MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 746f6ba7c116f58ae0f4a338a712f37fb501b3b6dd76071a5317285d86054e89. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 3 File information Comments

SHA256 hash: 746f6ba7c116f58ae0f4a338a712f37fb501b3b6dd76071a5317285d86054e89
SHA3-384 hash: 50f762abba79f10b5b3007c29310c898427a8298bae1709bc4ea77a66680d8319156f1449a554b48c1311c32227b8cfe
SHA1 hash: 0ce025e0c36e2a6c59a51ef8e8624df77b0bec21
MD5 hash: d7b8dfec38ffede081387e63db51a0fe
humanhash: magazine-queen-april-lake
File name:bins.sh
Download: download sample
File size:2'092 bytes
First seen:2026-01-11 02:08:23 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vb2Kjeb4/b2Fb0bqJbEb4bIbjUbaJbwbqLbz4bMyZo4:vb2KjebYb2Fb0bQbEb4bIbjUbAbwbqLY
TLSH T1874132CA31620D74BC629913767FA88431B4E1AA60EDDF59ECDE3CE9848DD587410E93
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://151.243.109.160/Demon.mipsn/an/aelf ua-wget
http://151.243.109.160/Demon.mpsln/an/aelf ua-wget
http://151.243.109.160/Demon.sh4n/an/aelf ua-wget
http://151.243.109.160/Demon.x86n/an/aelf ua-wget
http://151.243.109.160/Demon.arm6n/an/aelf ua-wget
http://151.243.109.160/Demon.i686n/an/aelf ua-wget
http://151.243.109.160/Demon.ppcn/an/aelf ua-wget
http://151.243.109.160/Demon.i586n/an/aelf ua-wget
http://151.243.109.160/Demon.m68kn/an/aelf ua-wget
http://151.243.109.160/Demon.sparcn/an/aelf ua-wget
http://151.243.109.160/Demon.arm4n/an/aelf ua-wget
http://151.243.109.160/Demon.arm5n/an/aelf ua-wget
http://151.243.109.160/Demon.arm7n/an/aelf ua-wget
http://151.243.109.160/Demon.ppc440fpn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
50
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-09T14:36:00Z UTC
Last seen:
2026-01-11T00:07:00Z UTC
Hits:
~100
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=5e47907d-1800-0000-4607-b89e640b0000 pid=2916 /usr/bin/sudo guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923 /tmp/sample.bin guuid=5e47907d-1800-0000-4607-b89e640b0000 pid=2916->guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923 execve guuid=9ef92381-1800-0000-4607-b89e6c0b0000 pid=2924 /usr/bin/wget net send-data write-file guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=9ef92381-1800-0000-4607-b89e6c0b0000 pid=2924 execve guuid=c6c8378a-1800-0000-4607-b89e780b0000 pid=2936 /usr/bin/chmod guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=c6c8378a-1800-0000-4607-b89e780b0000 pid=2936 execve guuid=b29c7e8a-1800-0000-4607-b89e790b0000 pid=2937 /usr/bin/bash guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=b29c7e8a-1800-0000-4607-b89e790b0000 pid=2937 clone guuid=0044028b-1800-0000-4607-b89e7d0b0000 pid=2941 /usr/bin/rm delete-file guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=0044028b-1800-0000-4607-b89e7d0b0000 pid=2941 execve guuid=dd57468b-1800-0000-4607-b89e7f0b0000 pid=2943 /usr/bin/wget net send-data write-file guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=dd57468b-1800-0000-4607-b89e7f0b0000 pid=2943 execve guuid=3f294a90-1800-0000-4607-b89e8b0b0000 pid=2955 /usr/bin/chmod guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=3f294a90-1800-0000-4607-b89e8b0b0000 pid=2955 execve guuid=a187bd90-1800-0000-4607-b89e8d0b0000 pid=2957 /usr/bin/bash guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=a187bd90-1800-0000-4607-b89e8d0b0000 pid=2957 clone guuid=a78c7991-1800-0000-4607-b89e8f0b0000 pid=2959 /usr/bin/rm delete-file guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=a78c7991-1800-0000-4607-b89e8f0b0000 pid=2959 execve guuid=f9b1d991-1800-0000-4607-b89e900b0000 pid=2960 /usr/bin/wget net send-data write-file guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=f9b1d991-1800-0000-4607-b89e900b0000 pid=2960 execve guuid=eb8a4596-1800-0000-4607-b89e990b0000 pid=2969 /usr/bin/chmod guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=eb8a4596-1800-0000-4607-b89e990b0000 pid=2969 execve guuid=377ed196-1800-0000-4607-b89e9a0b0000 pid=2970 /usr/bin/bash guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=377ed196-1800-0000-4607-b89e9a0b0000 pid=2970 clone guuid=63dc9497-1800-0000-4607-b89e9d0b0000 pid=2973 /usr/bin/rm delete-file guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=63dc9497-1800-0000-4607-b89e9d0b0000 pid=2973 execve guuid=2dafe897-1800-0000-4607-b89e9e0b0000 pid=2974 /usr/bin/wget net send-data write-file guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=2dafe897-1800-0000-4607-b89e9e0b0000 pid=2974 execve guuid=736b949c-1800-0000-4607-b89ea80b0000 pid=2984 /usr/bin/chmod guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=736b949c-1800-0000-4607-b89ea80b0000 pid=2984 execve guuid=df37d59c-1800-0000-4607-b89eaa0b0000 pid=2986 /tmp/Demon.x86 net guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=df37d59c-1800-0000-4607-b89eaa0b0000 pid=2986 execve guuid=fc23169d-1800-0000-4607-b89eae0b0000 pid=2990 /usr/bin/rm delete-file guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=fc23169d-1800-0000-4607-b89eae0b0000 pid=2990 execve guuid=53e2589d-1800-0000-4607-b89eb00b0000 pid=2992 /usr/bin/wget net send-data write-file guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=53e2589d-1800-0000-4607-b89eb00b0000 pid=2992 execve guuid=f84409a3-1800-0000-4607-b89ebc0b0000 pid=3004 /usr/bin/chmod guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=f84409a3-1800-0000-4607-b89ebc0b0000 pid=3004 execve guuid=9ab754a3-1800-0000-4607-b89ebe0b0000 pid=3006 /usr/bin/bash guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=9ab754a3-1800-0000-4607-b89ebe0b0000 pid=3006 clone guuid=6a332ba5-1800-0000-4607-b89ec50b0000 pid=3013 /usr/bin/rm delete-file guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=6a332ba5-1800-0000-4607-b89ec50b0000 pid=3013 execve guuid=f79c8aa5-1800-0000-4607-b89ec70b0000 pid=3015 /usr/bin/wget net send-data guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=f79c8aa5-1800-0000-4607-b89ec70b0000 pid=3015 execve guuid=f3e56aa8-1800-0000-4607-b89ecd0b0000 pid=3021 /usr/bin/chmod guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=f3e56aa8-1800-0000-4607-b89ecd0b0000 pid=3021 execve guuid=b987cea8-1800-0000-4607-b89ecf0b0000 pid=3023 /usr/bin/bash guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=b987cea8-1800-0000-4607-b89ecf0b0000 pid=3023 clone guuid=7167f6a8-1800-0000-4607-b89ed10b0000 pid=3025 /usr/bin/rm guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=7167f6a8-1800-0000-4607-b89ed10b0000 pid=3025 execve guuid=5e814ea9-1800-0000-4607-b89ed20b0000 pid=3026 /usr/bin/wget net send-data write-file guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=5e814ea9-1800-0000-4607-b89ed20b0000 pid=3026 execve guuid=d027e7ad-1800-0000-4607-b89edc0b0000 pid=3036 /usr/bin/chmod guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=d027e7ad-1800-0000-4607-b89edc0b0000 pid=3036 execve guuid=d0ea28ae-1800-0000-4607-b89ede0b0000 pid=3038 /usr/bin/bash guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=d0ea28ae-1800-0000-4607-b89ede0b0000 pid=3038 clone guuid=0625bdae-1800-0000-4607-b89ee20b0000 pid=3042 /usr/bin/rm delete-file guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=0625bdae-1800-0000-4607-b89ee20b0000 pid=3042 execve guuid=5c6308af-1800-0000-4607-b89ee30b0000 pid=3043 /usr/bin/wget net send-data write-file guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=5c6308af-1800-0000-4607-b89ee30b0000 pid=3043 execve guuid=7fd090b3-1800-0000-4607-b89eef0b0000 pid=3055 /usr/bin/chmod guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=7fd090b3-1800-0000-4607-b89eef0b0000 pid=3055 execve guuid=1ba00cb4-1800-0000-4607-b89ef20b0000 pid=3058 /tmp/Demon.i586 net guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=1ba00cb4-1800-0000-4607-b89ef20b0000 pid=3058 execve guuid=ea44a7b5-1800-0000-4607-b89efa0b0000 pid=3066 /usr/bin/rm delete-file guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=ea44a7b5-1800-0000-4607-b89efa0b0000 pid=3066 execve guuid=9fa919b6-1800-0000-4607-b89efc0b0000 pid=3068 /usr/bin/wget net send-data write-file guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=9fa919b6-1800-0000-4607-b89efc0b0000 pid=3068 execve guuid=00f6a7ba-1800-0000-4607-b89e0b0c0000 pid=3083 /usr/bin/chmod guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=00f6a7ba-1800-0000-4607-b89e0b0c0000 pid=3083 execve guuid=5993e6ba-1800-0000-4607-b89e0c0c0000 pid=3084 /usr/bin/bash guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=5993e6ba-1800-0000-4607-b89e0c0c0000 pid=3084 clone guuid=be14d8bb-1800-0000-4607-b89e110c0000 pid=3089 /usr/bin/rm delete-file guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=be14d8bb-1800-0000-4607-b89e110c0000 pid=3089 execve guuid=587828bc-1800-0000-4607-b89e130c0000 pid=3091 /usr/bin/wget net send-data write-file guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=587828bc-1800-0000-4607-b89e130c0000 pid=3091 execve guuid=a215afc2-1800-0000-4607-b89e240c0000 pid=3108 /usr/bin/chmod guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=a215afc2-1800-0000-4607-b89e240c0000 pid=3108 execve guuid=027e2fc3-1800-0000-4607-b89e260c0000 pid=3110 /usr/bin/bash guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=027e2fc3-1800-0000-4607-b89e260c0000 pid=3110 clone guuid=afdc24c4-1800-0000-4607-b89e2a0c0000 pid=3114 /usr/bin/rm delete-file guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=afdc24c4-1800-0000-4607-b89e2a0c0000 pid=3114 execve guuid=068296c4-1800-0000-4607-b89e2c0c0000 pid=3116 /usr/bin/wget net send-data write-file guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=068296c4-1800-0000-4607-b89e2c0c0000 pid=3116 execve guuid=ede15cc9-1800-0000-4607-b89e360c0000 pid=3126 /usr/bin/chmod guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=ede15cc9-1800-0000-4607-b89e360c0000 pid=3126 execve guuid=c6e699c9-1800-0000-4607-b89e380c0000 pid=3128 /usr/bin/bash guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=c6e699c9-1800-0000-4607-b89e380c0000 pid=3128 clone guuid=8fb538ca-1800-0000-4607-b89e3c0c0000 pid=3132 /usr/bin/rm delete-file guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=8fb538ca-1800-0000-4607-b89e3c0c0000 pid=3132 execve guuid=04ad90ca-1800-0000-4607-b89e3e0c0000 pid=3134 /usr/bin/wget net send-data write-file guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=04ad90ca-1800-0000-4607-b89e3e0c0000 pid=3134 execve guuid=c5650ccf-1800-0000-4607-b89e480c0000 pid=3144 /usr/bin/chmod guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=c5650ccf-1800-0000-4607-b89e480c0000 pid=3144 execve guuid=23a366cf-1800-0000-4607-b89e4a0c0000 pid=3146 /usr/bin/bash guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=23a366cf-1800-0000-4607-b89e4a0c0000 pid=3146 clone guuid=0b041cd0-1800-0000-4607-b89e4d0c0000 pid=3149 /usr/bin/rm delete-file guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=0b041cd0-1800-0000-4607-b89e4d0c0000 pid=3149 execve guuid=d93d82d0-1800-0000-4607-b89e500c0000 pid=3152 /usr/bin/wget net send-data write-file guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=d93d82d0-1800-0000-4607-b89e500c0000 pid=3152 execve guuid=a844edd5-1800-0000-4607-b89e5d0c0000 pid=3165 /usr/bin/chmod guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=a844edd5-1800-0000-4607-b89e5d0c0000 pid=3165 execve guuid=624c2dd6-1800-0000-4607-b89e5f0c0000 pid=3167 /usr/bin/bash guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=624c2dd6-1800-0000-4607-b89e5f0c0000 pid=3167 clone guuid=5c6e63d7-1800-0000-4607-b89e640c0000 pid=3172 /usr/bin/rm delete-file guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=5c6e63d7-1800-0000-4607-b89e640c0000 pid=3172 execve guuid=5abfcad7-1800-0000-4607-b89e660c0000 pid=3174 /usr/bin/wget net send-data guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=5abfcad7-1800-0000-4607-b89e660c0000 pid=3174 execve guuid=768298da-1800-0000-4607-b89e6e0c0000 pid=3182 /usr/bin/chmod guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=768298da-1800-0000-4607-b89e6e0c0000 pid=3182 execve guuid=9af5eeda-1800-0000-4607-b89e700c0000 pid=3184 /usr/bin/bash guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=9af5eeda-1800-0000-4607-b89e700c0000 pid=3184 clone guuid=644905db-1800-0000-4607-b89e710c0000 pid=3185 /usr/bin/rm guuid=8f855e80-1800-0000-4607-b89e6b0b0000 pid=2923->guuid=644905db-1800-0000-4607-b89e710c0000 pid=3185 execve 0aac434d-04b0-54fc-9625-99ac468c07b7 151.243.109.160:80 guuid=9ef92381-1800-0000-4607-b89e6c0b0000 pid=2924->0aac434d-04b0-54fc-9625-99ac468c07b7 send: 140B guuid=dd57468b-1800-0000-4607-b89e7f0b0000 pid=2943->0aac434d-04b0-54fc-9625-99ac468c07b7 send: 140B guuid=f9b1d991-1800-0000-4607-b89e900b0000 pid=2960->0aac434d-04b0-54fc-9625-99ac468c07b7 send: 139B guuid=2dafe897-1800-0000-4607-b89e9e0b0000 pid=2974->0aac434d-04b0-54fc-9625-99ac468c07b7 send: 139B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=df37d59c-1800-0000-4607-b89eaa0b0000 pid=2986->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ce2d059d-1800-0000-4607-b89eac0b0000 pid=2988 /tmp/Demon.x86 guuid=df37d59c-1800-0000-4607-b89eaa0b0000 pid=2986->guuid=ce2d059d-1800-0000-4607-b89eac0b0000 pid=2988 clone guuid=4b100a9d-1800-0000-4607-b89ead0b0000 pid=2989 /tmp/Demon.x86 net send-data zombie guuid=ce2d059d-1800-0000-4607-b89eac0b0000 pid=2988->guuid=4b100a9d-1800-0000-4607-b89ead0b0000 pid=2989 clone 45229030-59e0-5b11-b396-7b93eb5187f0 151.243.109.160:12345 guuid=4b100a9d-1800-0000-4607-b89ead0b0000 pid=2989->45229030-59e0-5b11-b396-7b93eb5187f0 send: 198B guuid=53e2589d-1800-0000-4607-b89eb00b0000 pid=2992->0aac434d-04b0-54fc-9625-99ac468c07b7 send: 140B guuid=f79c8aa5-1800-0000-4607-b89ec70b0000 pid=3015->0aac434d-04b0-54fc-9625-99ac468c07b7 send: 140B guuid=5e814ea9-1800-0000-4607-b89ed20b0000 pid=3026->0aac434d-04b0-54fc-9625-99ac468c07b7 send: 139B guuid=5c6308af-1800-0000-4607-b89ee30b0000 pid=3043->0aac434d-04b0-54fc-9625-99ac468c07b7 send: 140B guuid=1ba00cb4-1800-0000-4607-b89ef20b0000 pid=3058->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ae3286b5-1800-0000-4607-b89ef70b0000 pid=3063 /tmp/Demon.i586 guuid=1ba00cb4-1800-0000-4607-b89ef20b0000 pid=3058->guuid=ae3286b5-1800-0000-4607-b89ef70b0000 pid=3063 clone guuid=857d90b5-1800-0000-4607-b89ef80b0000 pid=3064 /tmp/Demon.i586 net send-data zombie guuid=ae3286b5-1800-0000-4607-b89ef70b0000 pid=3063->guuid=857d90b5-1800-0000-4607-b89ef80b0000 pid=3064 clone guuid=857d90b5-1800-0000-4607-b89ef80b0000 pid=3064->45229030-59e0-5b11-b396-7b93eb5187f0 send: 198B guuid=9fa919b6-1800-0000-4607-b89efc0b0000 pid=3068->0aac434d-04b0-54fc-9625-99ac468c07b7 send: 140B guuid=587828bc-1800-0000-4607-b89e130c0000 pid=3091->0aac434d-04b0-54fc-9625-99ac468c07b7 send: 141B guuid=068296c4-1800-0000-4607-b89e2c0c0000 pid=3116->0aac434d-04b0-54fc-9625-99ac468c07b7 send: 140B guuid=04ad90ca-1800-0000-4607-b89e3e0c0000 pid=3134->0aac434d-04b0-54fc-9625-99ac468c07b7 send: 140B guuid=d93d82d0-1800-0000-4607-b89e500c0000 pid=3152->0aac434d-04b0-54fc-9625-99ac468c07b7 send: 140B guuid=5abfcad7-1800-0000-4607-b89e660c0000 pid=3174->0aac434d-04b0-54fc-9625-99ac468c07b7 send: 144B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2026-01-09 22:39:01 UTC
AV detection:
17 of 24 (70.83%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
Reads system network configuration
Reads system routing table
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 746f6ba7c116f58ae0f4a338a712f37fb501b3b6dd76071a5317285d86054e89

(this sample)

  
Delivery method
Distributed via web download

Comments