MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ec1737ab1a02dc56f45ace0b4e34f8340309e43fc548b742e356698fc10c87da. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: ec1737ab1a02dc56f45ace0b4e34f8340309e43fc548b742e356698fc10c87da
SHA3-384 hash: 41530a80699c7b49485a83d253f8c36593c20cf8cb0428555c3dd666605c160581f0527f58792b2f89061f425f7effdd
SHA1 hash: 849685167e089bee5e763b874ee0bcc0e03fb8f6
MD5 hash: 8d002fb8f5af8324d022f6c7b69a6a16
humanhash: william-texas-oven-seventeen
File name:milan.sh
Download: download sample
File size:921 bytes
First seen:2026-01-13 13:59:37 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:4tmRthRtF1RtF8Rt/jRttRt0ZXRtw8Rtzt0FRtORtxQBsUXpIvRffiFl3zUzE1t9:VBrybNkBR8uRQq7yFxdhIqr
TLSH T1F611E6CA2005471ECC7ACF68796686B8D138FA84B1D49B348CDC283E8808638705791D
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://143.20.185.78:6677/main/bins/arm5n/an/aua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
55
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-13T11:08:00Z UTC
Last seen:
2026-01-13T23:44:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen
Status:
terminated
Behavior Graph:
%3 guuid=35ffbce7-1800-0000-4f67-db215c140000 pid=5212 /usr/bin/sudo guuid=49d6cce9-1800-0000-4f67-db215d140000 pid=5213 /tmp/sample.bin guuid=35ffbce7-1800-0000-4f67-db215c140000 pid=5212->guuid=49d6cce9-1800-0000-4f67-db215d140000 pid=5213 execve guuid=6327c1ea-1800-0000-4f67-db215e140000 pid=5214 /usr/bin/wget net send-data write-file guuid=49d6cce9-1800-0000-4f67-db215d140000 pid=5213->guuid=6327c1ea-1800-0000-4f67-db215e140000 pid=5214 execve guuid=4fd07b0d-1900-0000-4f67-db215f140000 pid=5215 /usr/bin/wget net send-data write-file guuid=49d6cce9-1800-0000-4f67-db215d140000 pid=5213->guuid=4fd07b0d-1900-0000-4f67-db215f140000 pid=5215 execve guuid=3a56ffeb-1900-0000-4f67-db2167140000 pid=5223 /usr/bin/wget net send-data guuid=49d6cce9-1800-0000-4f67-db215d140000 pid=5213->guuid=3a56ffeb-1900-0000-4f67-db2167140000 pid=5223 execve guuid=c0553cf4-1900-0000-4f67-db2168140000 pid=5224 /usr/bin/wget net send-data guuid=49d6cce9-1800-0000-4f67-db215d140000 pid=5213->guuid=c0553cf4-1900-0000-4f67-db2168140000 pid=5224 execve guuid=20d4dbfc-1900-0000-4f67-db2169140000 pid=5225 /usr/bin/wget net send-data guuid=49d6cce9-1800-0000-4f67-db215d140000 pid=5213->guuid=20d4dbfc-1900-0000-4f67-db2169140000 pid=5225 execve guuid=3222bd05-1a00-0000-4f67-db216a140000 pid=5226 /usr/bin/wget net send-data guuid=49d6cce9-1800-0000-4f67-db215d140000 pid=5213->guuid=3222bd05-1a00-0000-4f67-db216a140000 pid=5226 execve guuid=b377d80c-1a00-0000-4f67-db216b140000 pid=5227 /usr/bin/wget net send-data guuid=49d6cce9-1800-0000-4f67-db215d140000 pid=5213->guuid=b377d80c-1a00-0000-4f67-db216b140000 pid=5227 execve guuid=20e85115-1a00-0000-4f67-db216c140000 pid=5228 /usr/bin/wget net send-data guuid=49d6cce9-1800-0000-4f67-db215d140000 pid=5213->guuid=20e85115-1a00-0000-4f67-db216c140000 pid=5228 execve guuid=97583f5c-1a00-0000-4f67-db216d140000 pid=5229 /usr/bin/wget net send-data guuid=49d6cce9-1800-0000-4f67-db215d140000 pid=5213->guuid=97583f5c-1a00-0000-4f67-db216d140000 pid=5229 execve guuid=261a0b64-1a00-0000-4f67-db216e140000 pid=5230 /usr/bin/wget net send-data guuid=49d6cce9-1800-0000-4f67-db215d140000 pid=5213->guuid=261a0b64-1a00-0000-4f67-db216e140000 pid=5230 execve guuid=128b416e-1a00-0000-4f67-db216f140000 pid=5231 /usr/bin/wget net send-data guuid=49d6cce9-1800-0000-4f67-db215d140000 pid=5213->guuid=128b416e-1a00-0000-4f67-db216f140000 pid=5231 execve guuid=76aff777-1a00-0000-4f67-db2170140000 pid=5232 /usr/bin/chmod guuid=49d6cce9-1800-0000-4f67-db215d140000 pid=5213->guuid=76aff777-1a00-0000-4f67-db2170140000 pid=5232 execve guuid=ac378a79-1a00-0000-4f67-db2171140000 pid=5233 /usr/bin/bash guuid=49d6cce9-1800-0000-4f67-db215d140000 pid=5213->guuid=ac378a79-1a00-0000-4f67-db2171140000 pid=5233 clone guuid=28a09279-1a00-0000-4f67-db2172140000 pid=5234 /usr/bin/bash guuid=49d6cce9-1800-0000-4f67-db215d140000 pid=5213->guuid=28a09279-1a00-0000-4f67-db2172140000 pid=5234 clone guuid=a5109a79-1a00-0000-4f67-db2173140000 pid=5235 /usr/bin/bash guuid=49d6cce9-1800-0000-4f67-db215d140000 pid=5213->guuid=a5109a79-1a00-0000-4f67-db2173140000 pid=5235 clone guuid=13a9a179-1a00-0000-4f67-db2174140000 pid=5236 /usr/bin/bash guuid=49d6cce9-1800-0000-4f67-db215d140000 pid=5213->guuid=13a9a179-1a00-0000-4f67-db2174140000 pid=5236 clone guuid=1b69d079-1a00-0000-4f67-db2175140000 pid=5237 /usr/bin/bash guuid=49d6cce9-1800-0000-4f67-db215d140000 pid=5213->guuid=1b69d079-1a00-0000-4f67-db2175140000 pid=5237 clone guuid=7307d979-1a00-0000-4f67-db2177140000 pid=5239 /usr/bin/bash guuid=49d6cce9-1800-0000-4f67-db215d140000 pid=5213->guuid=7307d979-1a00-0000-4f67-db2177140000 pid=5239 clone guuid=4bae037a-1a00-0000-4f67-db2178140000 pid=5240 /usr/bin/bash guuid=49d6cce9-1800-0000-4f67-db215d140000 pid=5213->guuid=4bae037a-1a00-0000-4f67-db2178140000 pid=5240 clone guuid=50f40f7a-1a00-0000-4f67-db217a140000 pid=5242 /usr/bin/bash guuid=49d6cce9-1800-0000-4f67-db215d140000 pid=5213->guuid=50f40f7a-1a00-0000-4f67-db217a140000 pid=5242 clone guuid=205c1c7a-1a00-0000-4f67-db217c140000 pid=5244 /usr/bin/bash guuid=49d6cce9-1800-0000-4f67-db215d140000 pid=5213->guuid=205c1c7a-1a00-0000-4f67-db217c140000 pid=5244 clone guuid=b8464a7a-1a00-0000-4f67-db217d140000 pid=5245 /usr/bin/bash guuid=49d6cce9-1800-0000-4f67-db215d140000 pid=5213->guuid=b8464a7a-1a00-0000-4f67-db217d140000 pid=5245 clone guuid=a77d527a-1a00-0000-4f67-db217e140000 pid=5246 /usr/bin/bash guuid=49d6cce9-1800-0000-4f67-db215d140000 pid=5213->guuid=a77d527a-1a00-0000-4f67-db217e140000 pid=5246 clone guuid=3458357b-1a00-0000-4f67-db2185140000 pid=5253 /usr/bin/sleep guuid=49d6cce9-1800-0000-4f67-db215d140000 pid=5213->guuid=3458357b-1a00-0000-4f67-db2185140000 pid=5253 execve guuid=9788a9d0-1c00-0000-4f67-db21bc140000 pid=5308 /usr/bin/rm guuid=49d6cce9-1800-0000-4f67-db215d140000 pid=5213->guuid=9788a9d0-1c00-0000-4f67-db21bc140000 pid=5308 execve guuid=977f44d1-1c00-0000-4f67-db21bd140000 pid=5309 /usr/bin/rm delete-file guuid=49d6cce9-1800-0000-4f67-db215d140000 pid=5213->guuid=977f44d1-1c00-0000-4f67-db21bd140000 pid=5309 execve 9f23aef7-c9ba-5095-a7bd-76a3765187d1 143.20.185.78:6677 guuid=6327c1ea-1800-0000-4f67-db215e140000 pid=5214->9f23aef7-c9ba-5095-a7bd-76a3765187d1 send: 146B guuid=4fd07b0d-1900-0000-4f67-db215f140000 pid=5215->9f23aef7-c9ba-5095-a7bd-76a3765187d1 send: 146B guuid=3a56ffeb-1900-0000-4f67-db2167140000 pid=5223->9f23aef7-c9ba-5095-a7bd-76a3765187d1 send: 147B guuid=c0553cf4-1900-0000-4f67-db2168140000 pid=5224->9f23aef7-c9ba-5095-a7bd-76a3765187d1 send: 149B guuid=20d4dbfc-1900-0000-4f67-db2169140000 pid=5225->9f23aef7-c9ba-5095-a7bd-76a3765187d1 send: 147B guuid=3222bd05-1a00-0000-4f67-db216a140000 pid=5226->9f23aef7-c9ba-5095-a7bd-76a3765187d1 send: 146B guuid=b377d80c-1a00-0000-4f67-db216b140000 pid=5227->9f23aef7-c9ba-5095-a7bd-76a3765187d1 send: 147B guuid=20e85115-1a00-0000-4f67-db216c140000 pid=5228->9f23aef7-c9ba-5095-a7bd-76a3765187d1 send: 146B guuid=97583f5c-1a00-0000-4f67-db216d140000 pid=5229->9f23aef7-c9ba-5095-a7bd-76a3765187d1 send: 147B guuid=261a0b64-1a00-0000-4f67-db216e140000 pid=5230->9f23aef7-c9ba-5095-a7bd-76a3765187d1 send: 147B guuid=128b416e-1a00-0000-4f67-db216f140000 pid=5231->9f23aef7-c9ba-5095-a7bd-76a3765187d1 send: 147B guuid=da49be7b-1a00-0000-4f67-db2188140000 pid=5256 /tmp/x86 guuid=ac378a79-1a00-0000-4f67-db2171140000 pid=5233->guuid=da49be7b-1a00-0000-4f67-db2188140000 pid=5256 execve guuid=8ff87b7b-1a00-0000-4f67-db2186140000 pid=5254 /tmp/x32 guuid=28a09279-1a00-0000-4f67-db2172140000 pid=5234->guuid=8ff87b7b-1a00-0000-4f67-db2186140000 pid=5254 execve guuid=0fcad879-1a00-0000-4f67-db2176140000 pid=5238 /usr/bin/bash guuid=a5109a79-1a00-0000-4f67-db2173140000 pid=5235->guuid=0fcad879-1a00-0000-4f67-db2176140000 pid=5238 clone guuid=2125117a-1a00-0000-4f67-db217b140000 pid=5243 /usr/bin/bash guuid=13a9a179-1a00-0000-4f67-db2174140000 pid=5236->guuid=2125117a-1a00-0000-4f67-db217b140000 pid=5243 clone guuid=8679057a-1a00-0000-4f67-db2179140000 pid=5241 /usr/bin/bash guuid=1b69d079-1a00-0000-4f67-db2175140000 pid=5237->guuid=8679057a-1a00-0000-4f67-db2179140000 pid=5241 clone guuid=dd6dc17a-1a00-0000-4f67-db2182140000 pid=5250 /usr/bin/bash guuid=7307d979-1a00-0000-4f67-db2177140000 pid=5239->guuid=dd6dc17a-1a00-0000-4f67-db2182140000 pid=5250 clone guuid=ab04837a-1a00-0000-4f67-db217f140000 pid=5247 /usr/bin/bash guuid=4bae037a-1a00-0000-4f67-db2178140000 pid=5240->guuid=ab04837a-1a00-0000-4f67-db217f140000 pid=5247 clone guuid=d2e2867a-1a00-0000-4f67-db2181140000 pid=5249 /usr/bin/bash guuid=50f40f7a-1a00-0000-4f67-db217a140000 pid=5242->guuid=d2e2867a-1a00-0000-4f67-db2181140000 pid=5249 clone guuid=1d8f837a-1a00-0000-4f67-db2180140000 pid=5248 /usr/bin/bash guuid=205c1c7a-1a00-0000-4f67-db217c140000 pid=5244->guuid=1d8f837a-1a00-0000-4f67-db2180140000 pid=5248 clone guuid=a942cc7a-1a00-0000-4f67-db2183140000 pid=5251 /usr/bin/bash guuid=b8464a7a-1a00-0000-4f67-db217d140000 pid=5245->guuid=a942cc7a-1a00-0000-4f67-db2183140000 pid=5251 clone guuid=50eaf87a-1a00-0000-4f67-db2184140000 pid=5252 /usr/bin/bash guuid=a77d527a-1a00-0000-4f67-db217e140000 pid=5246->guuid=50eaf87a-1a00-0000-4f67-db2184140000 pid=5252 clone guuid=599e9f7b-1a00-0000-4f67-db2187140000 pid=5255 /tmp/x32 zombie guuid=8ff87b7b-1a00-0000-4f67-db2186140000 pid=5254->guuid=599e9f7b-1a00-0000-4f67-db2187140000 pid=5255 clone guuid=8d651e7d-1a00-0000-4f67-db218c140000 pid=5260 /tmp/x32 net write-file zombie guuid=599e9f7b-1a00-0000-4f67-db2187140000 pid=5255->guuid=8d651e7d-1a00-0000-4f67-db218c140000 pid=5260 clone guuid=fab9d67b-1a00-0000-4f67-db2189140000 pid=5257 /tmp/x86 zombie guuid=da49be7b-1a00-0000-4f67-db2188140000 pid=5256->guuid=fab9d67b-1a00-0000-4f67-db2189140000 pid=5257 clone guuid=0fa7a47c-1a00-0000-4f67-db218a140000 pid=5258 /tmp/x86 net write-file zombie guuid=fab9d67b-1a00-0000-4f67-db2189140000 pid=5257->guuid=0fa7a47c-1a00-0000-4f67-db218a140000 pid=5258 clone 47c64279-6e34-5ab3-9965-af10758081e4 143.20.185.78:6678 guuid=0fa7a47c-1a00-0000-4f67-db218a140000 pid=5258->47c64279-6e34-5ab3-9965-af10758081e4 con guuid=8065e37c-1a00-0000-4f67-db218b140000 pid=5259 /usr/bin/dash guuid=0fa7a47c-1a00-0000-4f67-db218a140000 pid=5258->guuid=8065e37c-1a00-0000-4f67-db218b140000 pid=5259 execve guuid=ece9387e-1a00-0000-4f67-db218f140000 pid=5263 /usr/bin/dash guuid=0fa7a47c-1a00-0000-4f67-db218a140000 pid=5258->guuid=ece9387e-1a00-0000-4f67-db218f140000 pid=5263 execve guuid=f396739f-1a00-0000-4f67-db2192140000 pid=5266 /usr/bin/dash guuid=0fa7a47c-1a00-0000-4f67-db218a140000 pid=5258->guuid=f396739f-1a00-0000-4f67-db2192140000 pid=5266 execve guuid=c3abc4ab-1a00-0000-4f67-db2198140000 pid=5272 /usr/bin/dash guuid=0fa7a47c-1a00-0000-4f67-db218a140000 pid=5258->guuid=c3abc4ab-1a00-0000-4f67-db2198140000 pid=5272 execve guuid=8d651e7d-1a00-0000-4f67-db218c140000 pid=5260->47c64279-6e34-5ab3-9965-af10758081e4 con guuid=9d445e7d-1a00-0000-4f67-db218d140000 pid=5261 /usr/bin/dash guuid=8d651e7d-1a00-0000-4f67-db218c140000 pid=5260->guuid=9d445e7d-1a00-0000-4f67-db218d140000 pid=5261 execve guuid=281dd57d-1a00-0000-4f67-db218e140000 pid=5262 /usr/bin/dash guuid=8d651e7d-1a00-0000-4f67-db218c140000 pid=5260->guuid=281dd57d-1a00-0000-4f67-db218e140000 pid=5262 execve guuid=a6f9e4a1-1a00-0000-4f67-db2195140000 pid=5269 /usr/bin/dash guuid=8d651e7d-1a00-0000-4f67-db218c140000 pid=5260->guuid=a6f9e4a1-1a00-0000-4f67-db2195140000 pid=5269 execve guuid=01a8e6ac-1a00-0000-4f67-db219a140000 pid=5274 /usr/bin/dash guuid=8d651e7d-1a00-0000-4f67-db218c140000 pid=5260->guuid=01a8e6ac-1a00-0000-4f67-db219a140000 pid=5274 execve guuid=2286b67e-1a00-0000-4f67-db2191140000 pid=5265 /usr/bin/wget dns net send-data write-file guuid=281dd57d-1a00-0000-4f67-db218e140000 pid=5262->guuid=2286b67e-1a00-0000-4f67-db2191140000 pid=5265 execve guuid=ec3e677e-1a00-0000-4f67-db2190140000 pid=5264 /usr/bin/wget dns net send-data write-file guuid=ece9387e-1a00-0000-4f67-db218f140000 pid=5263->guuid=ec3e677e-1a00-0000-4f67-db2190140000 pid=5264 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=ec3e677e-1a00-0000-4f67-db2190140000 pid=5264->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 164B 75aab096-419b-50ef-be46-7d76b6a90e4c github.com:443 guuid=ec3e677e-1a00-0000-4f67-db2190140000 pid=5264->75aab096-419b-50ef-be46-7d76b6a90e4c send: 802B f8c5e44f-328d-5324-8bbd-da50752b9120 release-assets.githubusercontent.com:0 guuid=ec3e677e-1a00-0000-4f67-db2190140000 pid=5264->f8c5e44f-328d-5324-8bbd-da50752b9120 con f0eebea5-e97d-507c-a771-59cac353877c release-assets.githubusercontent.com:443 guuid=ec3e677e-1a00-0000-4f67-db2190140000 pid=5264->f0eebea5-e97d-507c-a771-59cac353877c send: 1662B guuid=2286b67e-1a00-0000-4f67-db2191140000 pid=5265->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 164B guuid=2286b67e-1a00-0000-4f67-db2191140000 pid=5265->75aab096-419b-50ef-be46-7d76b6a90e4c send: 802B guuid=2286b67e-1a00-0000-4f67-db2191140000 pid=5265->f8c5e44f-328d-5324-8bbd-da50752b9120 con guuid=2286b67e-1a00-0000-4f67-db2191140000 pid=5265->f0eebea5-e97d-507c-a771-59cac353877c send: 1662B guuid=5be3a09f-1a00-0000-4f67-db2193140000 pid=5267 /usr/bin/tar write-file guuid=f396739f-1a00-0000-4f67-db2192140000 pid=5266->guuid=5be3a09f-1a00-0000-4f67-db2193140000 pid=5267 execve guuid=953493a0-1a00-0000-4f67-db2194140000 pid=5268 /usr/bin/gzip guuid=5be3a09f-1a00-0000-4f67-db2193140000 pid=5267->guuid=953493a0-1a00-0000-4f67-db2194140000 pid=5268 execve guuid=6ca314a2-1a00-0000-4f67-db2196140000 pid=5270 /usr/bin/tar delete-file write-file guuid=a6f9e4a1-1a00-0000-4f67-db2195140000 pid=5269->guuid=6ca314a2-1a00-0000-4f67-db2196140000 pid=5270 execve guuid=830b8ba2-1a00-0000-4f67-db2197140000 pid=5271 /usr/bin/gzip guuid=6ca314a2-1a00-0000-4f67-db2196140000 pid=5270->guuid=830b8ba2-1a00-0000-4f67-db2197140000 pid=5271 execve guuid=19afefab-1a00-0000-4f67-db2199140000 pid=5273 /usr/bin/rm delete-file guuid=c3abc4ab-1a00-0000-4f67-db2198140000 pid=5272->guuid=19afefab-1a00-0000-4f67-db2199140000 pid=5273 execve guuid=a79a17ad-1a00-0000-4f67-db219b140000 pid=5275 /usr/bin/rm guuid=01a8e6ac-1a00-0000-4f67-db219a140000 pid=5274->guuid=a79a17ad-1a00-0000-4f67-db219b140000 pid=5275 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2026-01-13 13:21:57 UTC
File Type:
Text (Shell)
AV detection:
6 of 36 (16.67%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh ec1737ab1a02dc56f45ace0b4e34f8340309e43fc548b742e356698fc10c87da

(this sample)

  
Delivery method
Distributed via web download

Comments