorcX4uorr:ydDpYEmoToePVXIemGCBoiXQeTE+aq2
TLSH T1301100DE0EF7A0F7C416DA4A2B63C84C900887D01DD8EE35E4463F7758C6D217564AEA
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
39
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive mirai
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=f701391c-1900-0000-c720-cd57fc060000 pid=1788 /usr/bin/sudo guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791 /tmp/sample.bin guuid=f701391c-1900-0000-c720-cd57fc060000 pid=1788->guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791 execve guuid=0f24501e-1900-0000-c720-cd5700070000 pid=1792 /usr/bin/wget net send-data write-file guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=0f24501e-1900-0000-c720-cd5700070000 pid=1792 execve guuid=a02b4c29-1900-0000-c720-cd5712070000 pid=1810 /usr/bin/chmod guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=a02b4c29-1900-0000-c720-cd5712070000 pid=1810 execve guuid=6740b929-1900-0000-c720-cd5714070000 pid=1812 /usr/bin/dash guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=6740b929-1900-0000-c720-cd5714070000 pid=1812 clone guuid=ce85882a-1900-0000-c720-cd5717070000 pid=1815 /usr/bin/wget net send-data write-file guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=ce85882a-1900-0000-c720-cd5717070000 pid=1815 execve guuid=45ba4035-1900-0000-c720-cd5728070000 pid=1832 /usr/bin/chmod guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=45ba4035-1900-0000-c720-cd5728070000 pid=1832 execve guuid=0a92bb35-1900-0000-c720-cd5729070000 pid=1833 /usr/bin/dash guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=0a92bb35-1900-0000-c720-cd5729070000 pid=1833 clone guuid=191d9236-1900-0000-c720-cd572d070000 pid=1837 /usr/bin/wget net send-data write-file guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=191d9236-1900-0000-c720-cd572d070000 pid=1837 execve guuid=40842e40-1900-0000-c720-cd573a070000 pid=1850 /usr/bin/chmod guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=40842e40-1900-0000-c720-cd573a070000 pid=1850 execve guuid=f4489a40-1900-0000-c720-cd573c070000 pid=1852 /usr/bin/dash guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=f4489a40-1900-0000-c720-cd573c070000 pid=1852 clone guuid=f6e56541-1900-0000-c720-cd5740070000 pid=1856 /usr/bin/wget net send-data write-file guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=f6e56541-1900-0000-c720-cd5740070000 pid=1856 execve guuid=9932ab4a-1900-0000-c720-cd5750070000 pid=1872 /usr/bin/chmod guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=9932ab4a-1900-0000-c720-cd5750070000 pid=1872 execve guuid=3604494b-1900-0000-c720-cd5752070000 pid=1874 /usr/bin/dash guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=3604494b-1900-0000-c720-cd5752070000 pid=1874 clone guuid=a894184d-1900-0000-c720-cd5758070000 pid=1880 /usr/bin/wget net send-data write-file guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=a894184d-1900-0000-c720-cd5758070000 pid=1880 execve guuid=f09e0556-1900-0000-c720-cd5769070000 pid=1897 /usr/bin/chmod guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=f09e0556-1900-0000-c720-cd5769070000 pid=1897 execve guuid=f18d5b56-1900-0000-c720-cd576a070000 pid=1898 /usr/bin/dash guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=f18d5b56-1900-0000-c720-cd576a070000 pid=1898 clone guuid=c7ae7b58-1900-0000-c720-cd5770070000 pid=1904 /usr/bin/wget net send-data write-file guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=c7ae7b58-1900-0000-c720-cd5770070000 pid=1904 execve guuid=fbfb4962-1900-0000-c720-cd577f070000 pid=1919 /usr/bin/chmod guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=fbfb4962-1900-0000-c720-cd577f070000 pid=1919 execve guuid=4a97c862-1900-0000-c720-cd5780070000 pid=1920 /usr/bin/dash guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=4a97c862-1900-0000-c720-cd5780070000 pid=1920 clone guuid=c442de63-1900-0000-c720-cd5783070000 pid=1923 /usr/bin/wget net send-data write-file guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=c442de63-1900-0000-c720-cd5783070000 pid=1923 execve guuid=4863ed6d-1900-0000-c720-cd5795070000 pid=1941 /usr/bin/chmod guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=4863ed6d-1900-0000-c720-cd5795070000 pid=1941 execve guuid=aee1506e-1900-0000-c720-cd5797070000 pid=1943 /usr/bin/dash guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=aee1506e-1900-0000-c720-cd5797070000 pid=1943 clone guuid=e4d05f70-1900-0000-c720-cd5799070000 pid=1945 /usr/bin/wget net send-data write-file guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=e4d05f70-1900-0000-c720-cd5799070000 pid=1945 execve guuid=7f13357a-1900-0000-c720-cd57a6070000 pid=1958 /usr/bin/chmod guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=7f13357a-1900-0000-c720-cd57a6070000 pid=1958 execve guuid=c02f877a-1900-0000-c720-cd57a7070000 pid=1959 /usr/bin/dash guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=c02f877a-1900-0000-c720-cd57a7070000 pid=1959 clone guuid=3c4f827b-1900-0000-c720-cd57ac070000 pid=1964 /usr/bin/wget net send-data write-file guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=3c4f827b-1900-0000-c720-cd57ac070000 pid=1964 execve guuid=1a108485-1900-0000-c720-cd57bd070000 pid=1981 /usr/bin/chmod guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=1a108485-1900-0000-c720-cd57bd070000 pid=1981 execve guuid=a5ecf985-1900-0000-c720-cd57bf070000 pid=1983 /usr/bin/dash guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=a5ecf985-1900-0000-c720-cd57bf070000 pid=1983 clone guuid=5a76ee86-1900-0000-c720-cd57c3070000 pid=1987 /usr/bin/wget net send-data write-file guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=5a76ee86-1900-0000-c720-cd57c3070000 pid=1987 execve guuid=b813bb90-1900-0000-c720-cd57cf070000 pid=1999 /usr/bin/chmod guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=b813bb90-1900-0000-c720-cd57cf070000 pid=1999 execve guuid=796e1091-1900-0000-c720-cd57d0070000 pid=2000 /home/sandbox/bot delete-file write-file guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=796e1091-1900-0000-c720-cd57d0070000 pid=2000 execve guuid=e5a8bb94-1900-0000-c720-cd57dd070000 pid=2013 /usr/bin/wget net send-data write-file guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=e5a8bb94-1900-0000-c720-cd57dd070000 pid=2013 execve guuid=b3c4829f-1900-0000-c720-cd57f7070000 pid=2039 /usr/bin/chmod guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=b3c4829f-1900-0000-c720-cd57f7070000 pid=2039 execve guuid=56e0c99f-1900-0000-c720-cd57f8070000 pid=2040 /home/sandbox/bot delete-file write-file guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=56e0c99f-1900-0000-c720-cd57f8070000 pid=2040 execve guuid=8d7c65a2-1900-0000-c720-cd5708080000 pid=2056 /usr/bin/dash guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=8d7c65a2-1900-0000-c720-cd5708080000 pid=2056 clone guuid=d5fc88a2-1900-0000-c720-cd570c080000 pid=2060 /usr/bin/chmod guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=d5fc88a2-1900-0000-c720-cd570c080000 pid=2060 execve guuid=5a6ceda2-1900-0000-c720-cd570d080000 pid=2061 /usr/bin/dash guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=5a6ceda2-1900-0000-c720-cd570d080000 pid=2061 clone guuid=2c4007a3-1900-0000-c720-cd570f080000 pid=2063 /usr/bin/dash guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=2c4007a3-1900-0000-c720-cd570f080000 pid=2063 clone guuid=a15b1ea3-1900-0000-c720-cd5710080000 pid=2064 /usr/bin/chmod guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=a15b1ea3-1900-0000-c720-cd5710080000 pid=2064 execve guuid=fa6880a3-1900-0000-c720-cd5712080000 pid=2066 /usr/bin/dash guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=fa6880a3-1900-0000-c720-cd5712080000 pid=2066 clone guuid=1d569aa3-1900-0000-c720-cd5714080000 pid=2068 /usr/bin/rm delete-file guuid=2f8a0e1e-1900-0000-c720-cd57ff060000 pid=1791->guuid=1d569aa3-1900-0000-c720-cd5714080000 pid=2068 execve e946025c-538c-5b4b-a294-8f32e6f07833 166.88.225.196:80 guuid=0f24501e-1900-0000-c720-cd5700070000 pid=1792->e946025c-538c-5b4b-a294-8f32e6f07833 send: 144B guuid=ce85882a-1900-0000-c720-cd5717070000 pid=1815->e946025c-538c-5b4b-a294-8f32e6f07833 send: 145B guuid=191d9236-1900-0000-c720-cd572d070000 pid=1837->e946025c-538c-5b4b-a294-8f32e6f07833 send: 145B guuid=f6e56541-1900-0000-c720-cd5740070000 pid=1856->e946025c-538c-5b4b-a294-8f32e6f07833 send: 145B guuid=a894184d-1900-0000-c720-cd5758070000 pid=1880->e946025c-538c-5b4b-a294-8f32e6f07833 send: 148B guuid=c7ae7b58-1900-0000-c720-cd5770070000 pid=1904->e946025c-538c-5b4b-a294-8f32e6f07833 send: 147B guuid=c442de63-1900-0000-c720-cd5783070000 pid=1923->e946025c-538c-5b4b-a294-8f32e6f07833 send: 145B guuid=e4d05f70-1900-0000-c720-cd5799070000 pid=1945->e946025c-538c-5b4b-a294-8f32e6f07833 send: 145B guuid=3c4f827b-1900-0000-c720-cd57ac070000 pid=1964->e946025c-538c-5b4b-a294-8f32e6f07833 send: 144B guuid=5a76ee86-1900-0000-c720-cd57c3070000 pid=1987->e946025c-538c-5b4b-a294-8f32e6f07833 send: 147B guuid=46811392-1900-0000-c720-cd57d3070000 pid=2003 /home/sandbox/bot guuid=796e1091-1900-0000-c720-cd57d0070000 pid=2000->guuid=46811392-1900-0000-c720-cd57d3070000 pid=2003 clone guuid=76ef0d93-1900-0000-c720-cd57d6070000 pid=2006 /root/.x41b5a000eae0a94e delete-file write-file guuid=796e1091-1900-0000-c720-cd57d0070000 pid=2000->guuid=76ef0d93-1900-0000-c720-cd57d6070000 pid=2006 execve guuid=a4c42193-1900-0000-c720-cd57d7070000 pid=2007 /root/.x41b5a000eae0a94e guuid=76ef0d93-1900-0000-c720-cd57d6070000 pid=2006->guuid=a4c42193-1900-0000-c720-cd57d7070000 pid=2007 clone guuid=c0727594-1900-0000-c720-cd57da070000 pid=2010 /root/.x41b5a000eae0a94e guuid=76ef0d93-1900-0000-c720-cd57d6070000 pid=2006->guuid=c0727594-1900-0000-c720-cd57da070000 pid=2010 clone guuid=b09a8994-1900-0000-c720-cd57db070000 pid=2011 /root/.x41b5a000eae0a94e guuid=76ef0d93-1900-0000-c720-cd57d6070000 pid=2006->guuid=b09a8994-1900-0000-c720-cd57db070000 pid=2011 clone guuid=613aa494-1900-0000-c720-cd57dc070000 pid=2012 /root/.x41b5a000eae0a94e zombie guuid=76ef0d93-1900-0000-c720-cd57d6070000 pid=2006->guuid=613aa494-1900-0000-c720-cd57dc070000 pid=2012 clone guuid=b643db94-1900-0000-c720-cd57df070000 pid=2015 /root/.x41b5a000eae0a94e guuid=613aa494-1900-0000-c720-cd57dc070000 pid=2012->guuid=b643db94-1900-0000-c720-cd57df070000 pid=2015 clone guuid=e5a8bb94-1900-0000-c720-cd57dd070000 pid=2013->e946025c-538c-5b4b-a294-8f32e6f07833 send: 145B guuid=a6a00495-1900-0000-c720-cd57e0070000 pid=2016 /root/.x41b5a000eae0a94e net send-data write-file guuid=b643db94-1900-0000-c720-cd57df070000 pid=2015->guuid=a6a00495-1900-0000-c720-cd57e0070000 pid=2016 clone c7409a10-9641-5468-92b0-24a0315bc73b 176.65.139.191:1337 guuid=a6a00495-1900-0000-c720-cd57e0070000 pid=2016->c7409a10-9641-5468-92b0-24a0315bc73b send: 255B guuid=a6a00495-1900-0000-c720-cd57e0070000 pid=2017 /root/.x41b5a000eae0a94e guuid=a6a00495-1900-0000-c720-cd57e0070000 pid=2016->guuid=a6a00495-1900-0000-c720-cd57e0070000 pid=2017 clone guuid=a6a00495-1900-0000-c720-cd57e0070000 pid=2019 /root/.x41b5a000eae0a94e guuid=a6a00495-1900-0000-c720-cd57e0070000 pid=2016->guuid=a6a00495-1900-0000-c720-cd57e0070000 pid=2019 clone guuid=a6a00495-1900-0000-c720-cd57e0070000 pid=2021 /root/.x41b5a000eae0a94e guuid=a6a00495-1900-0000-c720-cd57e0070000 pid=2016->guuid=a6a00495-1900-0000-c720-cd57e0070000 pid=2021 clone guuid=2c387091-2000-0000-c720-cd57af140000 pid=5295 /root/.x41b5a000eae0a94e guuid=a6a00495-1900-0000-c720-cd57e0070000 pid=2017->guuid=2c387091-2000-0000-c720-cd57af140000 pid=5295 clone guuid=9eee73a0-1900-0000-c720-cd57fa070000 pid=2042 /home/sandbox/bot guuid=56e0c99f-1900-0000-c720-cd57f8070000 pid=2040->guuid=9eee73a0-1900-0000-c720-cd57fa070000 pid=2042 clone guuid=3dabaaa0-1900-0000-c720-cd57fc070000 pid=2044 /root/.xae80fd5272d10bd7 delete-file write-file guuid=56e0c99f-1900-0000-c720-cd57f8070000 pid=2040->guuid=3dabaaa0-1900-0000-c720-cd57fc070000 pid=2044 execve guuid=b3bacca0-1900-0000-c720-cd57fd070000 pid=2045 /root/.xae80fd5272d10bd7 guuid=3dabaaa0-1900-0000-c720-cd57fc070000 pid=2044->guuid=b3bacca0-1900-0000-c720-cd57fd070000 pid=2045 clone guuid=a09321a2-1900-0000-c720-cd5703080000 pid=2051 /root/.xae80fd5272d10bd7 guuid=3dabaaa0-1900-0000-c720-cd57fc070000 pid=2044->guuid=a09321a2-1900-0000-c720-cd5703080000 pid=2051 clone guuid=e0f537a2-1900-0000-c720-cd5704080000 pid=2052 /root/.xae80fd5272d10bd7 guuid=3dabaaa0-1900-0000-c720-cd57fc070000 pid=2044->guuid=e0f537a2-1900-0000-c720-cd5704080000 pid=2052 clone guuid=684452a2-1900-0000-c720-cd5705080000 pid=2053 /root/.xae80fd5272d10bd7 guuid=3dabaaa0-1900-0000-c720-cd57fc070000 pid=2044->guuid=684452a2-1900-0000-c720-cd5705080000 pid=2053 clone guuid=dc8d5ba2-1900-0000-c720-cd5706080000 pid=2054 /root/.xae80fd5272d10bd7 guuid=684452a2-1900-0000-c720-cd5705080000 pid=2053->guuid=dc8d5ba2-1900-0000-c720-cd5706080000 pid=2054 clone guuid=70686ba2-1900-0000-c720-cd5709080000 pid=2057 /root/.xae80fd5272d10bd7 net send-data write-file guuid=dc8d5ba2-1900-0000-c720-cd5706080000 pid=2054->guuid=70686ba2-1900-0000-c720-cd5709080000 pid=2057 clone guuid=70686ba2-1900-0000-c720-cd5709080000 pid=2057->c7409a10-9641-5468-92b0-24a0315bc73b send: 416B guuid=70686ba2-1900-0000-c720-cd5709080000 pid=2058 /root/.xae80fd5272d10bd7 guuid=70686ba2-1900-0000-c720-cd5709080000 pid=2057->guuid=70686ba2-1900-0000-c720-cd5709080000 pid=2058 clone guuid=70686ba2-1900-0000-c720-cd5709080000 pid=2059 /root/.xae80fd5272d10bd7 guuid=70686ba2-1900-0000-c720-cd5709080000 pid=2057->guuid=70686ba2-1900-0000-c720-cd5709080000 pid=2059 clone guuid=70686ba2-1900-0000-c720-cd5709080000 pid=2072 /root/.xae80fd5272d10bd7 guuid=70686ba2-1900-0000-c720-cd5709080000 pid=2057->guuid=70686ba2-1900-0000-c720-cd5709080000 pid=2072 clone guuid=b392b59e-2000-0000-c720-cd57b0140000 pid=5296 /root/.xae80fd5272d10bd7 guuid=70686ba2-1900-0000-c720-cd5709080000 pid=2058->guuid=b392b59e-2000-0000-c720-cd57b0140000 pid=5296 clone
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Document-HTML.Hacktool.Heuristic
Status:
Malicious
First seen:
2026-05-14 21:57:27 UTC
File Type:
Text (Shell)
AV detection:
7 of 36 (19.44%)
Threat level:
  1/5
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 2cd23e785cb5acabe267d70bbfa609ede5a5d11a3ff1b8c3d9710aa334cc23ed

(this sample)

  
Delivery method
Distributed via web download

Comments