MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 48497f7eb6077a3f87cfbd8fd4a62849294b625a4e05c7f4a8f877f5b45cc7fe. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: 48497f7eb6077a3f87cfbd8fd4a62849294b625a4e05c7f4a8f877f5b45cc7fe
SHA3-384 hash: 927fd742b06547313ea72e0099c387439a64a5b9ffc3382ac0df35820b21e9f835d75fc12d047aa12742b9c59bcc6dbf
SHA1 hash: d660ae17b205c77be0422a274e9c81d344b154f4
MD5 hash: 5be130d64f31451634c2365bad090f3e
humanhash: white-jersey-carpet-alaska
File name:manual.sh
Download: download sample
File size:1'251 bytes
First seen:2026-05-25 22:14:42 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:rv5okq2cgqi8q9ZebptXtCqu26NcVc4bJlEx9d:rv5okqlgqi8q9ZettXtCqulKG4bJlExX
TLSH T1822165CA139026EA491BCF897A624DCD4F8F05F5FF4E0768DBC4181B516F29C3DA6A81
Magika txt
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
32
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Gathering data
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Status:
terminated
Behavior Graph:
%3 guuid=52c27c66-1a00-0000-4f54-ebfc0a0b0000 pid=2826 /usr/bin/sudo guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827 /tmp/sample.bin guuid=52c27c66-1a00-0000-4f54-ebfc0a0b0000 pid=2826->guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827 execve guuid=19747576-1a00-0000-4f54-ebfc0d0b0000 pid=2829 /usr/bin/wget net send-data write-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=19747576-1a00-0000-4f54-ebfc0d0b0000 pid=2829 execve guuid=27d6267f-1a00-0000-4f54-ebfc1a0b0000 pid=2842 /usr/bin/curl net send-data write-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=27d6267f-1a00-0000-4f54-ebfc1a0b0000 pid=2842 execve guuid=eddab189-1a00-0000-4f54-ebfc2e0b0000 pid=2862 /usr/bin/chmod guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=eddab189-1a00-0000-4f54-ebfc2e0b0000 pid=2862 execve guuid=c7c1338a-1a00-0000-4f54-ebfc300b0000 pid=2864 /usr/bin/dash guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=c7c1338a-1a00-0000-4f54-ebfc300b0000 pid=2864 clone guuid=d973f08b-1a00-0000-4f54-ebfc360b0000 pid=2870 /usr/bin/rm delete-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=d973f08b-1a00-0000-4f54-ebfc360b0000 pid=2870 execve guuid=59bd728c-1a00-0000-4f54-ebfc380b0000 pid=2872 /usr/bin/wget net send-data write-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=59bd728c-1a00-0000-4f54-ebfc380b0000 pid=2872 execve guuid=27441991-1a00-0000-4f54-ebfc430b0000 pid=2883 /usr/bin/curl net send-data write-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=27441991-1a00-0000-4f54-ebfc430b0000 pid=2883 execve guuid=b26e9096-1a00-0000-4f54-ebfc520b0000 pid=2898 /usr/bin/chmod guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=b26e9096-1a00-0000-4f54-ebfc520b0000 pid=2898 execve guuid=caa0ce96-1a00-0000-4f54-ebfc540b0000 pid=2900 /usr/bin/dash guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=caa0ce96-1a00-0000-4f54-ebfc540b0000 pid=2900 clone guuid=ab22fb97-1a00-0000-4f54-ebfc590b0000 pid=2905 /usr/bin/rm delete-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=ab22fb97-1a00-0000-4f54-ebfc590b0000 pid=2905 execve guuid=151ba3a8-1a00-0000-4f54-ebfc600b0000 pid=2912 /usr/bin/wget net send-data write-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=151ba3a8-1a00-0000-4f54-ebfc600b0000 pid=2912 execve guuid=ca0e6aae-1a00-0000-4f54-ebfc6d0b0000 pid=2925 /usr/bin/curl net send-data write-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=ca0e6aae-1a00-0000-4f54-ebfc6d0b0000 pid=2925 execve guuid=ebfea6b5-1a00-0000-4f54-ebfc7b0b0000 pid=2939 /usr/bin/chmod guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=ebfea6b5-1a00-0000-4f54-ebfc7b0b0000 pid=2939 execve guuid=f63feab5-1a00-0000-4f54-ebfc7d0b0000 pid=2941 /usr/bin/dash guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=f63feab5-1a00-0000-4f54-ebfc7d0b0000 pid=2941 clone guuid=7f2a69b6-1a00-0000-4f54-ebfc800b0000 pid=2944 /usr/bin/rm delete-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=7f2a69b6-1a00-0000-4f54-ebfc800b0000 pid=2944 execve guuid=243caeb6-1a00-0000-4f54-ebfc810b0000 pid=2945 /usr/bin/wget net send-data write-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=243caeb6-1a00-0000-4f54-ebfc810b0000 pid=2945 execve guuid=41ae8abc-1a00-0000-4f54-ebfc870b0000 pid=2951 /usr/bin/curl net send-data write-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=41ae8abc-1a00-0000-4f54-ebfc870b0000 pid=2951 execve guuid=2f2f1ec7-1a00-0000-4f54-ebfc9e0b0000 pid=2974 /usr/bin/chmod guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=2f2f1ec7-1a00-0000-4f54-ebfc9e0b0000 pid=2974 execve guuid=0b315dc7-1a00-0000-4f54-ebfca00b0000 pid=2976 /usr/bin/dash guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=0b315dc7-1a00-0000-4f54-ebfca00b0000 pid=2976 clone guuid=410bdfc7-1a00-0000-4f54-ebfca30b0000 pid=2979 /usr/bin/rm delete-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=410bdfc7-1a00-0000-4f54-ebfca30b0000 pid=2979 execve guuid=fcd504c9-1a00-0000-4f54-ebfca50b0000 pid=2981 /usr/bin/wget net send-data write-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=fcd504c9-1a00-0000-4f54-ebfca50b0000 pid=2981 execve guuid=62b94ece-1a00-0000-4f54-ebfcb10b0000 pid=2993 /usr/bin/curl net send-data write-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=62b94ece-1a00-0000-4f54-ebfcb10b0000 pid=2993 execve guuid=9e86a0d4-1a00-0000-4f54-ebfcc30b0000 pid=3011 /usr/bin/chmod guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=9e86a0d4-1a00-0000-4f54-ebfcc30b0000 pid=3011 execve guuid=f608e3d4-1a00-0000-4f54-ebfcc50b0000 pid=3013 /usr/bin/dash guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=f608e3d4-1a00-0000-4f54-ebfcc50b0000 pid=3013 clone guuid=4c9871d5-1a00-0000-4f54-ebfcc80b0000 pid=3016 /usr/bin/rm delete-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=4c9871d5-1a00-0000-4f54-ebfcc80b0000 pid=3016 execve guuid=fd55a3d6-1a00-0000-4f54-ebfccb0b0000 pid=3019 /usr/bin/wget net send-data write-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=fd55a3d6-1a00-0000-4f54-ebfccb0b0000 pid=3019 execve guuid=74d24fdb-1a00-0000-4f54-ebfcd80b0000 pid=3032 /usr/bin/curl net send-data write-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=74d24fdb-1a00-0000-4f54-ebfcd80b0000 pid=3032 execve guuid=02cdb9e1-1a00-0000-4f54-ebfce80b0000 pid=3048 /usr/bin/chmod guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=02cdb9e1-1a00-0000-4f54-ebfce80b0000 pid=3048 execve guuid=63ef06e2-1a00-0000-4f54-ebfce90b0000 pid=3049 /usr/bin/dash guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=63ef06e2-1a00-0000-4f54-ebfce90b0000 pid=3049 clone guuid=27249fe2-1a00-0000-4f54-ebfceb0b0000 pid=3051 /usr/bin/rm delete-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=27249fe2-1a00-0000-4f54-ebfceb0b0000 pid=3051 execve guuid=65eb85e3-1a00-0000-4f54-ebfcec0b0000 pid=3052 /usr/bin/wget net send-data write-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=65eb85e3-1a00-0000-4f54-ebfcec0b0000 pid=3052 execve guuid=154b06e8-1a00-0000-4f54-ebfcf60b0000 pid=3062 /usr/bin/curl net send-data write-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=154b06e8-1a00-0000-4f54-ebfcf60b0000 pid=3062 execve guuid=03aeceed-1a00-0000-4f54-ebfc040c0000 pid=3076 /usr/bin/chmod guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=03aeceed-1a00-0000-4f54-ebfc040c0000 pid=3076 execve guuid=2f2a2aee-1a00-0000-4f54-ebfc050c0000 pid=3077 /usr/bin/dash guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=2f2a2aee-1a00-0000-4f54-ebfc050c0000 pid=3077 clone guuid=4734c8ee-1a00-0000-4f54-ebfc080c0000 pid=3080 /usr/bin/rm delete-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=4734c8ee-1a00-0000-4f54-ebfc080c0000 pid=3080 execve guuid=41195bef-1a00-0000-4f54-ebfc0a0c0000 pid=3082 /usr/bin/wget net send-data write-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=41195bef-1a00-0000-4f54-ebfc0a0c0000 pid=3082 execve guuid=e63890f3-1a00-0000-4f54-ebfc190c0000 pid=3097 /usr/bin/curl net send-data write-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=e63890f3-1a00-0000-4f54-ebfc190c0000 pid=3097 execve guuid=3d84b6f9-1a00-0000-4f54-ebfc280c0000 pid=3112 /usr/bin/chmod guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=3d84b6f9-1a00-0000-4f54-ebfc280c0000 pid=3112 execve guuid=1bfcf6f9-1a00-0000-4f54-ebfc2a0c0000 pid=3114 /usr/bin/dash guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=1bfcf6f9-1a00-0000-4f54-ebfc2a0c0000 pid=3114 clone guuid=ae0e8dfa-1a00-0000-4f54-ebfc2d0c0000 pid=3117 /usr/bin/rm delete-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=ae0e8dfa-1a00-0000-4f54-ebfc2d0c0000 pid=3117 execve guuid=aeefd6fa-1a00-0000-4f54-ebfc2f0c0000 pid=3119 /usr/bin/wget net send-data write-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=aeefd6fa-1a00-0000-4f54-ebfc2f0c0000 pid=3119 execve guuid=7d7d7701-1b00-0000-4f54-ebfc420c0000 pid=3138 /usr/bin/curl net send-data write-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=7d7d7701-1b00-0000-4f54-ebfc420c0000 pid=3138 execve guuid=5825bf07-1b00-0000-4f54-ebfc520c0000 pid=3154 /usr/bin/chmod guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=5825bf07-1b00-0000-4f54-ebfc520c0000 pid=3154 execve guuid=6e1f5b08-1b00-0000-4f54-ebfc540c0000 pid=3156 /usr/bin/dash guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=6e1f5b08-1b00-0000-4f54-ebfc540c0000 pid=3156 clone guuid=1ed22809-1b00-0000-4f54-ebfc570c0000 pid=3159 /usr/bin/rm delete-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=1ed22809-1b00-0000-4f54-ebfc570c0000 pid=3159 execve guuid=f735ae0c-1b00-0000-4f54-ebfc5f0c0000 pid=3167 /usr/bin/wget net send-data write-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=f735ae0c-1b00-0000-4f54-ebfc5f0c0000 pid=3167 execve guuid=361c9f12-1b00-0000-4f54-ebfc6c0c0000 pid=3180 /usr/bin/curl net send-data write-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=361c9f12-1b00-0000-4f54-ebfc6c0c0000 pid=3180 execve guuid=3b20e018-1b00-0000-4f54-ebfc7c0c0000 pid=3196 /usr/bin/chmod guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=3b20e018-1b00-0000-4f54-ebfc7c0c0000 pid=3196 execve guuid=11674e19-1b00-0000-4f54-ebfc7e0c0000 pid=3198 /usr/bin/dash guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=11674e19-1b00-0000-4f54-ebfc7e0c0000 pid=3198 clone guuid=5026ef19-1b00-0000-4f54-ebfc810c0000 pid=3201 /usr/bin/rm delete-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=5026ef19-1b00-0000-4f54-ebfc810c0000 pid=3201 execve guuid=603e401b-1b00-0000-4f54-ebfc860c0000 pid=3206 /usr/bin/wget net send-data write-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=603e401b-1b00-0000-4f54-ebfc860c0000 pid=3206 execve guuid=04151320-1b00-0000-4f54-ebfc930c0000 pid=3219 /usr/bin/curl net send-data write-file guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=04151320-1b00-0000-4f54-ebfc930c0000 pid=3219 execve guuid=4de33027-1b00-0000-4f54-ebfca10c0000 pid=3233 /usr/bin/chmod guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=4de33027-1b00-0000-4f54-ebfca10c0000 pid=3233 execve guuid=6ed2f027-1b00-0000-4f54-ebfca20c0000 pid=3234 /home/sandbox/x86_64 delete-file net guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=6ed2f027-1b00-0000-4f54-ebfca20c0000 pid=3234 execve guuid=f92b6b28-1b00-0000-4f54-ebfca40c0000 pid=3236 /usr/bin/rm guuid=03877168-1a00-0000-4f54-ebfc0b0b0000 pid=2827->guuid=f92b6b28-1b00-0000-4f54-ebfca40c0000 pid=3236 execve 703d1e05-09f3-595f-ad9a-1fc6fad8a4e5 64.89.161.130:80 guuid=19747576-1a00-0000-4f54-ebfc0d0b0000 pid=2829->703d1e05-09f3-595f-ad9a-1fc6fad8a4e5 send: 136B guuid=27d6267f-1a00-0000-4f54-ebfc1a0b0000 pid=2842->703d1e05-09f3-595f-ad9a-1fc6fad8a4e5 send: 85B guuid=59bd728c-1a00-0000-4f54-ebfc380b0000 pid=2872->703d1e05-09f3-595f-ad9a-1fc6fad8a4e5 send: 139B guuid=27441991-1a00-0000-4f54-ebfc430b0000 pid=2883->703d1e05-09f3-595f-ad9a-1fc6fad8a4e5 send: 88B guuid=151ba3a8-1a00-0000-4f54-ebfc600b0000 pid=2912->703d1e05-09f3-595f-ad9a-1fc6fad8a4e5 send: 139B guuid=ca0e6aae-1a00-0000-4f54-ebfc6d0b0000 pid=2925->703d1e05-09f3-595f-ad9a-1fc6fad8a4e5 send: 88B guuid=243caeb6-1a00-0000-4f54-ebfc810b0000 pid=2945->703d1e05-09f3-595f-ad9a-1fc6fad8a4e5 send: 139B guuid=41ae8abc-1a00-0000-4f54-ebfc870b0000 pid=2951->703d1e05-09f3-595f-ad9a-1fc6fad8a4e5 send: 88B guuid=fcd504c9-1a00-0000-4f54-ebfca50b0000 pid=2981->703d1e05-09f3-595f-ad9a-1fc6fad8a4e5 send: 137B guuid=62b94ece-1a00-0000-4f54-ebfcb10b0000 pid=2993->703d1e05-09f3-595f-ad9a-1fc6fad8a4e5 send: 86B guuid=fd55a3d6-1a00-0000-4f54-ebfccb0b0000 pid=3019->703d1e05-09f3-595f-ad9a-1fc6fad8a4e5 send: 137B guuid=74d24fdb-1a00-0000-4f54-ebfcd80b0000 pid=3032->703d1e05-09f3-595f-ad9a-1fc6fad8a4e5 send: 86B guuid=65eb85e3-1a00-0000-4f54-ebfcec0b0000 pid=3052->703d1e05-09f3-595f-ad9a-1fc6fad8a4e5 send: 137B guuid=154b06e8-1a00-0000-4f54-ebfcf60b0000 pid=3062->703d1e05-09f3-595f-ad9a-1fc6fad8a4e5 send: 86B guuid=41195bef-1a00-0000-4f54-ebfc0a0c0000 pid=3082->703d1e05-09f3-595f-ad9a-1fc6fad8a4e5 send: 136B guuid=e63890f3-1a00-0000-4f54-ebfc190c0000 pid=3097->703d1e05-09f3-595f-ad9a-1fc6fad8a4e5 send: 85B guuid=aeefd6fa-1a00-0000-4f54-ebfc2f0c0000 pid=3119->703d1e05-09f3-595f-ad9a-1fc6fad8a4e5 send: 136B guuid=7d7d7701-1b00-0000-4f54-ebfc420c0000 pid=3138->703d1e05-09f3-595f-ad9a-1fc6fad8a4e5 send: 85B guuid=f735ae0c-1b00-0000-4f54-ebfc5f0c0000 pid=3167->703d1e05-09f3-595f-ad9a-1fc6fad8a4e5 send: 136B guuid=361c9f12-1b00-0000-4f54-ebfc6c0c0000 pid=3180->703d1e05-09f3-595f-ad9a-1fc6fad8a4e5 send: 85B guuid=603e401b-1b00-0000-4f54-ebfc860c0000 pid=3206->703d1e05-09f3-595f-ad9a-1fc6fad8a4e5 send: 139B guuid=04151320-1b00-0000-4f54-ebfc930c0000 pid=3219->703d1e05-09f3-595f-ad9a-1fc6fad8a4e5 send: 88B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=6ed2f027-1b00-0000-4f54-ebfca20c0000 pid=3234->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=18e46228-1b00-0000-4f54-ebfca30c0000 pid=3235 /home/sandbox/x86_64 net send-data zombie guuid=6ed2f027-1b00-0000-4f54-ebfca20c0000 pid=3234->guuid=18e46228-1b00-0000-4f54-ebfca30c0000 pid=3235 clone guuid=18e46228-1b00-0000-4f54-ebfca30c0000 pid=3235->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con eb947bbe-929d-5627-8812-ca2d6a229234 64.89.161.130:18129 guuid=18e46228-1b00-0000-4f54-ebfca30c0000 pid=3235->eb947bbe-929d-5627-8812-ca2d6a229234 send: 7B guuid=4c916f28-1b00-0000-4f54-ebfca50c0000 pid=3237 /home/sandbox/x86_64 write-file guuid=18e46228-1b00-0000-4f54-ebfca30c0000 pid=3235->guuid=4c916f28-1b00-0000-4f54-ebfca50c0000 pid=3237 clone guuid=15df7228-1b00-0000-4f54-ebfca60c0000 pid=3238 /home/sandbox/x86_64 write-file guuid=18e46228-1b00-0000-4f54-ebfca30c0000 pid=3235->guuid=15df7228-1b00-0000-4f54-ebfca60c0000 pid=3238 clone
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Geninst
Status:
Malicious
First seen:
2026-05-25 22:16:38 UTC
File Type:
Text (Shell)
AV detection:
11 of 36 (30.56%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 48497f7eb6077a3f87cfbd8fd4a62849294b625a4e05c7f4a8f877f5b45cc7fe

(this sample)

  
Delivery method
Distributed via web download

Comments