MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dfd0ae045f59c9e099db50f461abf60207182e3a2f8a3be02fcfd9dae7e0e2f6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: dfd0ae045f59c9e099db50f461abf60207182e3a2f8a3be02fcfd9dae7e0e2f6
SHA3-384 hash: eae367509864ec0e14552bcdea0f960e9b848c69d892f5ded0908d783d3e8f222e5bb6872b6973c34ebb1fa45372fcf7
SHA1 hash: 13132a6b750c387759705b687bf1f5e70828debd
MD5 hash: bf086e643736fd6bba96d03b0c596152
humanhash: mike-table-lake-virginia
File name:cat.sh
Download: download sample
File size:1'999 bytes
First seen:2026-03-16 20:12:32 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:sYh58y0mQXpN2Nn5UEB2VxQ9MeM9YNHg3mAnepH:/IXMtTg38H
TLSH T1C84153EF71F2683392A8CE5CB8A0C90D540654BA79EB7A24F8F81418D598F1570E47D9
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139.67/bins/spoofer.x86n/an/aelf ua-wget
http://176.65.139.67/bins/spoofer.mipsn/an/aelf ua-wget
http://176.65.139.67/bins/spoofer.mpsln/an/aelf ua-wget
http://176.65.139.67/bins/spoofer.armn/an/aelf ua-wget
http://176.65.139.67/bins/spoofer.arm5n/an/aelf ua-wget
http://176.65.139.67/bins/spoofer.arm6n/an/aelf ua-wget
http://176.65.139.67/bins/spoofer.arm7n/an/aelf ua-wget
http://176.65.139.67/bins/spoofer.ppcn/an/aelf ua-wget
http://176.65.139.67/bins/spoofer.spcn/an/aelf ua-wget
http://176.65.139.67/bins/spoofer.m68kn/an/aelf ua-wget
http://176.65.139.67/bins/spoofer.sh4n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
100
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Gathering data
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=a2f6e5b3-1900-0000-4f92-983698080000 pid=2200 /usr/bin/sudo guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210 /tmp/sample.bin guuid=a2f6e5b3-1900-0000-4f92-983698080000 pid=2200->guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210 execve guuid=39dae9b7-1900-0000-4f92-9836a5080000 pid=2213 /usr/bin/wget net send-data guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=39dae9b7-1900-0000-4f92-9836a5080000 pid=2213 execve guuid=b4080bbc-1900-0000-4f92-9836b1080000 pid=2225 /usr/bin/curl net send-data write-file guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=b4080bbc-1900-0000-4f92-9836b1080000 pid=2225 execve guuid=6c4b1ac4-1900-0000-4f92-9836c5080000 pid=2245 /usr/bin/chmod guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=6c4b1ac4-1900-0000-4f92-9836c5080000 pid=2245 execve guuid=495680c4-1900-0000-4f92-9836c6080000 pid=2246 /home/sandbox/spoofer.x86 guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=495680c4-1900-0000-4f92-9836c6080000 pid=2246 execve guuid=08cad9c4-1900-0000-4f92-9836c7080000 pid=2247 /usr/bin/rm delete-file guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=08cad9c4-1900-0000-4f92-9836c7080000 pid=2247 execve guuid=28a03ac5-1900-0000-4f92-9836cb080000 pid=2251 /usr/bin/wget net send-data guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=28a03ac5-1900-0000-4f92-9836cb080000 pid=2251 execve guuid=92443bca-1900-0000-4f92-9836d2080000 pid=2258 /usr/bin/curl net send-data write-file guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=92443bca-1900-0000-4f92-9836d2080000 pid=2258 execve guuid=dba685d1-1900-0000-4f92-9836da080000 pid=2266 /usr/bin/chmod guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=dba685d1-1900-0000-4f92-9836da080000 pid=2266 execve guuid=e46bd6d1-1900-0000-4f92-9836dc080000 pid=2268 /home/sandbox/spoofer.mips guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=e46bd6d1-1900-0000-4f92-9836dc080000 pid=2268 execve guuid=7ec814d2-1900-0000-4f92-9836dd080000 pid=2269 /usr/bin/rm delete-file guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=7ec814d2-1900-0000-4f92-9836dd080000 pid=2269 execve guuid=93cd61d2-1900-0000-4f92-9836de080000 pid=2270 /usr/bin/wget net send-data guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=93cd61d2-1900-0000-4f92-9836de080000 pid=2270 execve guuid=ba6723d5-1900-0000-4f92-9836e3080000 pid=2275 /usr/bin/curl net send-data write-file guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=ba6723d5-1900-0000-4f92-9836e3080000 pid=2275 execve guuid=eaf9d6db-1900-0000-4f92-9836f1080000 pid=2289 /usr/bin/chmod guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=eaf9d6db-1900-0000-4f92-9836f1080000 pid=2289 execve guuid=a62518dc-1900-0000-4f92-9836f2080000 pid=2290 /home/sandbox/spoofer.mpsl guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=a62518dc-1900-0000-4f92-9836f2080000 pid=2290 execve guuid=fc1c54dc-1900-0000-4f92-9836f3080000 pid=2291 /usr/bin/rm delete-file guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=fc1c54dc-1900-0000-4f92-9836f3080000 pid=2291 execve guuid=22c4a3dc-1900-0000-4f92-9836f5080000 pid=2293 /usr/bin/wget net send-data guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=22c4a3dc-1900-0000-4f92-9836f5080000 pid=2293 execve guuid=3145fbdf-1900-0000-4f92-9836fa080000 pid=2298 /usr/bin/curl net send-data write-file guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=3145fbdf-1900-0000-4f92-9836fa080000 pid=2298 execve guuid=091086e3-1900-0000-4f92-983602090000 pid=2306 /usr/bin/chmod guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=091086e3-1900-0000-4f92-983602090000 pid=2306 execve guuid=39d0c9e3-1900-0000-4f92-983604090000 pid=2308 /home/sandbox/spoofer.arm guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=39d0c9e3-1900-0000-4f92-983604090000 pid=2308 execve guuid=998800e4-1900-0000-4f92-983605090000 pid=2309 /usr/bin/rm delete-file guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=998800e4-1900-0000-4f92-983605090000 pid=2309 execve guuid=8ffd48e4-1900-0000-4f92-983608090000 pid=2312 /usr/bin/wget net send-data guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=8ffd48e4-1900-0000-4f92-983608090000 pid=2312 execve guuid=891dd5e6-1900-0000-4f92-983610090000 pid=2320 /usr/bin/curl net send-data write-file guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=891dd5e6-1900-0000-4f92-983610090000 pid=2320 execve guuid=fe18a0ea-1900-0000-4f92-983616090000 pid=2326 /usr/bin/chmod guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=fe18a0ea-1900-0000-4f92-983616090000 pid=2326 execve guuid=1961fcea-1900-0000-4f92-983619090000 pid=2329 /home/sandbox/spoofer.arm5 guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=1961fcea-1900-0000-4f92-983619090000 pid=2329 execve guuid=ff8744eb-1900-0000-4f92-98361a090000 pid=2330 /usr/bin/rm delete-file guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=ff8744eb-1900-0000-4f92-98361a090000 pid=2330 execve guuid=aa25b0eb-1900-0000-4f92-98361c090000 pid=2332 /usr/bin/wget net send-data guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=aa25b0eb-1900-0000-4f92-98361c090000 pid=2332 execve guuid=435d5bee-1900-0000-4f92-983622090000 pid=2338 /usr/bin/curl net send-data write-file guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=435d5bee-1900-0000-4f92-983622090000 pid=2338 execve guuid=8d0934f2-1900-0000-4f92-98362c090000 pid=2348 /usr/bin/chmod guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=8d0934f2-1900-0000-4f92-98362c090000 pid=2348 execve guuid=6e4c7bf2-1900-0000-4f92-98362e090000 pid=2350 /home/sandbox/spoofer.arm6 guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=6e4c7bf2-1900-0000-4f92-98362e090000 pid=2350 execve guuid=b9c3bcf2-1900-0000-4f92-983630090000 pid=2352 /usr/bin/rm delete-file guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=b9c3bcf2-1900-0000-4f92-983630090000 pid=2352 execve guuid=8ae023f3-1900-0000-4f92-983632090000 pid=2354 /usr/bin/wget net send-data guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=8ae023f3-1900-0000-4f92-983632090000 pid=2354 execve guuid=93f0cbf5-1900-0000-4f92-983638090000 pid=2360 /usr/bin/curl net send-data write-file guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=93f0cbf5-1900-0000-4f92-983638090000 pid=2360 execve guuid=698f02fa-1900-0000-4f92-983644090000 pid=2372 /usr/bin/chmod guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=698f02fa-1900-0000-4f92-983644090000 pid=2372 execve guuid=56a45efa-1900-0000-4f92-983645090000 pid=2373 /home/sandbox/spoofer.arm7 guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=56a45efa-1900-0000-4f92-983645090000 pid=2373 execve guuid=9288bcfa-1900-0000-4f92-983647090000 pid=2375 /usr/bin/rm delete-file guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=9288bcfa-1900-0000-4f92-983647090000 pid=2375 execve guuid=80f425fb-1900-0000-4f92-983649090000 pid=2377 /usr/bin/wget net send-data guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=80f425fb-1900-0000-4f92-983649090000 pid=2377 execve guuid=32beb7fd-1900-0000-4f92-98364f090000 pid=2383 /usr/bin/curl net send-data write-file guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=32beb7fd-1900-0000-4f92-98364f090000 pid=2383 execve guuid=06f00e09-1a00-0000-4f92-983653090000 pid=2387 /usr/bin/chmod guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=06f00e09-1a00-0000-4f92-983653090000 pid=2387 execve guuid=64e25309-1a00-0000-4f92-983654090000 pid=2388 /home/sandbox/spoofer.ppc guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=64e25309-1a00-0000-4f92-983654090000 pid=2388 execve guuid=8ddc8b09-1a00-0000-4f92-983655090000 pid=2389 /usr/bin/rm delete-file guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=8ddc8b09-1a00-0000-4f92-983655090000 pid=2389 execve guuid=1a6cf51e-1a00-0000-4f92-983656090000 pid=2390 /usr/bin/wget net send-data guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=1a6cf51e-1a00-0000-4f92-983656090000 pid=2390 execve guuid=a8c05923-1a00-0000-4f92-98365e090000 pid=2398 /usr/bin/curl net send-data write-file guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=a8c05923-1a00-0000-4f92-98365e090000 pid=2398 execve guuid=066c1428-1a00-0000-4f92-983668090000 pid=2408 /usr/bin/chmod guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=066c1428-1a00-0000-4f92-983668090000 pid=2408 execve guuid=f0a25f28-1a00-0000-4f92-98366a090000 pid=2410 /home/sandbox/spoofer.spc guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=f0a25f28-1a00-0000-4f92-98366a090000 pid=2410 execve guuid=b40d9a28-1a00-0000-4f92-98366c090000 pid=2412 /usr/bin/rm delete-file guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=b40d9a28-1a00-0000-4f92-98366c090000 pid=2412 execve guuid=66eee628-1a00-0000-4f92-98366e090000 pid=2414 /usr/bin/wget net send-data guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=66eee628-1a00-0000-4f92-98366e090000 pid=2414 execve guuid=dddedd2b-1a00-0000-4f92-983675090000 pid=2421 /usr/bin/curl net send-data write-file guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=dddedd2b-1a00-0000-4f92-983675090000 pid=2421 execve guuid=c668ab2f-1a00-0000-4f92-98367d090000 pid=2429 /usr/bin/chmod guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=c668ab2f-1a00-0000-4f92-98367d090000 pid=2429 execve guuid=1159e92f-1a00-0000-4f92-98367f090000 pid=2431 /home/sandbox/spoofer.m68k guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=1159e92f-1a00-0000-4f92-98367f090000 pid=2431 execve guuid=57781f30-1a00-0000-4f92-983681090000 pid=2433 /usr/bin/rm delete-file guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=57781f30-1a00-0000-4f92-983681090000 pid=2433 execve guuid=10216330-1a00-0000-4f92-983682090000 pid=2434 /usr/bin/wget net send-data guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=10216330-1a00-0000-4f92-983682090000 pid=2434 execve guuid=4ae3d233-1a00-0000-4f92-98368b090000 pid=2443 /usr/bin/curl net send-data write-file guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=4ae3d233-1a00-0000-4f92-98368b090000 pid=2443 execve guuid=6a7a9e3b-1a00-0000-4f92-983693090000 pid=2451 /usr/bin/chmod guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=6a7a9e3b-1a00-0000-4f92-983693090000 pid=2451 execve guuid=b7b7023c-1a00-0000-4f92-983696090000 pid=2454 /home/sandbox/spoofer.sh4 guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=b7b7023c-1a00-0000-4f92-983696090000 pid=2454 execve guuid=6909353c-1a00-0000-4f92-983697090000 pid=2455 /usr/bin/rm delete-file guuid=717727b7-1900-0000-4f92-9836a2080000 pid=2210->guuid=6909353c-1a00-0000-4f92-983697090000 pid=2455 execve 6c41c2cd-8068-525f-9229-995adab0aeae 176.65.139.67:80 guuid=39dae9b7-1900-0000-4f92-9836a5080000 pid=2213->6c41c2cd-8068-525f-9229-995adab0aeae send: 144B guuid=b4080bbc-1900-0000-4f92-9836b1080000 pid=2225->6c41c2cd-8068-525f-9229-995adab0aeae send: 93B guuid=28a03ac5-1900-0000-4f92-9836cb080000 pid=2251->6c41c2cd-8068-525f-9229-995adab0aeae send: 145B guuid=92443bca-1900-0000-4f92-9836d2080000 pid=2258->6c41c2cd-8068-525f-9229-995adab0aeae send: 94B guuid=93cd61d2-1900-0000-4f92-9836de080000 pid=2270->6c41c2cd-8068-525f-9229-995adab0aeae send: 145B guuid=ba6723d5-1900-0000-4f92-9836e3080000 pid=2275->6c41c2cd-8068-525f-9229-995adab0aeae send: 94B guuid=22c4a3dc-1900-0000-4f92-9836f5080000 pid=2293->6c41c2cd-8068-525f-9229-995adab0aeae send: 144B guuid=3145fbdf-1900-0000-4f92-9836fa080000 pid=2298->6c41c2cd-8068-525f-9229-995adab0aeae send: 93B guuid=8ffd48e4-1900-0000-4f92-983608090000 pid=2312->6c41c2cd-8068-525f-9229-995adab0aeae send: 145B guuid=891dd5e6-1900-0000-4f92-983610090000 pid=2320->6c41c2cd-8068-525f-9229-995adab0aeae send: 94B guuid=aa25b0eb-1900-0000-4f92-98361c090000 pid=2332->6c41c2cd-8068-525f-9229-995adab0aeae send: 145B guuid=435d5bee-1900-0000-4f92-983622090000 pid=2338->6c41c2cd-8068-525f-9229-995adab0aeae send: 94B guuid=8ae023f3-1900-0000-4f92-983632090000 pid=2354->6c41c2cd-8068-525f-9229-995adab0aeae send: 145B guuid=93f0cbf5-1900-0000-4f92-983638090000 pid=2360->6c41c2cd-8068-525f-9229-995adab0aeae send: 94B guuid=80f425fb-1900-0000-4f92-983649090000 pid=2377->6c41c2cd-8068-525f-9229-995adab0aeae send: 144B guuid=32beb7fd-1900-0000-4f92-98364f090000 pid=2383->6c41c2cd-8068-525f-9229-995adab0aeae send: 93B guuid=1a6cf51e-1a00-0000-4f92-983656090000 pid=2390->6c41c2cd-8068-525f-9229-995adab0aeae send: 144B guuid=a8c05923-1a00-0000-4f92-98365e090000 pid=2398->6c41c2cd-8068-525f-9229-995adab0aeae send: 93B guuid=66eee628-1a00-0000-4f92-98366e090000 pid=2414->6c41c2cd-8068-525f-9229-995adab0aeae send: 145B guuid=dddedd2b-1a00-0000-4f92-983675090000 pid=2421->6c41c2cd-8068-525f-9229-995adab0aeae send: 94B guuid=10216330-1a00-0000-4f92-983682090000 pid=2434->6c41c2cd-8068-525f-9229-995adab0aeae send: 144B guuid=4ae3d233-1a00-0000-4f92-98368b090000 pid=2443->6c41c2cd-8068-525f-9229-995adab0aeae send: 93B
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2026-03-16 20:13:23 UTC
File Type:
Text (Shell)
AV detection:
10 of 36 (27.78%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh dfd0ae045f59c9e099db50f461abf60207182e3a2f8a3be02fcfd9dae7e0e2f6

(this sample)

  
Delivery method
Distributed via web download

Comments