MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6a7ab437c5dad16b8b36efc7e43c5684cb5076481e0039fc51aa537152d0b5e7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 6a7ab437c5dad16b8b36efc7e43c5684cb5076481e0039fc51aa537152d0b5e7
SHA3-384 hash: fd13c3d0d6836d21d8a4f4324e40c7e67508325b8209afb55201c7a97ad8772ed8916b9aac36fdd593128886b385b601
SHA1 hash: b30c5a8751b92fa28f81e23bf1279966d099ea37
MD5 hash: 6f5fb53e384ceb5f695f277a14a5eb0a
humanhash: early-november-low-arkansas
File name:wget.sh
Download: download sample
File size:765 bytes
First seen:2026-01-20 19:13:57 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:ZKj+YMq+YYNIl5zA+YQc0LKj+Y2DOs+YsC+Yu/+YkuSE+YNQtaKA+YVaj+YsJiAw:ZKdMYYNI7qQfKd2DzsAuZkuB+tBWAsJy
TLSH T1C601CCAD2251614DC40C8F50F16A07745B8FCBD4F0781ED9A9844C73ADDAA10706DF4F
Magika txt
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
24
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=b6e773e7-2000-0000-80dd-98943f0a0000 pid=2623 /usr/bin/sudo guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629 /tmp/sample.bin guuid=b6e773e7-2000-0000-80dd-98943f0a0000 pid=2623->guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629 execve guuid=5e2ba0e9-2000-0000-80dd-9894460a0000 pid=2630 /usr/bin/wget net send-data write-file guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=5e2ba0e9-2000-0000-80dd-9894460a0000 pid=2630 execve guuid=b9753a21-2100-0000-80dd-9894ce0a0000 pid=2766 /usr/bin/chmod guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=b9753a21-2100-0000-80dd-9894ce0a0000 pid=2766 execve guuid=25f9a421-2100-0000-80dd-9894d10a0000 pid=2769 /usr/bin/dash guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=25f9a421-2100-0000-80dd-9894d10a0000 pid=2769 clone guuid=9e096d22-2100-0000-80dd-9894d30a0000 pid=2771 /usr/bin/wget net send-data write-file guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=9e096d22-2100-0000-80dd-9894d30a0000 pid=2771 execve guuid=5d60064a-2100-0000-80dd-9894d40a0000 pid=2772 /usr/bin/chmod guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=5d60064a-2100-0000-80dd-9894d40a0000 pid=2772 execve guuid=1d1a4b4a-2100-0000-80dd-9894d50a0000 pid=2773 /usr/bin/dash guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=1d1a4b4a-2100-0000-80dd-9894d50a0000 pid=2773 clone guuid=9423e84a-2100-0000-80dd-9894d70a0000 pid=2775 /usr/bin/wget net send-data write-file guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=9423e84a-2100-0000-80dd-9894d70a0000 pid=2775 execve guuid=f00fa284-2100-0000-80dd-98942a0b0000 pid=2858 /usr/bin/chmod guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=f00fa284-2100-0000-80dd-98942a0b0000 pid=2858 execve guuid=458be184-2100-0000-80dd-98942c0b0000 pid=2860 /usr/bin/dash guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=458be184-2100-0000-80dd-98942c0b0000 pid=2860 clone guuid=77a2d486-2100-0000-80dd-9894310b0000 pid=2865 /usr/bin/wget net send-data write-file guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=77a2d486-2100-0000-80dd-9894310b0000 pid=2865 execve guuid=b53d96cc-2100-0000-80dd-9894c00b0000 pid=3008 /usr/bin/chmod guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=b53d96cc-2100-0000-80dd-9894c00b0000 pid=3008 execve guuid=831ad8cc-2100-0000-80dd-9894c10b0000 pid=3009 /usr/bin/dash guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=831ad8cc-2100-0000-80dd-9894c10b0000 pid=3009 clone guuid=bbc56dcd-2100-0000-80dd-9894c40b0000 pid=3012 /usr/bin/wget net send-data write-file guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=bbc56dcd-2100-0000-80dd-9894c40b0000 pid=3012 execve guuid=5bbfcf00-2200-0000-80dd-9894490c0000 pid=3145 /usr/bin/chmod guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=5bbfcf00-2200-0000-80dd-9894490c0000 pid=3145 execve guuid=1b0d1c01-2200-0000-80dd-98944b0c0000 pid=3147 /usr/bin/dash guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=1b0d1c01-2200-0000-80dd-98944b0c0000 pid=3147 clone guuid=4458ed01-2200-0000-80dd-9894500c0000 pid=3152 /usr/bin/wget net send-data write-file guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=4458ed01-2200-0000-80dd-9894500c0000 pid=3152 execve guuid=65ade83c-2200-0000-80dd-9894aa0c0000 pid=3242 /usr/bin/chmod guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=65ade83c-2200-0000-80dd-9894aa0c0000 pid=3242 execve guuid=8cd0813d-2200-0000-80dd-9894ab0c0000 pid=3243 /usr/bin/dash guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=8cd0813d-2200-0000-80dd-9894ab0c0000 pid=3243 clone guuid=c940303f-2200-0000-80dd-9894ad0c0000 pid=3245 /usr/bin/wget net send-data write-file guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=c940303f-2200-0000-80dd-9894ad0c0000 pid=3245 execve guuid=67e3bd72-2200-0000-80dd-9894ee0c0000 pid=3310 /usr/bin/chmod guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=67e3bd72-2200-0000-80dd-9894ee0c0000 pid=3310 execve guuid=da341e73-2200-0000-80dd-9894ef0c0000 pid=3311 /usr/bin/dash guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=da341e73-2200-0000-80dd-9894ef0c0000 pid=3311 clone guuid=1d76ad73-2200-0000-80dd-9894f30c0000 pid=3315 /usr/bin/wget net send-data write-file guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=1d76ad73-2200-0000-80dd-9894f30c0000 pid=3315 execve guuid=b96179ac-2200-0000-80dd-9894610d0000 pid=3425 /usr/bin/chmod guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=b96179ac-2200-0000-80dd-9894610d0000 pid=3425 execve guuid=50a1beac-2200-0000-80dd-9894620d0000 pid=3426 /usr/bin/dash guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=50a1beac-2200-0000-80dd-9894620d0000 pid=3426 clone guuid=d98b52ad-2200-0000-80dd-9894640d0000 pid=3428 /usr/bin/wget net send-data write-file guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=d98b52ad-2200-0000-80dd-9894640d0000 pid=3428 execve guuid=ce236fe6-2200-0000-80dd-9894e30d0000 pid=3555 /usr/bin/chmod guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=ce236fe6-2200-0000-80dd-9894e30d0000 pid=3555 execve guuid=ddb7b5e6-2200-0000-80dd-9894e40d0000 pid=3556 /usr/bin/dash guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=ddb7b5e6-2200-0000-80dd-9894e40d0000 pid=3556 clone guuid=c44592e8-2200-0000-80dd-9894ec0d0000 pid=3564 /usr/bin/wget net send-data write-file guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=c44592e8-2200-0000-80dd-9894ec0d0000 pid=3564 execve guuid=bf3e661e-2300-0000-80dd-98945d0e0000 pid=3677 /usr/bin/chmod guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=bf3e661e-2300-0000-80dd-98945d0e0000 pid=3677 execve guuid=25e7c31e-2300-0000-80dd-98945f0e0000 pid=3679 /usr/bin/dash guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=25e7c31e-2300-0000-80dd-98945f0e0000 pid=3679 clone guuid=4b21e11f-2300-0000-80dd-9894650e0000 pid=3685 /usr/bin/wget net send-data write-file guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=4b21e11f-2300-0000-80dd-9894650e0000 pid=3685 execve guuid=bb9da156-2300-0000-80dd-9894340f0000 pid=3892 /usr/bin/chmod guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=bb9da156-2300-0000-80dd-9894340f0000 pid=3892 execve guuid=bfd1dc56-2300-0000-80dd-9894350f0000 pid=3893 /home/sandbox/x86 net guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=bfd1dc56-2300-0000-80dd-9894350f0000 pid=3893 execve guuid=6d569258-2300-0000-80dd-9894410f0000 pid=3905 /usr/bin/wget net send-data write-file guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=6d569258-2300-0000-80dd-9894410f0000 pid=3905 execve guuid=546fc68e-2300-0000-80dd-989407100000 pid=4103 /usr/bin/chmod guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=546fc68e-2300-0000-80dd-989407100000 pid=4103 execve guuid=73651b8f-2300-0000-80dd-989408100000 pid=4104 /home/sandbox/x86_64 net guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=73651b8f-2300-0000-80dd-989408100000 pid=4104 execve guuid=79b9a290-2300-0000-80dd-989414100000 pid=4116 /usr/bin/rm delete-file guuid=d65a55e9-2000-0000-80dd-9894450a0000 pid=2629->guuid=79b9a290-2300-0000-80dd-989414100000 pid=4116 execve e9272886-a735-5495-acea-11202e0d0fe3 103.124.93.149:80 guuid=5e2ba0e9-2000-0000-80dd-9894460a0000 pid=2630->e9272886-a735-5495-acea-11202e0d0fe3 send: 132B guuid=9e096d22-2100-0000-80dd-9894d30a0000 pid=2771->e9272886-a735-5495-acea-11202e0d0fe3 send: 133B guuid=9423e84a-2100-0000-80dd-9894d70a0000 pid=2775->e9272886-a735-5495-acea-11202e0d0fe3 send: 133B guuid=77a2d486-2100-0000-80dd-9894310b0000 pid=2865->e9272886-a735-5495-acea-11202e0d0fe3 send: 133B guuid=bbc56dcd-2100-0000-80dd-9894c40b0000 pid=3012->e9272886-a735-5495-acea-11202e0d0fe3 send: 133B guuid=4458ed01-2200-0000-80dd-9894500c0000 pid=3152->e9272886-a735-5495-acea-11202e0d0fe3 send: 133B guuid=c940303f-2200-0000-80dd-9894ad0c0000 pid=3245->e9272886-a735-5495-acea-11202e0d0fe3 send: 133B guuid=1d76ad73-2200-0000-80dd-9894f30c0000 pid=3315->e9272886-a735-5495-acea-11202e0d0fe3 send: 132B guuid=d98b52ad-2200-0000-80dd-9894640d0000 pid=3428->e9272886-a735-5495-acea-11202e0d0fe3 send: 132B guuid=c44592e8-2200-0000-80dd-9894ec0d0000 pid=3564->e9272886-a735-5495-acea-11202e0d0fe3 send: 132B guuid=4b21e11f-2300-0000-80dd-9894650e0000 pid=3685->e9272886-a735-5495-acea-11202e0d0fe3 send: 132B 75e02d42-b51b-5d27-8d02-47737f4115cc 103.124.93.149:53 guuid=bfd1dc56-2300-0000-80dd-9894350f0000 pid=3893->75e02d42-b51b-5d27-8d02-47737f4115cc con guuid=ae78f556-2300-0000-80dd-9894360f0000 pid=3894 /usr/bin/dash guuid=bfd1dc56-2300-0000-80dd-9894350f0000 pid=3893->guuid=ae78f556-2300-0000-80dd-9894360f0000 pid=3894 execve guuid=400f8e58-2300-0000-80dd-9894400f0000 pid=3904 /home/sandbox/bin/systemd dns net send-data zombie guuid=bfd1dc56-2300-0000-80dd-9894350f0000 pid=3893->guuid=400f8e58-2300-0000-80dd-9894400f0000 pid=3904 clone guuid=de281f57-2300-0000-80dd-9894380f0000 pid=3896 /usr/bin/rm guuid=ae78f556-2300-0000-80dd-9894360f0000 pid=3894->guuid=de281f57-2300-0000-80dd-9894380f0000 pid=3896 execve guuid=ba185c57-2300-0000-80dd-9894390f0000 pid=3897 /usr/bin/mkdir guuid=ae78f556-2300-0000-80dd-9894360f0000 pid=3894->guuid=ba185c57-2300-0000-80dd-9894390f0000 pid=3897 execve guuid=2be6a957-2300-0000-80dd-98943b0f0000 pid=3899 /usr/bin/mv guuid=ae78f556-2300-0000-80dd-9894360f0000 pid=3894->guuid=2be6a957-2300-0000-80dd-98943b0f0000 pid=3899 execve guuid=b4a41458-2300-0000-80dd-98943e0f0000 pid=3902 /usr/bin/chmod guuid=ae78f556-2300-0000-80dd-9894360f0000 pid=3894->guuid=b4a41458-2300-0000-80dd-98943e0f0000 pid=3902 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=400f8e58-2300-0000-80dd-9894400f0000 pid=3904->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 35B d57a74f8-c390-5ef0-a056-525f371ee375 bot.taphoanxn.cfd:56999 guuid=400f8e58-2300-0000-80dd-9894400f0000 pid=3904->d57a74f8-c390-5ef0-a056-525f371ee375 send: 13B 52572bc8-10a5-5075-af21-133a5c079c93 bot.taphoanxn.cfd:53 guuid=400f8e58-2300-0000-80dd-9894400f0000 pid=3904->52572bc8-10a5-5075-af21-133a5c079c93 con guuid=e9939a58-2300-0000-80dd-9894420f0000 pid=3906 /home/sandbox/bin/systemd guuid=400f8e58-2300-0000-80dd-9894400f0000 pid=3904->guuid=e9939a58-2300-0000-80dd-9894420f0000 pid=3906 clone guuid=be5c9e58-2300-0000-80dd-9894430f0000 pid=3907 /home/sandbox/bin/systemd net net-scan send-data guuid=400f8e58-2300-0000-80dd-9894400f0000 pid=3904->guuid=be5c9e58-2300-0000-80dd-9894430f0000 pid=3907 clone 563f4588-1a35-5b6c-ac87-745d295586e8 bot.taphoanxn.cfd:80 guuid=6d569258-2300-0000-80dd-9894410f0000 pid=3905->563f4588-1a35-5b6c-ac87-745d295586e8 send: 135B guuid=be5c9e58-2300-0000-80dd-9894430f0000 pid=3907->75e02d42-b51b-5d27-8d02-47737f4115cc con guuid=be5c9e58-2300-0000-80dd-9894430f0000 pid=3907|send-data send-data to 3099 IP addresses review logs to see them all guuid=be5c9e58-2300-0000-80dd-9894430f0000 pid=3907->guuid=be5c9e58-2300-0000-80dd-9894430f0000 pid=3907|send-data send guuid=73651b8f-2300-0000-80dd-989408100000 pid=4104->52572bc8-10a5-5075-af21-133a5c079c93 con guuid=55d9298f-2300-0000-80dd-989409100000 pid=4105 /usr/bin/dash guuid=73651b8f-2300-0000-80dd-989408100000 pid=4104->guuid=55d9298f-2300-0000-80dd-989409100000 pid=4105 execve guuid=42c09790-2300-0000-80dd-989413100000 pid=4115 /home/sandbox/x86_64 dns net send-data zombie guuid=73651b8f-2300-0000-80dd-989408100000 pid=4104->guuid=42c09790-2300-0000-80dd-989413100000 pid=4115 clone guuid=df17578f-2300-0000-80dd-98940a100000 pid=4106 /usr/bin/rm delete-file guuid=55d9298f-2300-0000-80dd-989409100000 pid=4105->guuid=df17578f-2300-0000-80dd-98940a100000 pid=4106 execve guuid=caf2a28f-2300-0000-80dd-98940d100000 pid=4109 /usr/bin/mkdir guuid=55d9298f-2300-0000-80dd-989409100000 pid=4105->guuid=caf2a28f-2300-0000-80dd-98940d100000 pid=4109 execve guuid=02190f90-2300-0000-80dd-98940f100000 pid=4111 /usr/bin/chmod guuid=55d9298f-2300-0000-80dd-989409100000 pid=4105->guuid=02190f90-2300-0000-80dd-98940f100000 pid=4111 execve guuid=42c09790-2300-0000-80dd-989413100000 pid=4115->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 420B guuid=42c09790-2300-0000-80dd-989413100000 pid=4115->d57a74f8-c390-5ef0-a056-525f371ee375 send: 22B guuid=42c09790-2300-0000-80dd-989413100000 pid=4115->52572bc8-10a5-5075-af21-133a5c079c93 con guuid=00ffa390-2300-0000-80dd-989415100000 pid=4117 /home/sandbox/x86_64 guuid=42c09790-2300-0000-80dd-989413100000 pid=4115->guuid=00ffa390-2300-0000-80dd-989415100000 pid=4117 clone guuid=7b99a890-2300-0000-80dd-989416100000 pid=4118 /home/sandbox/x86_64 net net-scan send-data guuid=42c09790-2300-0000-80dd-989413100000 pid=4115->guuid=7b99a890-2300-0000-80dd-989416100000 pid=4118 clone guuid=7b99a890-2300-0000-80dd-989416100000 pid=4118->52572bc8-10a5-5075-af21-133a5c079c93 con d11a4463-b94b-57c1-a9a1-82cad832a5e6 43.174.210.21:37215 guuid=7b99a890-2300-0000-80dd-989416100000 pid=4118->d11a4463-b94b-57c1-a9a1-82cad832a5e6 send: 854B guuid=7b99a890-2300-0000-80dd-989416100000 pid=4118|send-data send-data to 3061 IP addresses review logs to see them all guuid=7b99a890-2300-0000-80dd-989416100000 pid=4118->guuid=7b99a890-2300-0000-80dd-989416100000 pid=4118|send-data send
Threat name:
Script-Shell.Worm.Mirai
Status:
Malicious
First seen:
2026-01-20 15:39:52 UTC
File Type:
Text (Shell)
AV detection:
15 of 36 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 6a7ab437c5dad16b8b36efc7e43c5684cb5076481e0039fc51aa537152d0b5e7

(this sample)

  
Delivery method
Distributed via web download

Comments