MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5379e5da6c6eae2eab376717f13ec203dea2307167bbe32fbd2156deabf1d356. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: 5379e5da6c6eae2eab376717f13ec203dea2307167bbe32fbd2156deabf1d356
SHA3-384 hash: e79dd6b3b773744de1e85ad6859640c063ee367148f52414ab8a1ff2b0b131c7ec14af0d3303e632569152159954729c
SHA1 hash: 8cf69841237306089b12b37e3d9fa316315288ef
MD5 hash: 2fd9338041ecc38116d9606cf76155c3
humanhash: nebraska-twelve-crazy-snake
File name:1.sh
Download: download sample
File size:6'359 bytes
First seen:2025-12-20 18:14:42 UTC
Last seen:2025-12-21 12:25:26 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 192:oJ3mB/oOBqELp83RcC12w2k7saCgnAOBPOZHBPOZHKofImPNwDtgGpismUr8KTxq:oJ3mB/oOBqELp83RcC12w2k7saCgnAON
TLSH T174D12FF2B4851BBCDE9FCD3E9151297D108AB9DB66870D6487AE20657C89FCD2C409C3
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://94.156.152.67/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.x86n/an/aelf ua-wget
http://94.156.152.67/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.mipsn/an/aelf ua-wget
http://94.156.152.67/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.arcn/an/aarc elf geofenced ua-wget USA
http://94.156.152.67/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.i468n/an/aelf ua-wget
http://94.156.152.67/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.i686n/an/aelf geofenced ua-wget USA x86
http://94.156.152.67/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.x86_64n/an/aelf geofenced ua-wget USA x86
http://94.156.152.67/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.mpsln/an/aelf ua-wget
http://94.156.152.67/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.armn/an/aarm elf geofenced ua-wget USA
http://94.156.152.67/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.arm5n/an/aarm elf geofenced ua-wget USA
http://94.156.152.67/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.arm6n/an/aarm elf geofenced ua-wget USA
http://94.156.152.67/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.arm7n/an/aarm elf geofenced ua-wget USA
http://94.156.152.67/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.ppcn/an/aelf ua-wget
http://94.156.152.67/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.spcn/an/aelf geofenced sparc ua-wget USA
http://94.156.152.67/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.m68kn/an/aelf ua-wget
http://94.156.152.67/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.sh4n/an/aelf geofenced SuperH ua-wget USA

Intelligence


File Origin
# of uploads :
2
# of downloads :
30
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-20T15:24:00Z UTC
Last seen:
2025-12-21T12:48:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=ee2bc26c-1a00-0000-64bc-426e4a0a0000 pid=2634 /usr/bin/sudo guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640 /tmp/sample.bin guuid=ee2bc26c-1a00-0000-64bc-426e4a0a0000 pid=2634->guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640 execve guuid=1d77386f-1a00-0000-64bc-426e530a0000 pid=2643 /usr/bin/cp guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=1d77386f-1a00-0000-64bc-426e530a0000 pid=2643 execve guuid=8de3b273-1a00-0000-64bc-426e5e0a0000 pid=2654 /usr/bin/wget net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=8de3b273-1a00-0000-64bc-426e5e0a0000 pid=2654 execve guuid=7f03d778-1a00-0000-64bc-426e6c0a0000 pid=2668 /usr/bin/curl net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=7f03d778-1a00-0000-64bc-426e6c0a0000 pid=2668 execve guuid=fac52486-1a00-0000-64bc-426e8f0a0000 pid=2703 /usr/bin/chmod guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=fac52486-1a00-0000-64bc-426e8f0a0000 pid=2703 execve guuid=55b77386-1a00-0000-64bc-426e900a0000 pid=2704 /usr/bin/bash guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=55b77386-1a00-0000-64bc-426e900a0000 pid=2704 clone guuid=39968f86-1a00-0000-64bc-426e920a0000 pid=2706 /usr/bin/rm guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=39968f86-1a00-0000-64bc-426e920a0000 pid=2706 execve guuid=2469eb86-1a00-0000-64bc-426e930a0000 pid=2707 /usr/bin/wget net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=2469eb86-1a00-0000-64bc-426e930a0000 pid=2707 execve guuid=277cad8a-1a00-0000-64bc-426e9f0a0000 pid=2719 /usr/bin/curl net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=277cad8a-1a00-0000-64bc-426e9f0a0000 pid=2719 execve guuid=8ad34d90-1a00-0000-64bc-426eac0a0000 pid=2732 /usr/bin/chmod guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=8ad34d90-1a00-0000-64bc-426eac0a0000 pid=2732 execve guuid=9741c290-1a00-0000-64bc-426eae0a0000 pid=2734 /usr/bin/bash guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=9741c290-1a00-0000-64bc-426eae0a0000 pid=2734 clone guuid=a5b6df90-1a00-0000-64bc-426eb00a0000 pid=2736 /usr/bin/rm guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=a5b6df90-1a00-0000-64bc-426eb00a0000 pid=2736 execve guuid=2dd73191-1a00-0000-64bc-426eb10a0000 pid=2737 /usr/bin/wget net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=2dd73191-1a00-0000-64bc-426eb10a0000 pid=2737 execve guuid=8cae1296-1a00-0000-64bc-426ebd0a0000 pid=2749 /usr/bin/curl net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=8cae1296-1a00-0000-64bc-426ebd0a0000 pid=2749 execve guuid=90cb769b-1a00-0000-64bc-426ec60a0000 pid=2758 /usr/bin/chmod guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=90cb769b-1a00-0000-64bc-426ec60a0000 pid=2758 execve guuid=6b93eb9b-1a00-0000-64bc-426ec70a0000 pid=2759 /usr/bin/bash guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=6b93eb9b-1a00-0000-64bc-426ec70a0000 pid=2759 clone guuid=73db059c-1a00-0000-64bc-426ec90a0000 pid=2761 /usr/bin/rm guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=73db059c-1a00-0000-64bc-426ec90a0000 pid=2761 execve guuid=738a5b9c-1a00-0000-64bc-426ecb0a0000 pid=2763 /usr/bin/wget net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=738a5b9c-1a00-0000-64bc-426ecb0a0000 pid=2763 execve guuid=cd0800a0-1a00-0000-64bc-426ed50a0000 pid=2773 /usr/bin/curl net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=cd0800a0-1a00-0000-64bc-426ed50a0000 pid=2773 execve guuid=ebe993a5-1a00-0000-64bc-426edf0a0000 pid=2783 /usr/bin/chmod guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=ebe993a5-1a00-0000-64bc-426edf0a0000 pid=2783 execve guuid=5e35fda5-1a00-0000-64bc-426ee00a0000 pid=2784 /usr/bin/bash guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=5e35fda5-1a00-0000-64bc-426ee00a0000 pid=2784 clone guuid=d17320a6-1a00-0000-64bc-426ee10a0000 pid=2785 /usr/bin/rm guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=d17320a6-1a00-0000-64bc-426ee10a0000 pid=2785 execve guuid=291f94a6-1a00-0000-64bc-426ee20a0000 pid=2786 /usr/bin/wget net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=291f94a6-1a00-0000-64bc-426ee20a0000 pid=2786 execve guuid=d40493aa-1a00-0000-64bc-426ee30a0000 pid=2787 /usr/bin/curl net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=d40493aa-1a00-0000-64bc-426ee30a0000 pid=2787 execve guuid=02c22bb0-1a00-0000-64bc-426eeb0a0000 pid=2795 /usr/bin/chmod guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=02c22bb0-1a00-0000-64bc-426eeb0a0000 pid=2795 execve guuid=115f7fb0-1a00-0000-64bc-426eed0a0000 pid=2797 /usr/bin/bash guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=115f7fb0-1a00-0000-64bc-426eed0a0000 pid=2797 clone guuid=d4dd96b0-1a00-0000-64bc-426eee0a0000 pid=2798 /usr/bin/rm guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=d4dd96b0-1a00-0000-64bc-426eee0a0000 pid=2798 execve guuid=f9a31db1-1a00-0000-64bc-426eef0a0000 pid=2799 /usr/bin/wget net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=f9a31db1-1a00-0000-64bc-426eef0a0000 pid=2799 execve guuid=46b4d2b4-1a00-0000-64bc-426efa0a0000 pid=2810 /usr/bin/curl net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=46b4d2b4-1a00-0000-64bc-426efa0a0000 pid=2810 execve guuid=79f3acb9-1a00-0000-64bc-426e060b0000 pid=2822 /usr/bin/chmod guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=79f3acb9-1a00-0000-64bc-426e060b0000 pid=2822 execve guuid=2fd508ba-1a00-0000-64bc-426e080b0000 pid=2824 /usr/bin/bash guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=2fd508ba-1a00-0000-64bc-426e080b0000 pid=2824 clone guuid=a53e27ba-1a00-0000-64bc-426e0a0b0000 pid=2826 /usr/bin/rm guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=a53e27ba-1a00-0000-64bc-426e0a0b0000 pid=2826 execve guuid=0f8577ba-1a00-0000-64bc-426e0c0b0000 pid=2828 /usr/bin/wget net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=0f8577ba-1a00-0000-64bc-426e0c0b0000 pid=2828 execve guuid=bd87dbbd-1a00-0000-64bc-426e140b0000 pid=2836 /usr/bin/curl net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=bd87dbbd-1a00-0000-64bc-426e140b0000 pid=2836 execve guuid=a938aac3-1a00-0000-64bc-426e1b0b0000 pid=2843 /usr/bin/chmod guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=a938aac3-1a00-0000-64bc-426e1b0b0000 pid=2843 execve guuid=964c0dc4-1a00-0000-64bc-426e1d0b0000 pid=2845 /usr/bin/bash guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=964c0dc4-1a00-0000-64bc-426e1d0b0000 pid=2845 clone guuid=416b26c4-1a00-0000-64bc-426e1e0b0000 pid=2846 /usr/bin/rm guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=416b26c4-1a00-0000-64bc-426e1e0b0000 pid=2846 execve guuid=15d77ac4-1a00-0000-64bc-426e1f0b0000 pid=2847 /usr/bin/wget net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=15d77ac4-1a00-0000-64bc-426e1f0b0000 pid=2847 execve guuid=f76f51c8-1a00-0000-64bc-426e260b0000 pid=2854 /usr/bin/curl net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=f76f51c8-1a00-0000-64bc-426e260b0000 pid=2854 execve guuid=2a7706cd-1a00-0000-64bc-426e2e0b0000 pid=2862 /usr/bin/chmod guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=2a7706cd-1a00-0000-64bc-426e2e0b0000 pid=2862 execve guuid=84f1ded5-1a00-0000-64bc-426e300b0000 pid=2864 /usr/bin/bash guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=84f1ded5-1a00-0000-64bc-426e300b0000 pid=2864 clone guuid=eb4f24d6-1a00-0000-64bc-426e310b0000 pid=2865 /usr/bin/rm guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=eb4f24d6-1a00-0000-64bc-426e310b0000 pid=2865 execve guuid=35f56dd6-1a00-0000-64bc-426e330b0000 pid=2867 /usr/bin/wget net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=35f56dd6-1a00-0000-64bc-426e330b0000 pid=2867 execve guuid=ba2ffed9-1a00-0000-64bc-426e3a0b0000 pid=2874 /usr/bin/curl net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=ba2ffed9-1a00-0000-64bc-426e3a0b0000 pid=2874 execve guuid=d04497e0-1a00-0000-64bc-426e450b0000 pid=2885 /usr/bin/chmod guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=d04497e0-1a00-0000-64bc-426e450b0000 pid=2885 execve guuid=069f11e1-1a00-0000-64bc-426e460b0000 pid=2886 /usr/bin/bash guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=069f11e1-1a00-0000-64bc-426e460b0000 pid=2886 clone guuid=398d39e1-1a00-0000-64bc-426e470b0000 pid=2887 /usr/bin/rm guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=398d39e1-1a00-0000-64bc-426e470b0000 pid=2887 execve guuid=bc1998e1-1a00-0000-64bc-426e480b0000 pid=2888 /usr/bin/wget net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=bc1998e1-1a00-0000-64bc-426e480b0000 pid=2888 execve guuid=d37b45e5-1a00-0000-64bc-426e510b0000 pid=2897 /usr/bin/curl net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=d37b45e5-1a00-0000-64bc-426e510b0000 pid=2897 execve guuid=7da097eb-1a00-0000-64bc-426e620b0000 pid=2914 /usr/bin/chmod guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=7da097eb-1a00-0000-64bc-426e620b0000 pid=2914 execve guuid=a44ce5eb-1a00-0000-64bc-426e640b0000 pid=2916 /usr/bin/bash guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=a44ce5eb-1a00-0000-64bc-426e640b0000 pid=2916 clone guuid=507f05ec-1a00-0000-64bc-426e650b0000 pid=2917 /usr/bin/rm guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=507f05ec-1a00-0000-64bc-426e650b0000 pid=2917 execve guuid=313f53ec-1a00-0000-64bc-426e670b0000 pid=2919 /usr/bin/wget net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=313f53ec-1a00-0000-64bc-426e670b0000 pid=2919 execve guuid=320b33f0-1a00-0000-64bc-426e710b0000 pid=2929 /usr/bin/curl net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=320b33f0-1a00-0000-64bc-426e710b0000 pid=2929 execve guuid=62c33cf6-1a00-0000-64bc-426e810b0000 pid=2945 /usr/bin/chmod guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=62c33cf6-1a00-0000-64bc-426e810b0000 pid=2945 execve guuid=921faff6-1a00-0000-64bc-426e830b0000 pid=2947 /usr/bin/bash guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=921faff6-1a00-0000-64bc-426e830b0000 pid=2947 clone guuid=1539e3f6-1a00-0000-64bc-426e850b0000 pid=2949 /usr/bin/rm guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=1539e3f6-1a00-0000-64bc-426e850b0000 pid=2949 execve guuid=82cb48f7-1a00-0000-64bc-426e860b0000 pid=2950 /usr/bin/wget net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=82cb48f7-1a00-0000-64bc-426e860b0000 pid=2950 execve guuid=3c38f3fa-1a00-0000-64bc-426e8f0b0000 pid=2959 /usr/bin/curl net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=3c38f3fa-1a00-0000-64bc-426e8f0b0000 pid=2959 execve guuid=69d0eeff-1a00-0000-64bc-426e9c0b0000 pid=2972 /usr/bin/chmod guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=69d0eeff-1a00-0000-64bc-426e9c0b0000 pid=2972 execve guuid=1fd04900-1b00-0000-64bc-426e9e0b0000 pid=2974 /usr/bin/bash guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=1fd04900-1b00-0000-64bc-426e9e0b0000 pid=2974 clone guuid=cac55e00-1b00-0000-64bc-426e9f0b0000 pid=2975 /usr/bin/rm guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=cac55e00-1b00-0000-64bc-426e9f0b0000 pid=2975 execve guuid=f5eecf00-1b00-0000-64bc-426ea00b0000 pid=2976 /usr/bin/wget net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=f5eecf00-1b00-0000-64bc-426ea00b0000 pid=2976 execve guuid=e81d7a04-1b00-0000-64bc-426eaa0b0000 pid=2986 /usr/bin/curl net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=e81d7a04-1b00-0000-64bc-426eaa0b0000 pid=2986 execve guuid=66046d0a-1b00-0000-64bc-426eb50b0000 pid=2997 /usr/bin/chmod guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=66046d0a-1b00-0000-64bc-426eb50b0000 pid=2997 execve guuid=0b80c30a-1b00-0000-64bc-426eb60b0000 pid=2998 /usr/bin/bash guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=0b80c30a-1b00-0000-64bc-426eb60b0000 pid=2998 clone guuid=af08db0a-1b00-0000-64bc-426eb80b0000 pid=3000 /usr/bin/rm guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=af08db0a-1b00-0000-64bc-426eb80b0000 pid=3000 execve guuid=8aa3310b-1b00-0000-64bc-426eba0b0000 pid=3002 /usr/bin/wget net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=8aa3310b-1b00-0000-64bc-426eba0b0000 pid=3002 execve guuid=7baf7f0e-1b00-0000-64bc-426ec20b0000 pid=3010 /usr/bin/curl net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=7baf7f0e-1b00-0000-64bc-426ec20b0000 pid=3010 execve guuid=bd9c8f14-1b00-0000-64bc-426ecb0b0000 pid=3019 /usr/bin/chmod guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=bd9c8f14-1b00-0000-64bc-426ecb0b0000 pid=3019 execve guuid=8aaee414-1b00-0000-64bc-426ecc0b0000 pid=3020 /usr/bin/bash guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=8aaee414-1b00-0000-64bc-426ecc0b0000 pid=3020 clone guuid=dc37f914-1b00-0000-64bc-426ece0b0000 pid=3022 /usr/bin/rm guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=dc37f914-1b00-0000-64bc-426ece0b0000 pid=3022 execve guuid=f56e5415-1b00-0000-64bc-426ed00b0000 pid=3024 /usr/bin/wget net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=f56e5415-1b00-0000-64bc-426ed00b0000 pid=3024 execve guuid=21fbd018-1b00-0000-64bc-426ed80b0000 pid=3032 /usr/bin/curl net guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=21fbd018-1b00-0000-64bc-426ed80b0000 pid=3032 execve guuid=d677e51d-1b00-0000-64bc-426ee10b0000 pid=3041 /usr/bin/chmod guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=d677e51d-1b00-0000-64bc-426ee10b0000 pid=3041 execve guuid=6296561e-1b00-0000-64bc-426ee20b0000 pid=3042 /usr/bin/bash guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=6296561e-1b00-0000-64bc-426ee20b0000 pid=3042 clone guuid=b53f741e-1b00-0000-64bc-426ee40b0000 pid=3044 /usr/bin/rm guuid=3f67be6e-1a00-0000-64bc-426e500a0000 pid=2640->guuid=b53f741e-1b00-0000-64bc-426ee40b0000 pid=3044 execve a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 94.156.152.67:80 guuid=8de3b273-1a00-0000-64bc-426e5e0a0000 pid=2654->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=7f03d778-1a00-0000-64bc-426e6c0a0000 pid=2668->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=2469eb86-1a00-0000-64bc-426e930a0000 pid=2707->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=277cad8a-1a00-0000-64bc-426e9f0a0000 pid=2719->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=2dd73191-1a00-0000-64bc-426eb10a0000 pid=2737->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=8cae1296-1a00-0000-64bc-426ebd0a0000 pid=2749->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=738a5b9c-1a00-0000-64bc-426ecb0a0000 pid=2763->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=cd0800a0-1a00-0000-64bc-426ed50a0000 pid=2773->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=291f94a6-1a00-0000-64bc-426ee20a0000 pid=2786->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=d40493aa-1a00-0000-64bc-426ee30a0000 pid=2787->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=f9a31db1-1a00-0000-64bc-426eef0a0000 pid=2799->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=46b4d2b4-1a00-0000-64bc-426efa0a0000 pid=2810->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=0f8577ba-1a00-0000-64bc-426e0c0b0000 pid=2828->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=bd87dbbd-1a00-0000-64bc-426e140b0000 pid=2836->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=15d77ac4-1a00-0000-64bc-426e1f0b0000 pid=2847->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=f76f51c8-1a00-0000-64bc-426e260b0000 pid=2854->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=35f56dd6-1a00-0000-64bc-426e330b0000 pid=2867->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=ba2ffed9-1a00-0000-64bc-426e3a0b0000 pid=2874->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=bc1998e1-1a00-0000-64bc-426e480b0000 pid=2888->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=d37b45e5-1a00-0000-64bc-426e510b0000 pid=2897->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=313f53ec-1a00-0000-64bc-426e670b0000 pid=2919->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=320b33f0-1a00-0000-64bc-426e710b0000 pid=2929->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=82cb48f7-1a00-0000-64bc-426e860b0000 pid=2950->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=3c38f3fa-1a00-0000-64bc-426e8f0b0000 pid=2959->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=f5eecf00-1b00-0000-64bc-426ea00b0000 pid=2976->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=e81d7a04-1b00-0000-64bc-426eaa0b0000 pid=2986->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=8aa3310b-1b00-0000-64bc-426eba0b0000 pid=3002->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=7baf7f0e-1b00-0000-64bc-426ec20b0000 pid=3010->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=f56e5415-1b00-0000-64bc-426ed00b0000 pid=3024->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con guuid=21fbd018-1b00-0000-64bc-426ed80b0000 pid=3032->a0cce8c1-8de3-5e77-97c2-8db8bf5fa654 con
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2025-12-20 18:15:24 UTC
File Type:
Text (Shell)
AV detection:
12 of 24 (50.00%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 5379e5da6c6eae2eab376717f13ec203dea2307167bbe32fbd2156deabf1d356

(this sample)

  
Delivery method
Distributed via web download

Comments