MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ef2f28b8f20aab6c56ab8bcde6a7e1a0b0ab17c2ec8cee02f3bf369140e8a700. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: ef2f28b8f20aab6c56ab8bcde6a7e1a0b0ab17c2ec8cee02f3bf369140e8a700
SHA3-384 hash: 0fe3acde971f6a47336962994582e8c0b45fda4ea3e464b513366704c1bbba2e8c22ded8cc3c25989466e52a8b5d6c99
SHA1 hash: afe78b69e8def4806c63f56f85f9ea5e773d3c6b
MD5 hash: 79705c9ab0b03aae6462944fcf224d53
humanhash: kansas-robin-fanta-two
File name:californication.sh
Download: download sample
Signature Gafgyt
File size:2'115 bytes
First seen:2026-04-06 08:03:03 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:1zttYLqnTPj/owXqCGa/zr3b66rserPqVo8:1zHnTPj/owXqCf/zzb66rsqPqV5
TLSH T1274183C760E10770ECB5AA3772669801B9D9D0E626DD5F96DCFC38E9408CEC4389E683
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://82.25.56.112/cali.mipsee4732df2f600bba6faf9790d822a9ab9f40fe2bf72b0c64917359e12043a820 Gafgytelf gafgyt ua-wget
http://82.25.56.112/cali.mipsel363cb0b6bdd66193ec537f2a2222657a8389c493e8e8b091268b748795c04c9d Gafgytelf gafgyt ua-wget
http://82.25.56.112/cali.sh4c74bda6c601c08802724569b523ab94f2bff979d6ae2e1972a618dc4e303a08a Gafgytelf gafgyt ua-wget
http://82.25.56.112/cali.x8639bea49f694f71113619706b0df298fefc29139f9006b5031a287dc4b3b351c1 Miraielf gafgyt ua-wget
http://82.25.56.112/cali.armv7l365bd19979a7de7b34cb1bc01d35d7f4b4d4b0cda3996021fd88616457c3554e Gafgytelf gafgyt ua-wget
http://82.25.56.112/cali.armv6l05e8bcfc1f5ae44413daa7e5dc772d4316901be7a59fe3862a6c3f8fbf2de19c Gafgytelf gafgyt ua-wget
http://82.25.56.112/cali.i6860dbe04e2373342275ff1e25963440c56b07ab056a23927cfaf94a1d7ece8c596 Miraielf gafgyt ua-wget
http://82.25.56.112/cali.powerpcb135ccb9dadede605fd0d2f9269d455419ca5fd6e01df71ed011ea157fc5d857 Gafgytelf gafgyt ua-wget
http://82.25.56.112/cali.i5860c635a845f285a5b4cbe3ec0dc7cd3f2b20f3e580634c459c0e6590411f034d1 Miraielf gafgyt ua-wget
http://82.25.56.112/cali.m68ke83640cd75236a3cc3f7310404e6451a31c351ae0e65b2816f8b50722a6e12c5 Gafgytelf gafgyt ua-wget
http://82.25.56.112/cali.sparc834410da03692bcb79c6259b2bc5091cda7fe48c8f524d02f0a6ba93c4bedf06 Gafgytelf gafgyt ua-wget
http://82.25.56.112/cali.armv4lae39d9bb90596bad86c57dfd18a5fb1923be8f052cec069632e568cf50e79114 Gafgytelf gafgyt ua-wget
http://82.25.56.112/cali.armv5l70b58485e56d83cef2e2ed664391833eef49b367b870d1050bdb13099d125d45 Gafgytelf gafgyt ua-wget
http://82.25.56.112/cali.powerpc-440fpn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
54
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive medusa mirai
Verdict:
Malicious
File Type:
text
First seen:
2026-04-06T00:21:00Z UTC
Last seen:
2026-04-07T23:45:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=2c592868-1800-0000-b6f1-ae26a4080000 pid=2212 /usr/bin/sudo guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220 /tmp/sample.bin guuid=2c592868-1800-0000-b6f1-ae26a4080000 pid=2212->guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220 execve guuid=d58f2e6b-1800-0000-b6f1-ae26ae080000 pid=2222 /usr/bin/wget net send-data write-file guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=d58f2e6b-1800-0000-b6f1-ae26ae080000 pid=2222 execve guuid=a00f8c73-1800-0000-b6f1-ae26c6080000 pid=2246 /usr/bin/chmod guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=a00f8c73-1800-0000-b6f1-ae26c6080000 pid=2246 execve guuid=d4420674-1800-0000-b6f1-ae26c7080000 pid=2247 /usr/bin/dash guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=d4420674-1800-0000-b6f1-ae26c7080000 pid=2247 clone guuid=0d961a74-1800-0000-b6f1-ae26c8080000 pid=2248 /usr/bin/rm delete-file guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=0d961a74-1800-0000-b6f1-ae26c8080000 pid=2248 execve guuid=ae7f8574-1800-0000-b6f1-ae26ca080000 pid=2250 /usr/bin/wget net send-data write-file guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=ae7f8574-1800-0000-b6f1-ae26ca080000 pid=2250 execve guuid=1e7fa97a-1800-0000-b6f1-ae26d8080000 pid=2264 /usr/bin/chmod guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=1e7fa97a-1800-0000-b6f1-ae26d8080000 pid=2264 execve guuid=33bb037b-1800-0000-b6f1-ae26da080000 pid=2266 /usr/bin/dash guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=33bb037b-1800-0000-b6f1-ae26da080000 pid=2266 clone guuid=1ef6107b-1800-0000-b6f1-ae26db080000 pid=2267 /usr/bin/rm delete-file guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=1ef6107b-1800-0000-b6f1-ae26db080000 pid=2267 execve guuid=9e28617b-1800-0000-b6f1-ae26dd080000 pid=2269 /usr/bin/wget net send-data write-file guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=9e28617b-1800-0000-b6f1-ae26dd080000 pid=2269 execve guuid=71aec585-1800-0000-b6f1-ae26f6080000 pid=2294 /usr/bin/chmod guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=71aec585-1800-0000-b6f1-ae26f6080000 pid=2294 execve guuid=73280486-1800-0000-b6f1-ae26f7080000 pid=2295 /usr/bin/dash guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=73280486-1800-0000-b6f1-ae26f7080000 pid=2295 clone guuid=b7cf1186-1800-0000-b6f1-ae26f8080000 pid=2296 /usr/bin/rm delete-file guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=b7cf1186-1800-0000-b6f1-ae26f8080000 pid=2296 execve guuid=9aac5186-1800-0000-b6f1-ae26fa080000 pid=2298 /usr/bin/wget net send-data write-file guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=9aac5186-1800-0000-b6f1-ae26fa080000 pid=2298 execve guuid=ad9d808c-1800-0000-b6f1-ae2608090000 pid=2312 /usr/bin/chmod guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=ad9d808c-1800-0000-b6f1-ae2608090000 pid=2312 execve guuid=1391ca8c-1800-0000-b6f1-ae2609090000 pid=2313 /usr/bin/dash guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=1391ca8c-1800-0000-b6f1-ae2609090000 pid=2313 clone guuid=e260d58c-1800-0000-b6f1-ae260a090000 pid=2314 /usr/bin/rm delete-file guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=e260d58c-1800-0000-b6f1-ae260a090000 pid=2314 execve guuid=abfb1d8d-1800-0000-b6f1-ae260b090000 pid=2315 /usr/bin/wget net send-data write-file guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=abfb1d8d-1800-0000-b6f1-ae260b090000 pid=2315 execve guuid=67b7fd96-1800-0000-b6f1-ae2624090000 pid=2340 /usr/bin/chmod guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=67b7fd96-1800-0000-b6f1-ae2624090000 pid=2340 execve guuid=06c06097-1800-0000-b6f1-ae2626090000 pid=2342 /usr/bin/dash guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=06c06097-1800-0000-b6f1-ae2626090000 pid=2342 clone guuid=9de88197-1800-0000-b6f1-ae2627090000 pid=2343 /usr/bin/rm delete-file guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=9de88197-1800-0000-b6f1-ae2627090000 pid=2343 execve guuid=ab83cc97-1800-0000-b6f1-ae2629090000 pid=2345 /usr/bin/wget net send-data write-file guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=ab83cc97-1800-0000-b6f1-ae2629090000 pid=2345 execve guuid=8bb10fa3-1800-0000-b6f1-ae2641090000 pid=2369 /usr/bin/chmod guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=8bb10fa3-1800-0000-b6f1-ae2641090000 pid=2369 execve guuid=46cf58a3-1800-0000-b6f1-ae2643090000 pid=2371 /usr/bin/dash guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=46cf58a3-1800-0000-b6f1-ae2643090000 pid=2371 clone guuid=6e1164a3-1800-0000-b6f1-ae2644090000 pid=2372 /usr/bin/rm delete-file guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=6e1164a3-1800-0000-b6f1-ae2644090000 pid=2372 execve guuid=71da9ea3-1800-0000-b6f1-ae2645090000 pid=2373 /usr/bin/wget net send-data write-file guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=71da9ea3-1800-0000-b6f1-ae2645090000 pid=2373 execve guuid=c1ad83aa-1800-0000-b6f1-ae2658090000 pid=2392 /usr/bin/chmod guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=c1ad83aa-1800-0000-b6f1-ae2658090000 pid=2392 execve guuid=6686d9aa-1800-0000-b6f1-ae265a090000 pid=2394 /usr/bin/dash guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=6686d9aa-1800-0000-b6f1-ae265a090000 pid=2394 clone guuid=0a93e7aa-1800-0000-b6f1-ae265b090000 pid=2395 /usr/bin/rm delete-file guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=0a93e7aa-1800-0000-b6f1-ae265b090000 pid=2395 execve guuid=5a4c29ab-1800-0000-b6f1-ae265d090000 pid=2397 /usr/bin/wget net send-data write-file guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=5a4c29ab-1800-0000-b6f1-ae265d090000 pid=2397 execve guuid=b76085b0-1800-0000-b6f1-ae266d090000 pid=2413 /usr/bin/chmod guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=b76085b0-1800-0000-b6f1-ae266d090000 pid=2413 execve guuid=6511e5b0-1800-0000-b6f1-ae266f090000 pid=2415 /usr/bin/dash guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=6511e5b0-1800-0000-b6f1-ae266f090000 pid=2415 clone guuid=4197f2b0-1800-0000-b6f1-ae2670090000 pid=2416 /usr/bin/rm delete-file guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=4197f2b0-1800-0000-b6f1-ae2670090000 pid=2416 execve guuid=31ab2fb1-1800-0000-b6f1-ae2672090000 pid=2418 /usr/bin/wget net send-data write-file guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=31ab2fb1-1800-0000-b6f1-ae2672090000 pid=2418 execve guuid=dc5f9eb6-1800-0000-b6f1-ae2676090000 pid=2422 /usr/bin/chmod guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=dc5f9eb6-1800-0000-b6f1-ae2676090000 pid=2422 execve guuid=0386e9b6-1800-0000-b6f1-ae2677090000 pid=2423 /usr/bin/dash guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=0386e9b6-1800-0000-b6f1-ae2677090000 pid=2423 clone guuid=0182feb6-1800-0000-b6f1-ae2678090000 pid=2424 /usr/bin/rm delete-file guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=0182feb6-1800-0000-b6f1-ae2678090000 pid=2424 execve guuid=ee7963b7-1800-0000-b6f1-ae2679090000 pid=2425 /usr/bin/wget net send-data write-file guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=ee7963b7-1800-0000-b6f1-ae2679090000 pid=2425 execve guuid=883c6cc1-1800-0000-b6f1-ae268e090000 pid=2446 /usr/bin/chmod guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=883c6cc1-1800-0000-b6f1-ae268e090000 pid=2446 execve guuid=f92cb3c1-1800-0000-b6f1-ae268f090000 pid=2447 /usr/bin/dash guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=f92cb3c1-1800-0000-b6f1-ae268f090000 pid=2447 clone guuid=74c6c0c1-1800-0000-b6f1-ae2690090000 pid=2448 /usr/bin/rm delete-file guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=74c6c0c1-1800-0000-b6f1-ae2690090000 pid=2448 execve guuid=6e9110c2-1800-0000-b6f1-ae2691090000 pid=2449 /usr/bin/wget net send-data write-file guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=6e9110c2-1800-0000-b6f1-ae2691090000 pid=2449 execve guuid=91590bcd-1800-0000-b6f1-ae26ac090000 pid=2476 /usr/bin/chmod guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=91590bcd-1800-0000-b6f1-ae26ac090000 pid=2476 execve guuid=991664cd-1800-0000-b6f1-ae26ae090000 pid=2478 /usr/bin/dash guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=991664cd-1800-0000-b6f1-ae26ae090000 pid=2478 clone guuid=e5e372cd-1800-0000-b6f1-ae26af090000 pid=2479 /usr/bin/rm delete-file guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=e5e372cd-1800-0000-b6f1-ae26af090000 pid=2479 execve guuid=6a3a09ce-1800-0000-b6f1-ae26b1090000 pid=2481 /usr/bin/wget net send-data write-file guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=6a3a09ce-1800-0000-b6f1-ae26b1090000 pid=2481 execve guuid=dcbd39d4-1800-0000-b6f1-ae26bd090000 pid=2493 /usr/bin/chmod guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=dcbd39d4-1800-0000-b6f1-ae26bd090000 pid=2493 execve guuid=58de7ed4-1800-0000-b6f1-ae26bf090000 pid=2495 /usr/bin/dash guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=58de7ed4-1800-0000-b6f1-ae26bf090000 pid=2495 clone guuid=32bb89d4-1800-0000-b6f1-ae26c0090000 pid=2496 /usr/bin/rm delete-file guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=32bb89d4-1800-0000-b6f1-ae26c0090000 pid=2496 execve guuid=2648d4d4-1800-0000-b6f1-ae26c2090000 pid=2498 /usr/bin/wget net send-data write-file guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=2648d4d4-1800-0000-b6f1-ae26c2090000 pid=2498 execve guuid=b95259da-1800-0000-b6f1-ae26d4090000 pid=2516 /usr/bin/chmod guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=b95259da-1800-0000-b6f1-ae26d4090000 pid=2516 execve guuid=5e2ea8da-1800-0000-b6f1-ae26d6090000 pid=2518 /usr/bin/dash guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=5e2ea8da-1800-0000-b6f1-ae26d6090000 pid=2518 clone guuid=40bbbcda-1800-0000-b6f1-ae26d7090000 pid=2519 /usr/bin/rm delete-file guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=40bbbcda-1800-0000-b6f1-ae26d7090000 pid=2519 execve guuid=0a8303db-1800-0000-b6f1-ae26d9090000 pid=2521 /usr/bin/wget net send-data guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=0a8303db-1800-0000-b6f1-ae26d9090000 pid=2521 execve guuid=19ac38df-1800-0000-b6f1-ae26e1090000 pid=2529 /usr/bin/chmod guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=19ac38df-1800-0000-b6f1-ae26e1090000 pid=2529 execve guuid=ef9b77df-1800-0000-b6f1-ae26e2090000 pid=2530 /usr/bin/dash guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=ef9b77df-1800-0000-b6f1-ae26e2090000 pid=2530 clone guuid=17907cdf-1800-0000-b6f1-ae26e3090000 pid=2531 /usr/bin/rm guuid=fc0bed6a-1800-0000-b6f1-ae26ac080000 pid=2220->guuid=17907cdf-1800-0000-b6f1-ae26e3090000 pid=2531 execve 82bb1217-6cac-520f-b818-a90e8a4f235f 82.25.56.112:80 guuid=d58f2e6b-1800-0000-b6f1-ae26ae080000 pid=2222->82bb1217-6cac-520f-b818-a90e8a4f235f send: 136B guuid=ae7f8574-1800-0000-b6f1-ae26ca080000 pid=2250->82bb1217-6cac-520f-b818-a90e8a4f235f send: 138B guuid=9e28617b-1800-0000-b6f1-ae26dd080000 pid=2269->82bb1217-6cac-520f-b818-a90e8a4f235f send: 135B guuid=9aac5186-1800-0000-b6f1-ae26fa080000 pid=2298->82bb1217-6cac-520f-b818-a90e8a4f235f send: 135B guuid=abfb1d8d-1800-0000-b6f1-ae260b090000 pid=2315->82bb1217-6cac-520f-b818-a90e8a4f235f send: 138B guuid=ab83cc97-1800-0000-b6f1-ae2629090000 pid=2345->82bb1217-6cac-520f-b818-a90e8a4f235f send: 138B guuid=71da9ea3-1800-0000-b6f1-ae2645090000 pid=2373->82bb1217-6cac-520f-b818-a90e8a4f235f send: 136B guuid=5a4c29ab-1800-0000-b6f1-ae265d090000 pid=2397->82bb1217-6cac-520f-b818-a90e8a4f235f send: 139B guuid=31ab2fb1-1800-0000-b6f1-ae2672090000 pid=2418->82bb1217-6cac-520f-b818-a90e8a4f235f send: 136B guuid=ee7963b7-1800-0000-b6f1-ae2679090000 pid=2425->82bb1217-6cac-520f-b818-a90e8a4f235f send: 136B guuid=6e9110c2-1800-0000-b6f1-ae2691090000 pid=2449->82bb1217-6cac-520f-b818-a90e8a4f235f send: 137B guuid=6a3a09ce-1800-0000-b6f1-ae26b1090000 pid=2481->82bb1217-6cac-520f-b818-a90e8a4f235f send: 138B guuid=2648d4d4-1800-0000-b6f1-ae26c2090000 pid=2498->82bb1217-6cac-520f-b818-a90e8a4f235f send: 138B guuid=0a8303db-1800-0000-b6f1-ae26d9090000 pid=2521->82bb1217-6cac-520f-b818-a90e8a4f235f send: 145B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-04-06 08:03:48 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh ef2f28b8f20aab6c56ab8bcde6a7e1a0b0ab17c2ec8cee02f3bf369140e8a700

(this sample)

  
Delivery method
Distributed via web download

Comments