MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d651fbf908c4f5a25cd048b993b5bc8b99ca011c070749bcaf5e4b1b7bc14f5c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: d651fbf908c4f5a25cd048b993b5bc8b99ca011c070749bcaf5e4b1b7bc14f5c
SHA3-384 hash: 4efe6becc29a04db0d9fc7735f144d04f9453fc366629dcc7d3d89442cddd8a0780b545179777b35837b02913df31305
SHA1 hash: 4688ef39add10a344c67ec0ab2b3da57d67354b5
MD5 hash: 836950a7bbd14e21625d9eb7976a1247
humanhash: california-juliet-robin-arizona
File name:o.xml
Download: download sample
File size:736 bytes
First seen:2026-06-29 23:21:14 UTC
Last seen:2026-06-30 09:19:56 UTC
File type:
MIME type:text/plain
ssdeep 12:FH8ioNJAC7ukxGWi2jU30+0K5+A+GSjRCkvDClkvDoBjZhG+E6:FH8j/wWi2jzCmPWScf
TLSH T12301F9BD91A88A5205B5C5C7B2F14546C490D08BA2FE97E6F38D09266F38CDE3C5330D
Magika xml
Reporter abuse_ch
Tags:xml

Intelligence


File Origin
# of uploads :
143
# of downloads :
13
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
92.5%
Tags:
virus
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
downloader
Gathering data
Threat name:
Script.Trojan.Heuristic
Status:
Malicious
First seen:
2026-06-30 02:35:56 UTC
File Type:
Text
AV detection:
12 of 24 (50.00%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

d651fbf908c4f5a25cd048b993b5bc8b99ca011c070749bcaf5e4b1b7bc14f5c

(this sample)

  
Delivery method
Distributed via web download

Comments