MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 72338acaf95cf0e6347393b45d080bde00964a23023f39f563c971a8158d1df0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 72338acaf95cf0e6347393b45d080bde00964a23023f39f563c971a8158d1df0
SHA3-384 hash: 040a910a19f1294488d278b3a24014caaab99ee7add35d88c0425d745c541eda9b7ce36387c1305067408d3dd1ac1d17
SHA1 hash: 1643c6665365107f1f90f31225f36519a6ac285a
MD5 hash: e52455a8dbbb1beec20a7ced41bd6af0
humanhash: potato-timing-autumn-apart
File name:cat.sh
Download: download sample
File size:1'873 bytes
First seen:2026-02-14 19:11:19 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:MIgeHDd+R56qO1Zdit848BM/hIIlI1bZINI2wxhE6fyGUo7cXtgKmMdJ0Z84+GPd:Gw1i1jo7+8
TLSH T10131848F71B04A69A5CCCE4071E16DC8E78599A97FB00A32DDD10EEB44C9E4437CDAB5
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
30
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=f1ffc57a-1600-0000-e7e9-49d8ab100000 pid=4267 /usr/bin/sudo guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273 /tmp/sample.bin guuid=f1ffc57a-1600-0000-e7e9-49d8ab100000 pid=4267->guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273 execve guuid=cc4ca97c-1600-0000-e7e9-49d8b2100000 pid=4274 /usr/bin/wget net send-data write-file guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=cc4ca97c-1600-0000-e7e9-49d8b2100000 pid=4274 execve guuid=6ea99982-1600-0000-e7e9-49d8c8100000 pid=4296 /usr/bin/chmod guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=6ea99982-1600-0000-e7e9-49d8c8100000 pid=4296 execve guuid=df3be282-1600-0000-e7e9-49d8ca100000 pid=4298 /home/sandbox/iran.x86_64 mprotect-exec guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=df3be282-1600-0000-e7e9-49d8ca100000 pid=4298 execve guuid=f2e50084-1600-0000-e7e9-49d8d1100000 pid=4305 /usr/bin/wget net send-data write-file guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=f2e50084-1600-0000-e7e9-49d8d1100000 pid=4305 execve guuid=7d71638a-1600-0000-e7e9-49d8e7100000 pid=4327 /usr/bin/chmod guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=7d71638a-1600-0000-e7e9-49d8e7100000 pid=4327 execve guuid=1b10f08a-1600-0000-e7e9-49d8ea100000 pid=4330 /usr/bin/dash guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=1b10f08a-1600-0000-e7e9-49d8ea100000 pid=4330 clone guuid=83e8b58c-1600-0000-e7e9-49d8f4100000 pid=4340 /usr/bin/wget net send-data write-file guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=83e8b58c-1600-0000-e7e9-49d8f4100000 pid=4340 execve guuid=392628d1-1600-0000-e7e9-49d839120000 pid=4665 /usr/bin/chmod guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=392628d1-1600-0000-e7e9-49d839120000 pid=4665 execve guuid=b46368d1-1600-0000-e7e9-49d83d120000 pid=4669 /usr/bin/dash guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=b46368d1-1600-0000-e7e9-49d83d120000 pid=4669 clone guuid=4af8fbd1-1600-0000-e7e9-49d841120000 pid=4673 /usr/bin/wget net send-data write-file guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=4af8fbd1-1600-0000-e7e9-49d841120000 pid=4673 execve guuid=ffd8d8d7-1600-0000-e7e9-49d85c120000 pid=4700 /usr/bin/chmod guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=ffd8d8d7-1600-0000-e7e9-49d85c120000 pid=4700 execve guuid=a3e418d8-1600-0000-e7e9-49d860120000 pid=4704 /usr/bin/dash guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=a3e418d8-1600-0000-e7e9-49d860120000 pid=4704 clone guuid=ce41a4d8-1600-0000-e7e9-49d863120000 pid=4707 /usr/bin/wget net send-data write-file guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=ce41a4d8-1600-0000-e7e9-49d863120000 pid=4707 execve guuid=942100df-1600-0000-e7e9-49d882120000 pid=4738 /usr/bin/chmod guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=942100df-1600-0000-e7e9-49d882120000 pid=4738 execve guuid=974a41df-1600-0000-e7e9-49d885120000 pid=4741 /usr/bin/dash guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=974a41df-1600-0000-e7e9-49d885120000 pid=4741 clone guuid=2dcb6ee0-1600-0000-e7e9-49d88a120000 pid=4746 /usr/bin/wget net send-data write-file guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=2dcb6ee0-1600-0000-e7e9-49d88a120000 pid=4746 execve guuid=ef31b9e5-1600-0000-e7e9-49d893120000 pid=4755 /usr/bin/chmod guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=ef31b9e5-1600-0000-e7e9-49d893120000 pid=4755 execve guuid=8357f4e5-1600-0000-e7e9-49d895120000 pid=4757 /usr/bin/dash guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=8357f4e5-1600-0000-e7e9-49d895120000 pid=4757 clone guuid=4c3f6ce6-1600-0000-e7e9-49d898120000 pid=4760 /usr/bin/wget net send-data write-file guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=4c3f6ce6-1600-0000-e7e9-49d898120000 pid=4760 execve guuid=23a02ce9-1600-0000-e7e9-49d8a4120000 pid=4772 /usr/bin/chmod guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=23a02ce9-1600-0000-e7e9-49d8a4120000 pid=4772 execve guuid=9b3b61e9-1600-0000-e7e9-49d8a6120000 pid=4774 /usr/bin/dash guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=9b3b61e9-1600-0000-e7e9-49d8a6120000 pid=4774 clone guuid=73e3d5e9-1600-0000-e7e9-49d8aa120000 pid=4778 /usr/bin/wget net send-data write-file guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=73e3d5e9-1600-0000-e7e9-49d8aa120000 pid=4778 execve guuid=6056abee-1600-0000-e7e9-49d8bf120000 pid=4799 /usr/bin/chmod guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=6056abee-1600-0000-e7e9-49d8bf120000 pid=4799 execve guuid=60a0e5ee-1600-0000-e7e9-49d8c1120000 pid=4801 /usr/bin/dash guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=60a0e5ee-1600-0000-e7e9-49d8c1120000 pid=4801 clone guuid=578261ef-1600-0000-e7e9-49d8c5120000 pid=4805 /usr/bin/wget net send-data write-file guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=578261ef-1600-0000-e7e9-49d8c5120000 pid=4805 execve guuid=4ea3a1f4-1600-0000-e7e9-49d8dc120000 pid=4828 /usr/bin/chmod guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=4ea3a1f4-1600-0000-e7e9-49d8dc120000 pid=4828 execve guuid=8e29dcf4-1600-0000-e7e9-49d8de120000 pid=4830 /usr/bin/dash guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=8e29dcf4-1600-0000-e7e9-49d8de120000 pid=4830 clone guuid=25dc58f5-1600-0000-e7e9-49d8e2120000 pid=4834 /usr/bin/wget net send-data write-file guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=25dc58f5-1600-0000-e7e9-49d8e2120000 pid=4834 execve guuid=135879f9-1600-0000-e7e9-49d8f5120000 pid=4853 /usr/bin/chmod guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=135879f9-1600-0000-e7e9-49d8f5120000 pid=4853 execve guuid=c6f9aff9-1600-0000-e7e9-49d8f7120000 pid=4855 /home/sandbox/iran.i486 guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=c6f9aff9-1600-0000-e7e9-49d8f7120000 pid=4855 execve guuid=ab6cf8f9-1600-0000-e7e9-49d8fc120000 pid=4860 /usr/bin/wget net send-data write-file guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=ab6cf8f9-1600-0000-e7e9-49d8fc120000 pid=4860 execve guuid=52691f02-1700-0000-e7e9-49d817130000 pid=4887 /usr/bin/chmod guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=52691f02-1700-0000-e7e9-49d817130000 pid=4887 execve guuid=edb1b102-1700-0000-e7e9-49d81a130000 pid=4890 /usr/bin/dash guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=edb1b102-1700-0000-e7e9-49d81a130000 pid=4890 clone guuid=7f4a8603-1700-0000-e7e9-49d81f130000 pid=4895 /usr/bin/wget net send-data write-file guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=7f4a8603-1700-0000-e7e9-49d81f130000 pid=4895 execve guuid=ab85d409-1700-0000-e7e9-49d833130000 pid=4915 /usr/bin/chmod guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=ab85d409-1700-0000-e7e9-49d833130000 pid=4915 execve guuid=cc4a220a-1700-0000-e7e9-49d835130000 pid=4917 /usr/bin/dash guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=cc4a220a-1700-0000-e7e9-49d835130000 pid=4917 clone guuid=88a6be0a-1700-0000-e7e9-49d839130000 pid=4921 /usr/bin/wget net send-data write-file guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=88a6be0a-1700-0000-e7e9-49d839130000 pid=4921 execve guuid=27264310-1700-0000-e7e9-49d84b130000 pid=4939 /usr/bin/chmod guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=27264310-1700-0000-e7e9-49d84b130000 pid=4939 execve guuid=fe3a8d10-1700-0000-e7e9-49d84e130000 pid=4942 /usr/bin/dash guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=fe3a8d10-1700-0000-e7e9-49d84e130000 pid=4942 clone guuid=4322a911-1700-0000-e7e9-49d854130000 pid=4948 /usr/bin/wget net send-data write-file guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=4322a911-1700-0000-e7e9-49d854130000 pid=4948 execve guuid=ec942816-1700-0000-e7e9-49d863130000 pid=4963 /usr/bin/chmod guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=ec942816-1700-0000-e7e9-49d863130000 pid=4963 execve guuid=f7b17d16-1700-0000-e7e9-49d865130000 pid=4965 /usr/bin/dash guuid=07a06a7c-1600-0000-e7e9-49d8b1100000 pid=4273->guuid=f7b17d16-1700-0000-e7e9-49d865130000 pid=4965 clone 465b7190-3501-545b-b6aa-fbcf9cff6a23 130.12.180.85:80 guuid=cc4ca97c-1600-0000-e7e9-49d8b2100000 pid=4274->465b7190-3501-545b-b6aa-fbcf9cff6a23 send: 139B guuid=89f8f883-1600-0000-e7e9-49d8d0100000 pid=4304 /home/sandbox/iran.x86_64 zombie guuid=df3be282-1600-0000-e7e9-49d8ca100000 pid=4298->guuid=89f8f883-1600-0000-e7e9-49d8d0100000 pid=4304 clone guuid=b8a40184-1600-0000-e7e9-49d8d2100000 pid=4306 /home/sandbox/iran.x86_64 delete-file net send-data zombie guuid=89f8f883-1600-0000-e7e9-49d8d0100000 pid=4304->guuid=b8a40184-1600-0000-e7e9-49d8d2100000 pid=4306 clone guuid=f2e50084-1600-0000-e7e9-49d8d1100000 pid=4305->465b7190-3501-545b-b6aa-fbcf9cff6a23 send: 140B 1c9fb318-7bbc-587e-9634-567b0e1604ea 130.12.180.85:7080 guuid=b8a40184-1600-0000-e7e9-49d8d2100000 pid=4306->1c9fb318-7bbc-587e-9634-567b0e1604ea send: 413B guuid=83e8b58c-1600-0000-e7e9-49d8f4100000 pid=4340->465b7190-3501-545b-b6aa-fbcf9cff6a23 send: 137B guuid=4af8fbd1-1600-0000-e7e9-49d841120000 pid=4673->465b7190-3501-545b-b6aa-fbcf9cff6a23 send: 137B guuid=ce41a4d8-1600-0000-e7e9-49d863120000 pid=4707->465b7190-3501-545b-b6aa-fbcf9cff6a23 send: 139B guuid=2dcb6ee0-1600-0000-e7e9-49d88a120000 pid=4746->465b7190-3501-545b-b6aa-fbcf9cff6a23 send: 140B guuid=4c3f6ce6-1600-0000-e7e9-49d898120000 pid=4760->465b7190-3501-545b-b6aa-fbcf9cff6a23 send: 138B guuid=73e3d5e9-1600-0000-e7e9-49d8aa120000 pid=4778->465b7190-3501-545b-b6aa-fbcf9cff6a23 send: 136B guuid=578261ef-1600-0000-e7e9-49d8c5120000 pid=4805->465b7190-3501-545b-b6aa-fbcf9cff6a23 send: 136B guuid=25dc58f5-1600-0000-e7e9-49d8e2120000 pid=4834->465b7190-3501-545b-b6aa-fbcf9cff6a23 send: 137B guuid=42bdf0f9-1600-0000-e7e9-49d8f9120000 pid=4857 /home/sandbox/iran.i486 guuid=c6f9aff9-1600-0000-e7e9-49d8f7120000 pid=4855->guuid=42bdf0f9-1600-0000-e7e9-49d8f9120000 pid=4857 clone guuid=d464f7f9-1600-0000-e7e9-49d8fb120000 pid=4859 /home/sandbox/iran.i486 delete-file net send-data zombie guuid=42bdf0f9-1600-0000-e7e9-49d8f9120000 pid=4857->guuid=d464f7f9-1600-0000-e7e9-49d8fb120000 pid=4859 clone guuid=d464f7f9-1600-0000-e7e9-49d8fb120000 pid=4859->1c9fb318-7bbc-587e-9634-567b0e1604ea send: 836B guuid=ab6cf8f9-1600-0000-e7e9-49d8fc120000 pid=4860->465b7190-3501-545b-b6aa-fbcf9cff6a23 send: 139B guuid=7f4a8603-1700-0000-e7e9-49d81f130000 pid=4895->465b7190-3501-545b-b6aa-fbcf9cff6a23 send: 139B guuid=88a6be0a-1700-0000-e7e9-49d839130000 pid=4921->465b7190-3501-545b-b6aa-fbcf9cff6a23 send: 139B guuid=4322a911-1700-0000-e7e9-49d854130000 pid=4948->465b7190-3501-545b-b6aa-fbcf9cff6a23 send: 139B
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2026-02-13 22:45:42 UTC
File Type:
Text (Shell)
AV detection:
10 of 36 (27.78%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
UPX packed file
Enumerates running processes
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 72338acaf95cf0e6347393b45d080bde00964a23023f39f563c971a8158d1df0

(this sample)

  
Delivery method
Distributed via web download

Comments