MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 749441f67c977e570be5b60b8a34aa3fcc25846a78a01cd64163b9d02337a1fb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 3 File information Comments

SHA256 hash: 749441f67c977e570be5b60b8a34aa3fcc25846a78a01cd64163b9d02337a1fb
SHA3-384 hash: caf0230bc86f0034dcc864126228b8f0cc2696c6dd496edf164d7607142b96e93643b7bd60a8fba7de99b6f3ac3b9724
SHA1 hash: be46470d155046dbeb0ad7ff9c2c9a0a2bc6d9a4
MD5 hash: 61a4375af4b62a589a2b52f76a0ecd93
humanhash: muppet-leopard-beryllium-angel
File name:bot.sh
Download: download sample
File size:2'421 bytes
First seen:2026-02-20 05:34:05 UTC
Last seen:2026-02-20 12:02:33 UTC
File type: sh
MIME type:text/plain
ssdeep 24:UDgtgfWRDb3DW2NWSdpOJUDgRRgRv0JTD8EsDkVDFtxDkBDRPR0JLsDRTDUNFDTN:UkWfWRnNbE8Yfs8/xMVFQH0i
TLSH T10641518930924E71E986ADD373AE9844B480F4DBA5CADFB198DD38E190CED14709A6C3
Magika txt
Reporter adliwahid
URLMalware sample (SHA256 hash)SignatureTags
http://156.246.95.51/bot.arcn/an/an/a
http://156.246.95.51/bot.x86_64n/an/an/a
http://156.246.95.51/bot.sh4n/an/an/a
http://156.246.95.51/bot.powerpcn/an/an/a
http://156.246.95.51/bot.mipsroutern/an/an/a
http://156.246.95.51/bot.mipseln/an/an/a
http://156.246.95.51/bot.mipsn/an/an/a
http://156.246.95.51/bot.m68kn/an/an/a
http://156.246.95.51/bot.i486n/an/an/a
http://156.246.95.51/bot.armv7ln/an/an/a
http://156.246.95.51/bot.armv6ln/an/an/a
http://156.246.95.51/bot.armv5ln/an/an/a
http://156.246.95.51/bot.armv4ln/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
61
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=f086f0df-1900-0000-622e-5114d7070000 pid=2007 /usr/bin/sudo guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012 /tmp/sample.bin guuid=f086f0df-1900-0000-622e-5114d7070000 pid=2007->guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012 execve guuid=5dc40de3-1900-0000-622e-5114de070000 pid=2014 /usr/bin/wget net send-data write-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=5dc40de3-1900-0000-622e-5114de070000 pid=2014 execve guuid=2fad1e46-1a00-0000-622e-5114b5080000 pid=2229 /usr/bin/curl net send-data write-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=2fad1e46-1a00-0000-622e-5114b5080000 pid=2229 execve guuid=1d9491f0-1a00-0000-622e-51141d0a0000 pid=2589 /usr/bin/chmod guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=1d9491f0-1a00-0000-622e-51141d0a0000 pid=2589 execve guuid=1a14f5f0-1a00-0000-622e-51141f0a0000 pid=2591 /usr/bin/dash guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=1a14f5f0-1a00-0000-622e-51141f0a0000 pid=2591 execve guuid=f1b753f1-1a00-0000-622e-5114210a0000 pid=2593 /usr/bin/rm delete-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=f1b753f1-1a00-0000-622e-5114210a0000 pid=2593 execve guuid=4561a8f1-1a00-0000-622e-5114230a0000 pid=2595 /usr/bin/wget net send-data write-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=4561a8f1-1a00-0000-622e-5114230a0000 pid=2595 execve guuid=12fa242c-1b00-0000-622e-5114c10a0000 pid=2753 /usr/bin/curl net send-data write-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=12fa242c-1b00-0000-622e-5114c10a0000 pid=2753 execve guuid=f19dbd68-1b00-0000-622e-5114230b0000 pid=2851 /usr/bin/chmod guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=f19dbd68-1b00-0000-622e-5114230b0000 pid=2851 execve guuid=af593769-1b00-0000-622e-5114260b0000 pid=2854 /usr/bin/dash guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=af593769-1b00-0000-622e-5114260b0000 pid=2854 execve guuid=5d1bb669-1b00-0000-622e-5114280b0000 pid=2856 /usr/bin/rm delete-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=5d1bb669-1b00-0000-622e-5114280b0000 pid=2856 execve guuid=f3c56a71-1b00-0000-622e-51142a0b0000 pid=2858 /usr/bin/wget net send-data write-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=f3c56a71-1b00-0000-622e-51142a0b0000 pid=2858 execve guuid=cf16efbb-1b00-0000-622e-5114b10b0000 pid=2993 /usr/bin/curl net send-data write-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=cf16efbb-1b00-0000-622e-5114b10b0000 pid=2993 execve guuid=6054a60b-1c00-0000-622e-51145c0c0000 pid=3164 /usr/bin/chmod guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=6054a60b-1c00-0000-622e-51145c0c0000 pid=3164 execve guuid=1878020c-1c00-0000-622e-51145d0c0000 pid=3165 /usr/bin/dash guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=1878020c-1c00-0000-622e-51145d0c0000 pid=3165 execve guuid=41e24d0c-1c00-0000-622e-51145e0c0000 pid=3166 /usr/bin/rm delete-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=41e24d0c-1c00-0000-622e-51145e0c0000 pid=3166 execve guuid=07c59f0c-1c00-0000-622e-51145f0c0000 pid=3167 /usr/bin/wget net send-data write-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=07c59f0c-1c00-0000-622e-51145f0c0000 pid=3167 execve guuid=0ac7a658-1c00-0000-622e-5114cd0c0000 pid=3277 /usr/bin/curl net send-data write-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=0ac7a658-1c00-0000-622e-5114cd0c0000 pid=3277 execve guuid=b2fa39a7-1c00-0000-622e-5114580d0000 pid=3416 /usr/bin/chmod guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=b2fa39a7-1c00-0000-622e-5114580d0000 pid=3416 execve guuid=5a92a4a7-1c00-0000-622e-51145a0d0000 pid=3418 /usr/bin/dash guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=5a92a4a7-1c00-0000-622e-51145a0d0000 pid=3418 execve guuid=d68af9a7-1c00-0000-622e-51145c0d0000 pid=3420 /usr/bin/rm delete-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=d68af9a7-1c00-0000-622e-51145c0d0000 pid=3420 execve guuid=2b4849a8-1c00-0000-622e-51145e0d0000 pid=3422 /usr/bin/wget net send-data write-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=2b4849a8-1c00-0000-622e-51145e0d0000 pid=3422 execve guuid=146abc00-1d00-0000-622e-51141b0e0000 pid=3611 /usr/bin/curl net send-data write-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=146abc00-1d00-0000-622e-51141b0e0000 pid=3611 execve guuid=2ba5c75c-1d00-0000-622e-5114040f0000 pid=3844 /usr/bin/chmod guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=2ba5c75c-1d00-0000-622e-5114040f0000 pid=3844 execve guuid=84b2215d-1d00-0000-622e-5114050f0000 pid=3845 /usr/bin/dash guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=84b2215d-1d00-0000-622e-5114050f0000 pid=3845 execve guuid=b456625d-1d00-0000-622e-5114060f0000 pid=3846 /usr/bin/rm delete-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=b456625d-1d00-0000-622e-5114060f0000 pid=3846 execve guuid=f435ac5d-1d00-0000-622e-5114070f0000 pid=3847 /usr/bin/wget net send-data write-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=f435ac5d-1d00-0000-622e-5114070f0000 pid=3847 execve guuid=5ec6f8b3-1d00-0000-622e-511413100000 pid=4115 /usr/bin/curl net send-data write-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=5ec6f8b3-1d00-0000-622e-511413100000 pid=4115 execve guuid=9aaeae0b-1e00-0000-622e-511420110000 pid=4384 /usr/bin/chmod guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=9aaeae0b-1e00-0000-622e-511420110000 pid=4384 execve guuid=492b020c-1e00-0000-622e-511423110000 pid=4387 /usr/bin/dash guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=492b020c-1e00-0000-622e-511423110000 pid=4387 execve guuid=2735490c-1e00-0000-622e-511425110000 pid=4389 /usr/bin/rm delete-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=2735490c-1e00-0000-622e-511425110000 pid=4389 execve guuid=518da10c-1e00-0000-622e-511428110000 pid=4392 /usr/bin/wget net send-data write-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=518da10c-1e00-0000-622e-511428110000 pid=4392 execve guuid=1c5ea561-1e00-0000-622e-51142f120000 pid=4655 /usr/bin/curl net send-data write-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=1c5ea561-1e00-0000-622e-51142f120000 pid=4655 execve guuid=a0e174b8-1e00-0000-622e-511458130000 pid=4952 /usr/bin/chmod guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=a0e174b8-1e00-0000-622e-511458130000 pid=4952 execve guuid=9996aeb8-1e00-0000-622e-51145a130000 pid=4954 /usr/bin/dash guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=9996aeb8-1e00-0000-622e-51145a130000 pid=4954 execve guuid=72c2e5b8-1e00-0000-622e-51145c130000 pid=4956 /usr/bin/rm delete-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=72c2e5b8-1e00-0000-622e-51145c130000 pid=4956 execve guuid=888637b9-1e00-0000-622e-51145e130000 pid=4958 /usr/bin/wget net send-data write-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=888637b9-1e00-0000-622e-51145e130000 pid=4958 execve guuid=0ec0e308-1f00-0000-622e-511469140000 pid=5225 /usr/bin/curl net send-data write-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=0ec0e308-1f00-0000-622e-511469140000 pid=5225 execve guuid=f5b2ed58-1f00-0000-622e-511494140000 pid=5268 /usr/bin/chmod guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=f5b2ed58-1f00-0000-622e-511494140000 pid=5268 execve guuid=a7e53359-1f00-0000-622e-511495140000 pid=5269 /usr/bin/dash guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=a7e53359-1f00-0000-622e-511495140000 pid=5269 execve guuid=e05a7e59-1f00-0000-622e-511496140000 pid=5270 /usr/bin/rm delete-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=e05a7e59-1f00-0000-622e-511496140000 pid=5270 execve guuid=3d3dca59-1f00-0000-622e-511497140000 pid=5271 /usr/bin/wget net send-data write-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=3d3dca59-1f00-0000-622e-511497140000 pid=5271 execve guuid=2f35b58b-1f00-0000-622e-511498140000 pid=5272 /usr/bin/curl net send-data write-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=2f35b58b-1f00-0000-622e-511498140000 pid=5272 execve guuid=0e3479c8-1f00-0000-622e-511499140000 pid=5273 /usr/bin/chmod guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=0e3479c8-1f00-0000-622e-511499140000 pid=5273 execve guuid=3ceecdc8-1f00-0000-622e-51149a140000 pid=5274 /usr/bin/dash guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=3ceecdc8-1f00-0000-622e-51149a140000 pid=5274 execve guuid=67eb1fc9-1f00-0000-622e-51149b140000 pid=5275 /usr/bin/rm delete-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=67eb1fc9-1f00-0000-622e-51149b140000 pid=5275 execve guuid=80e1a0e4-1f00-0000-622e-51149c140000 pid=5276 /usr/bin/wget net send-data write-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=80e1a0e4-1f00-0000-622e-51149c140000 pid=5276 execve guuid=a057703c-2000-0000-622e-51149e140000 pid=5278 /usr/bin/curl net send-data write-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=a057703c-2000-0000-622e-51149e140000 pid=5278 execve guuid=1b31ec8c-2000-0000-622e-5114a5140000 pid=5285 /usr/bin/chmod guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=1b31ec8c-2000-0000-622e-5114a5140000 pid=5285 execve guuid=3793678d-2000-0000-622e-5114a6140000 pid=5286 /usr/bin/dash guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=3793678d-2000-0000-622e-5114a6140000 pid=5286 execve guuid=f62cca8d-2000-0000-622e-5114a7140000 pid=5287 /usr/bin/rm delete-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=f62cca8d-2000-0000-622e-5114a7140000 pid=5287 execve guuid=11f9398e-2000-0000-622e-5114a8140000 pid=5288 /usr/bin/wget net send-data write-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=11f9398e-2000-0000-622e-5114a8140000 pid=5288 execve guuid=d8f2cae0-2000-0000-622e-5114a9140000 pid=5289 /usr/bin/curl net send-data write-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=d8f2cae0-2000-0000-622e-5114a9140000 pid=5289 execve guuid=2b2dbe30-2100-0000-622e-5114aa140000 pid=5290 /usr/bin/chmod guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=2b2dbe30-2100-0000-622e-5114aa140000 pid=5290 execve guuid=c4ab1531-2100-0000-622e-5114ab140000 pid=5291 /usr/bin/dash guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=c4ab1531-2100-0000-622e-5114ab140000 pid=5291 execve guuid=6bb47431-2100-0000-622e-5114ac140000 pid=5292 /usr/bin/rm delete-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=6bb47431-2100-0000-622e-5114ac140000 pid=5292 execve guuid=bd811932-2100-0000-622e-5114ad140000 pid=5293 /usr/bin/wget net send-data write-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=bd811932-2100-0000-622e-5114ad140000 pid=5293 execve guuid=8d5ecc7c-2100-0000-622e-5114bb140000 pid=5307 /usr/bin/curl net send-data write-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=8d5ecc7c-2100-0000-622e-5114bb140000 pid=5307 execve guuid=2daa56c8-2100-0000-622e-5114cf140000 pid=5327 /usr/bin/chmod guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=2daa56c8-2100-0000-622e-5114cf140000 pid=5327 execve guuid=898ba4c8-2100-0000-622e-5114d0140000 pid=5328 /usr/bin/dash guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=898ba4c8-2100-0000-622e-5114d0140000 pid=5328 execve guuid=2abdd6c8-2100-0000-622e-5114d1140000 pid=5329 /usr/bin/rm delete-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=2abdd6c8-2100-0000-622e-5114d1140000 pid=5329 execve guuid=b2851bc9-2100-0000-622e-5114d2140000 pid=5330 /usr/bin/wget net send-data write-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=b2851bc9-2100-0000-622e-5114d2140000 pid=5330 execve guuid=fa4ce714-2200-0000-622e-5114d3140000 pid=5331 /usr/bin/curl net send-data write-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=fa4ce714-2200-0000-622e-5114d3140000 pid=5331 execve guuid=40ee9d62-2200-0000-622e-5114d4140000 pid=5332 /usr/bin/chmod guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=40ee9d62-2200-0000-622e-5114d4140000 pid=5332 execve guuid=9ddce362-2200-0000-622e-5114d5140000 pid=5333 /usr/bin/dash guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=9ddce362-2200-0000-622e-5114d5140000 pid=5333 execve guuid=1e961963-2200-0000-622e-5114d6140000 pid=5334 /usr/bin/rm delete-file guuid=717da4e2-1900-0000-622e-5114dc070000 pid=2012->guuid=1e961963-2200-0000-622e-5114d6140000 pid=5334 execve 86474224-c803-53bc-a595-613a9c4fe2be 156.246.95.51:80 guuid=5dc40de3-1900-0000-622e-5114de070000 pid=2014->86474224-c803-53bc-a595-613a9c4fe2be send: 135B guuid=2fad1e46-1a00-0000-622e-5114b5080000 pid=2229->86474224-c803-53bc-a595-613a9c4fe2be send: 84B guuid=4561a8f1-1a00-0000-622e-5114230a0000 pid=2595->86474224-c803-53bc-a595-613a9c4fe2be send: 138B guuid=12fa242c-1b00-0000-622e-5114c10a0000 pid=2753->86474224-c803-53bc-a595-613a9c4fe2be send: 87B guuid=f3c56a71-1b00-0000-622e-51142a0b0000 pid=2858->86474224-c803-53bc-a595-613a9c4fe2be send: 135B guuid=cf16efbb-1b00-0000-622e-5114b10b0000 pid=2993->86474224-c803-53bc-a595-613a9c4fe2be send: 84B guuid=07c59f0c-1c00-0000-622e-51145f0c0000 pid=3167->86474224-c803-53bc-a595-613a9c4fe2be send: 139B guuid=0ac7a658-1c00-0000-622e-5114cd0c0000 pid=3277->86474224-c803-53bc-a595-613a9c4fe2be send: 88B guuid=2b4849a8-1c00-0000-622e-51145e0d0000 pid=3422->86474224-c803-53bc-a595-613a9c4fe2be send: 142B guuid=146abc00-1d00-0000-622e-51141b0e0000 pid=3611->86474224-c803-53bc-a595-613a9c4fe2be send: 91B guuid=f435ac5d-1d00-0000-622e-5114070f0000 pid=3847->86474224-c803-53bc-a595-613a9c4fe2be send: 138B guuid=5ec6f8b3-1d00-0000-622e-511413100000 pid=4115->86474224-c803-53bc-a595-613a9c4fe2be send: 87B guuid=518da10c-1e00-0000-622e-511428110000 pid=4392->86474224-c803-53bc-a595-613a9c4fe2be send: 136B guuid=1c5ea561-1e00-0000-622e-51142f120000 pid=4655->86474224-c803-53bc-a595-613a9c4fe2be send: 85B guuid=888637b9-1e00-0000-622e-51145e130000 pid=4958->86474224-c803-53bc-a595-613a9c4fe2be send: 136B guuid=0ec0e308-1f00-0000-622e-511469140000 pid=5225->86474224-c803-53bc-a595-613a9c4fe2be send: 85B guuid=3d3dca59-1f00-0000-622e-511497140000 pid=5271->86474224-c803-53bc-a595-613a9c4fe2be send: 136B guuid=2f35b58b-1f00-0000-622e-511498140000 pid=5272->86474224-c803-53bc-a595-613a9c4fe2be send: 85B guuid=80e1a0e4-1f00-0000-622e-51149c140000 pid=5276->86474224-c803-53bc-a595-613a9c4fe2be send: 138B guuid=a057703c-2000-0000-622e-51149e140000 pid=5278->86474224-c803-53bc-a595-613a9c4fe2be send: 87B guuid=11f9398e-2000-0000-622e-5114a8140000 pid=5288->86474224-c803-53bc-a595-613a9c4fe2be send: 138B guuid=d8f2cae0-2000-0000-622e-5114a9140000 pid=5289->86474224-c803-53bc-a595-613a9c4fe2be send: 87B guuid=bd811932-2100-0000-622e-5114ad140000 pid=5293->86474224-c803-53bc-a595-613a9c4fe2be send: 138B guuid=8d5ecc7c-2100-0000-622e-5114bb140000 pid=5307->86474224-c803-53bc-a595-613a9c4fe2be send: 87B guuid=b2851bc9-2100-0000-622e-5114d2140000 pid=5330->86474224-c803-53bc-a595-613a9c4fe2be send: 138B guuid=fa4ce714-2200-0000-622e-5114d3140000 pid=5331->86474224-c803-53bc-a595-613a9c4fe2be send: 87B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-02-19 00:05:02 UTC
AV detection:
13 of 38 (34.21%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh
Rule name:UNK_install_script
Author:evilcel3ri
Description:Detects a suspicious behaviour in an bash installation script

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 749441f67c977e570be5b60b8a34aa3fcc25846a78a01cd64163b9d02337a1fb

(this sample)

  
Delivery method
Distributed via web download

Comments