MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9101bd5fd52fac30eb6fe9362d0a045db7a5108c8ae4248564d23e829e5f22ba. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: 9101bd5fd52fac30eb6fe9362d0a045db7a5108c8ae4248564d23e829e5f22ba
SHA3-384 hash: 42152119b880dce46e2fd163ea1003f493c7c00fc162cfb28b4cb83eedcb89169aef83872cbd94630d580a6dc9ad00dc
SHA1 hash: 7a3b2bc67f7ca013f8727658c4ed317a2471c35a
MD5 hash: fc332f5ca08d5f166a173f394cc42da6
humanhash: berlin-charlie-failed-georgia
File name:ipmiv2.xml
Download: download sample
File size:983 bytes
First seen:2026-06-24 06:30:58 UTC
Last seen:2026-06-24 23:29:15 UTC
File type:
MIME type:text/plain
ssdeep 12:FzY8id/7JAC7akxGWi2jX0KTkQyHV0FBoHAxABUWxABC7XfAw6fnv:FzY8k1/sWi2jkIyH+BA2ibiC7van
TLSH T1E411EB7FE07495F02B55C98671A8C48C29934197B1A75EC1B3CC7831ABAFE4D38E124E
Magika xml
Reporter abuse_ch
Tags:xml

Intelligence


File Origin
# of uploads :
10
# of downloads :
77
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
opendir
Verdict:
Suspicious
Labled as:
TrojanDownloader/Linux.NetLoader
Verdict:
Malicious
File Type:
text
First seen:
2026-06-24T03:44:00Z UTC
Last seen:
2026-06-25T23:49:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.p
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-JS.Downloader.Heuristic
Status:
Malicious
First seen:
2026-06-24 06:39:32 UTC
File Type:
Text (Shell)
AV detection:
12 of 24 (50.00%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

9101bd5fd52fac30eb6fe9362d0a045db7a5108c8ae4248564d23e829e5f22ba

(this sample)

  
Delivery method
Distributed via web download

Comments