MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c0b1bbdd2dd4dd3430af4e06fb05a9b412de8c18b22f71a4cfe4d6822d2f4c2b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: c0b1bbdd2dd4dd3430af4e06fb05a9b412de8c18b22f71a4cfe4d6822d2f4c2b
SHA3-384 hash: fb450bb82843f33fbc1b4dbfe43bf66303ea62f6afe025ca7f1923ad7531afe0c78e02a11e72f51f9bcaed073fb5606c
SHA1 hash: 897965ad007c252df52b8ac0aa28f353c29bd38e
MD5 hash: 882ef5270dafae69332bcf44314b4c9c
humanhash: april-don-bacon-bravo
File name:android.sh
Download: download sample
File size:1'178 bytes
First seen:2026-05-21 21:57:24 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:q0I0e0kNIc/0nKyS50I5Nl5u5S0uWMoS0bzXp0ETde2deFTdS0DwI0bKAJv02zM9:q0I0e06/0nc0I5b5u5S0uWMoS0bzXp0Z
TLSH T19121C2CE60F0B1078068CE1434A3E5817004CBDB92AA5F39FDB95B73C5C6A44F128B8A
Magika csv
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139.188/2s3dkw7s/atbtjft.armn/an/aarm elf ua-wget
http://176.65.139.188/2s3dkw7s/wyszztw.arm5n/an/aarm elf ua-wget
http://176.65.139.188/2s3dkw7s/iztsowy.arm6n/an/aarm elf ua-wget
http://176.65.139.188/2s3dkw7s/iwhcwck.arm7n/an/aarm elf ua-wget
http://176.65.139.188/2s3dkw7s/uagkrww.aarch64n/an/aarm elf ua-wget
http://176.65.139.188/2s3dkw7s/nbhpcpg.mipsn/an/aelf mips ua-wget
http://176.65.139.188/2s3dkw7s/edykljw.mpsln/an/aelf mips ua-wget
http://176.65.139.188/2s3dkw7s/einqgiy.mips64n/an/aelf mips ua-wget
http://176.65.139.188/2s3dkw7s/tpprwsu.ppcn/an/aelf PowerPC ua-wget
http://176.65.139.188/2s3dkw7s/ljwqgms.x86_64n/an/aelf ua-wget x86
http://176.65.139.188/2s3dkw7s/znebtbj.i686n/an/aelf ua-wget x86
http://176.65.139.188/2s3dkw7s/iovmytx.i586n/an/aelf ua-wget x86
http://176.65.139.188/2s3dkw7s/lduhsjo.i486n/an/aelf ua-wget x86

Intelligence


File Origin
# of uploads :
1
# of downloads :
55
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Verdict:
Malicious
File Type:
ps1
First seen:
2026-05-21T19:05:00Z UTC
Last seen:
2026-05-22T03:57:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.cl
Status:
terminated
Behavior Graph:
%3 guuid=dc9e6050-1c00-0000-af5c-c3e392090000 pid=2450 /usr/bin/sudo guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456 /tmp/sample.bin guuid=dc9e6050-1c00-0000-af5c-c3e392090000 pid=2450->guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456 execve guuid=d1a52352-1c00-0000-af5c-c3e399090000 pid=2457 /usr/bin/wget net send-data write-file guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=d1a52352-1c00-0000-af5c-c3e399090000 pid=2457 execve guuid=e417d65c-1c00-0000-af5c-c3e3ad090000 pid=2477 /usr/bin/chmod guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=e417d65c-1c00-0000-af5c-c3e3ad090000 pid=2477 execve guuid=4143395d-1c00-0000-af5c-c3e3ae090000 pid=2478 /usr/bin/dash guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=4143395d-1c00-0000-af5c-c3e3ae090000 pid=2478 clone guuid=a60f085e-1c00-0000-af5c-c3e3b1090000 pid=2481 /usr/bin/wget net send-data write-file guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=a60f085e-1c00-0000-af5c-c3e3b1090000 pid=2481 execve guuid=efe44d69-1c00-0000-af5c-c3e3ca090000 pid=2506 /usr/bin/chmod guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=efe44d69-1c00-0000-af5c-c3e3ca090000 pid=2506 execve guuid=0fcca569-1c00-0000-af5c-c3e3cc090000 pid=2508 /usr/bin/dash guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=0fcca569-1c00-0000-af5c-c3e3cc090000 pid=2508 clone guuid=8bdb316a-1c00-0000-af5c-c3e3cf090000 pid=2511 /usr/bin/wget net send-data write-file guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=8bdb316a-1c00-0000-af5c-c3e3cf090000 pid=2511 execve guuid=b05a7872-1c00-0000-af5c-c3e3de090000 pid=2526 /usr/bin/chmod guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=b05a7872-1c00-0000-af5c-c3e3de090000 pid=2526 execve guuid=3c80b572-1c00-0000-af5c-c3e3e0090000 pid=2528 /usr/bin/dash guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=3c80b572-1c00-0000-af5c-c3e3e0090000 pid=2528 clone guuid=afdf3573-1c00-0000-af5c-c3e3e3090000 pid=2531 /usr/bin/wget net send-data write-file guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=afdf3573-1c00-0000-af5c-c3e3e3090000 pid=2531 execve guuid=ecad077c-1c00-0000-af5c-c3e3f3090000 pid=2547 /usr/bin/chmod guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=ecad077c-1c00-0000-af5c-c3e3f3090000 pid=2547 execve guuid=1d82bd7c-1c00-0000-af5c-c3e3f4090000 pid=2548 /usr/bin/dash guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=1d82bd7c-1c00-0000-af5c-c3e3f4090000 pid=2548 clone guuid=c03da27e-1c00-0000-af5c-c3e3fb090000 pid=2555 /usr/bin/wget net send-data write-file guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=c03da27e-1c00-0000-af5c-c3e3fb090000 pid=2555 execve guuid=2f00e489-1c00-0000-af5c-c3e30e0a0000 pid=2574 /usr/bin/chmod guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=2f00e489-1c00-0000-af5c-c3e30e0a0000 pid=2574 execve guuid=d4ce258a-1c00-0000-af5c-c3e3100a0000 pid=2576 /usr/bin/dash guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=d4ce258a-1c00-0000-af5c-c3e3100a0000 pid=2576 clone guuid=6955ba8a-1c00-0000-af5c-c3e3140a0000 pid=2580 /usr/bin/wget net send-data write-file guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=6955ba8a-1c00-0000-af5c-c3e3140a0000 pid=2580 execve guuid=b78f7695-1c00-0000-af5c-c3e32a0a0000 pid=2602 /usr/bin/chmod guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=b78f7695-1c00-0000-af5c-c3e32a0a0000 pid=2602 execve guuid=3803ba95-1c00-0000-af5c-c3e32c0a0000 pid=2604 /usr/bin/dash guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=3803ba95-1c00-0000-af5c-c3e32c0a0000 pid=2604 clone guuid=81c04e96-1c00-0000-af5c-c3e3300a0000 pid=2608 /usr/bin/wget net send-data write-file guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=81c04e96-1c00-0000-af5c-c3e3300a0000 pid=2608 execve guuid=6589cea1-1c00-0000-af5c-c3e34e0a0000 pid=2638 /usr/bin/chmod guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=6589cea1-1c00-0000-af5c-c3e34e0a0000 pid=2638 execve guuid=b2331ba2-1c00-0000-af5c-c3e3500a0000 pid=2640 /usr/bin/dash guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=b2331ba2-1c00-0000-af5c-c3e3500a0000 pid=2640 clone guuid=29596ea3-1c00-0000-af5c-c3e3550a0000 pid=2645 /usr/bin/wget net send-data write-file guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=29596ea3-1c00-0000-af5c-c3e3550a0000 pid=2645 execve guuid=921109b0-1c00-0000-af5c-c3e3760a0000 pid=2678 /usr/bin/chmod guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=921109b0-1c00-0000-af5c-c3e3760a0000 pid=2678 execve guuid=94cd43b0-1c00-0000-af5c-c3e3780a0000 pid=2680 /usr/bin/dash guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=94cd43b0-1c00-0000-af5c-c3e3780a0000 pid=2680 clone guuid=7044f3b0-1c00-0000-af5c-c3e37c0a0000 pid=2684 /usr/bin/wget net send-data write-file guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=7044f3b0-1c00-0000-af5c-c3e37c0a0000 pid=2684 execve guuid=b79799bb-1c00-0000-af5c-c3e39c0a0000 pid=2716 /usr/bin/chmod guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=b79799bb-1c00-0000-af5c-c3e39c0a0000 pid=2716 execve guuid=927d04bc-1c00-0000-af5c-c3e39e0a0000 pid=2718 /usr/bin/dash guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=927d04bc-1c00-0000-af5c-c3e39e0a0000 pid=2718 clone guuid=001528bd-1c00-0000-af5c-c3e3a30a0000 pid=2723 /usr/bin/wget net send-data write-file guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=001528bd-1c00-0000-af5c-c3e3a30a0000 pid=2723 execve guuid=52e03bc7-1c00-0000-af5c-c3e3c40a0000 pid=2756 /usr/bin/chmod guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=52e03bc7-1c00-0000-af5c-c3e3c40a0000 pid=2756 execve guuid=a64a95c7-1c00-0000-af5c-c3e3c70a0000 pid=2759 memfd: delete-file write-file guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=a64a95c7-1c00-0000-af5c-c3e3c70a0000 pid=2759 execve guuid=789ae6d2-1c00-0000-af5c-c3e3e50a0000 pid=2789 /usr/bin/wget net send-data write-file guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=789ae6d2-1c00-0000-af5c-c3e3e50a0000 pid=2789 execve guuid=87d3f1df-1c00-0000-af5c-c3e3fd0a0000 pid=2813 /usr/bin/chmod guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=87d3f1df-1c00-0000-af5c-c3e3fd0a0000 pid=2813 execve guuid=bd8c2ee0-1c00-0000-af5c-c3e3ff0a0000 pid=2815 memfd: write-file guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=bd8c2ee0-1c00-0000-af5c-c3e3ff0a0000 pid=2815 execve guuid=d8d651e4-1c00-0000-af5c-c3e3090b0000 pid=2825 /usr/bin/dash guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=d8d651e4-1c00-0000-af5c-c3e3090b0000 pid=2825 clone guuid=4f7860e4-1c00-0000-af5c-c3e30a0b0000 pid=2826 /usr/bin/chmod guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=4f7860e4-1c00-0000-af5c-c3e30a0b0000 pid=2826 execve guuid=45a1a3e4-1c00-0000-af5c-c3e30c0b0000 pid=2828 /usr/bin/dash guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=45a1a3e4-1c00-0000-af5c-c3e30c0b0000 pid=2828 clone guuid=e6e1b2e4-1c00-0000-af5c-c3e30d0b0000 pid=2829 /usr/bin/dash guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=e6e1b2e4-1c00-0000-af5c-c3e30d0b0000 pid=2829 clone guuid=3388c4e4-1c00-0000-af5c-c3e30f0b0000 pid=2831 /usr/bin/chmod guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=3388c4e4-1c00-0000-af5c-c3e30f0b0000 pid=2831 execve guuid=54e40ce5-1c00-0000-af5c-c3e3100b0000 pid=2832 /usr/bin/dash guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=54e40ce5-1c00-0000-af5c-c3e3100b0000 pid=2832 clone guuid=d83717e5-1c00-0000-af5c-c3e3110b0000 pid=2833 /usr/bin/rm delete-file guuid=5a0df251-1c00-0000-af5c-c3e398090000 pid=2456->guuid=d83717e5-1c00-0000-af5c-c3e3110b0000 pid=2833 execve bbf5bc96-9f47-54ce-aa51-70672524d0f0 176.65.139.188:80 guuid=d1a52352-1c00-0000-af5c-c3e399090000 pid=2457->bbf5bc96-9f47-54ce-aa51-70672524d0f0 send: 149B guuid=a60f085e-1c00-0000-af5c-c3e3b1090000 pid=2481->bbf5bc96-9f47-54ce-aa51-70672524d0f0 send: 150B guuid=8bdb316a-1c00-0000-af5c-c3e3cf090000 pid=2511->bbf5bc96-9f47-54ce-aa51-70672524d0f0 send: 150B guuid=afdf3573-1c00-0000-af5c-c3e3e3090000 pid=2531->bbf5bc96-9f47-54ce-aa51-70672524d0f0 send: 150B guuid=c03da27e-1c00-0000-af5c-c3e3fb090000 pid=2555->bbf5bc96-9f47-54ce-aa51-70672524d0f0 send: 153B guuid=6955ba8a-1c00-0000-af5c-c3e3140a0000 pid=2580->bbf5bc96-9f47-54ce-aa51-70672524d0f0 send: 150B guuid=81c04e96-1c00-0000-af5c-c3e3300a0000 pid=2608->bbf5bc96-9f47-54ce-aa51-70672524d0f0 send: 150B guuid=29596ea3-1c00-0000-af5c-c3e3550a0000 pid=2645->bbf5bc96-9f47-54ce-aa51-70672524d0f0 send: 152B guuid=7044f3b0-1c00-0000-af5c-c3e37c0a0000 pid=2684->bbf5bc96-9f47-54ce-aa51-70672524d0f0 send: 149B guuid=001528bd-1c00-0000-af5c-c3e3a30a0000 pid=2723->bbf5bc96-9f47-54ce-aa51-70672524d0f0 send: 152B guuid=88681cd0-1c00-0000-af5c-c3e3da0a0000 pid=2778 memfd: guuid=a64a95c7-1c00-0000-af5c-c3e3c70a0000 pid=2759->guuid=88681cd0-1c00-0000-af5c-c3e3da0a0000 pid=2778 clone guuid=312e70d2-1c00-0000-af5c-c3e3de0a0000 pid=2782 memfd: guuid=a64a95c7-1c00-0000-af5c-c3e3c70a0000 pid=2759->guuid=312e70d2-1c00-0000-af5c-c3e3de0a0000 pid=2782 clone guuid=437693d2-1c00-0000-af5c-c3e3e00a0000 pid=2784 memfd: guuid=a64a95c7-1c00-0000-af5c-c3e3c70a0000 pid=2759->guuid=437693d2-1c00-0000-af5c-c3e3e00a0000 pid=2784 clone guuid=b1f2ced2-1c00-0000-af5c-c3e3e30a0000 pid=2787 memfd: zombie guuid=a64a95c7-1c00-0000-af5c-c3e3c70a0000 pid=2759->guuid=b1f2ced2-1c00-0000-af5c-c3e3e30a0000 pid=2787 clone guuid=0a1be4d2-1c00-0000-af5c-c3e3e40a0000 pid=2788 memfd: guuid=b1f2ced2-1c00-0000-af5c-c3e3e30a0000 pid=2787->guuid=0a1be4d2-1c00-0000-af5c-c3e3e40a0000 pid=2788 clone guuid=7a4bf3d2-1c00-0000-af5c-c3e3e60a0000 pid=2790 memfd: dns net send-data write-file guuid=0a1be4d2-1c00-0000-af5c-c3e3e40a0000 pid=2788->guuid=7a4bf3d2-1c00-0000-af5c-c3e3e60a0000 pid=2790 clone guuid=789ae6d2-1c00-0000-af5c-c3e3e50a0000 pid=2789->bbf5bc96-9f47-54ce-aa51-70672524d0f0 send: 150B 80639f7d-8d8e-5d60-8819-65337bb0e774 criminalcloudflare.online:1337 guuid=7a4bf3d2-1c00-0000-af5c-c3e3e60a0000 pid=2790->80639f7d-8d8e-5d60-8819-65337bb0e774 send: 256B a0528efd-1018-56b4-b518-221acb0fa7ca 9.9.9.9:53 guuid=7a4bf3d2-1c00-0000-af5c-c3e3e60a0000 pid=2790->a0528efd-1018-56b4-b518-221acb0fa7ca send: 43B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=7a4bf3d2-1c00-0000-af5c-c3e3e60a0000 pid=2790->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 43B guuid=7a4bf3d2-1c00-0000-af5c-c3e3e60a0000 pid=2791 memfd: guuid=7a4bf3d2-1c00-0000-af5c-c3e3e60a0000 pid=2790->guuid=7a4bf3d2-1c00-0000-af5c-c3e3e60a0000 pid=2791 clone guuid=7a4bf3d2-1c00-0000-af5c-c3e3e60a0000 pid=2792 memfd: guuid=7a4bf3d2-1c00-0000-af5c-c3e3e60a0000 pid=2790->guuid=7a4bf3d2-1c00-0000-af5c-c3e3e60a0000 pid=2792 clone guuid=7a4bf3d2-1c00-0000-af5c-c3e3e60a0000 pid=2795 memfd: guuid=7a4bf3d2-1c00-0000-af5c-c3e3e60a0000 pid=2790->guuid=7a4bf3d2-1c00-0000-af5c-c3e3e60a0000 pid=2795 clone guuid=0b4161cf-2300-0000-af5c-c3e3db140000 pid=5339 memfd: guuid=7a4bf3d2-1c00-0000-af5c-c3e3e60a0000 pid=2791->guuid=0b4161cf-2300-0000-af5c-c3e3db140000 pid=5339 clone
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script.Trojan.Heuristic
Status:
Malicious
First seen:
2026-05-21 21:58:36 UTC
File Type:
Text (Shell)
AV detection:
11 of 24 (45.83%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh c0b1bbdd2dd4dd3430af4e06fb05a9b412de8c18b22f71a4cfe4d6822d2f4c2b

(this sample)

  
Delivery method
Distributed via web download

Comments