MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f0f33fed457fb3547e9a2f2a913a611299c5efa7efbba696d9bd00a01bcb1084. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: f0f33fed457fb3547e9a2f2a913a611299c5efa7efbba696d9bd00a01bcb1084
SHA3-384 hash: 3fe53c3481bb7b28fcfdb45b326ac89722d7a25ede4b9d022c8e18c358e557a9d522ed303633d67ab4c8bd4e91054233
SHA1 hash: d6c881918b11fe237972643efc0707f10adacb44
MD5 hash: becb188b716783b88a221ad30ff97795
humanhash: aspen-echo-kentucky-magnesium
File name:android.sh
Download: download sample
File size:1'181 bytes
First seen:2026-05-23 00:43:57 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:qcW4h9b9W9SR+8NI5IX+ryCKHNS5Go3sdefU+deIfdSIHYDKrBsTsXpYYeBKOp84:q4h9b9W9SQGCWgLs8U+ffAJDKraTsXp0
TLSH T12021B0DE00A17C4381649D1930E1C9489005CADF75EE1F68FEC87C36DDD599C73A6B5A
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139.188/tg1zgmft/uasvdmt.armn/an/aarm elf ua-wget
http://176.65.139.188/tg1zgmft/qtmrdhj.arm5n/an/aarm elf ua-wget
http://176.65.139.188/tg1zgmft/tpydwmr.arm6n/an/aarm elf ua-wget
http://176.65.139.188/tg1zgmft/rrolpik.arm7n/an/aarm elf ua-wget
http://176.65.139.188/tg1zgmft/czwzdzt.aarch64n/an/aarm elf ua-wget
http://176.65.139.188/tg1zgmft/nqxefxw.mips64n/an/aelf mips ua-wget
http://176.65.139.188/tg1zgmft/bjsvazz.mipsn/an/aelf mips ua-wget
http://176.65.139.188/tg1zgmft/uztbtfs.mpsln/an/aelf mips ua-wget
http://176.65.139.188/tg1zgmft/jvwyawa.ppcn/an/aelf PowerPC ua-wget
http://176.65.139.188/tg1zgmft/nknrjhk.x86_64n/an/aelf ua-wget x86
http://176.65.139.188/tg1zgmft/jdruzjv.i686n/an/aelf ua-wget x86
http://176.65.139.188/tg1zgmft/nvbiyjp.i586n/an/aelf ua-wget x86
http://176.65.139.188/tg1zgmft/amvdvgp.i486n/an/aelf ua-wget x86

Intelligence


File Origin
# of uploads :
1
# of downloads :
51
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
ps1
First seen:
2026-05-22T21:15:00Z UTC
Last seen:
2026-05-23T00:34:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.gen
Status:
terminated
Behavior Graph:
%3 guuid=7e0aaa3f-1a00-0000-d459-01a5ae090000 pid=2478 /usr/bin/sudo guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485 /tmp/sample.bin guuid=7e0aaa3f-1a00-0000-d459-01a5ae090000 pid=2478->guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485 execve guuid=be9c2042-1a00-0000-d459-01a5b7090000 pid=2487 /usr/bin/wget net send-data write-file guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=be9c2042-1a00-0000-d459-01a5b7090000 pid=2487 execve guuid=e17e1b50-1a00-0000-d459-01a5cb090000 pid=2507 /usr/bin/chmod guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=e17e1b50-1a00-0000-d459-01a5cb090000 pid=2507 execve guuid=6c096550-1a00-0000-d459-01a5cd090000 pid=2509 /usr/bin/dash guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=6c096550-1a00-0000-d459-01a5cd090000 pid=2509 clone guuid=b20c2e51-1a00-0000-d459-01a5d1090000 pid=2513 /usr/bin/wget net send-data write-file guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=b20c2e51-1a00-0000-d459-01a5d1090000 pid=2513 execve guuid=2f8d1c5c-1a00-0000-d459-01a5e5090000 pid=2533 /usr/bin/chmod guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=2f8d1c5c-1a00-0000-d459-01a5e5090000 pid=2533 execve guuid=f605615c-1a00-0000-d459-01a5e7090000 pid=2535 /usr/bin/dash guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=f605615c-1a00-0000-d459-01a5e7090000 pid=2535 clone guuid=2211ea5c-1a00-0000-d459-01a5ea090000 pid=2538 /usr/bin/wget net send-data write-file guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=2211ea5c-1a00-0000-d459-01a5ea090000 pid=2538 execve guuid=9155bb68-1a00-0000-d459-01a5fa090000 pid=2554 /usr/bin/chmod guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=9155bb68-1a00-0000-d459-01a5fa090000 pid=2554 execve guuid=96b90469-1a00-0000-d459-01a5fc090000 pid=2556 /usr/bin/dash guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=96b90469-1a00-0000-d459-01a5fc090000 pid=2556 clone guuid=a3d1ae69-1a00-0000-d459-01a5ff090000 pid=2559 /usr/bin/wget net send-data write-file guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=a3d1ae69-1a00-0000-d459-01a5ff090000 pid=2559 execve guuid=2f8bf472-1a00-0000-d459-01a5100a0000 pid=2576 /usr/bin/chmod guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=2f8bf472-1a00-0000-d459-01a5100a0000 pid=2576 execve guuid=33bf4c73-1a00-0000-d459-01a5120a0000 pid=2578 /usr/bin/dash guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=33bf4c73-1a00-0000-d459-01a5120a0000 pid=2578 clone guuid=5bcdf973-1a00-0000-d459-01a5160a0000 pid=2582 /usr/bin/wget net send-data write-file guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=5bcdf973-1a00-0000-d459-01a5160a0000 pid=2582 execve guuid=f0c4807f-1a00-0000-d459-01a5330a0000 pid=2611 /usr/bin/chmod guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=f0c4807f-1a00-0000-d459-01a5330a0000 pid=2611 execve guuid=2ae7c07f-1a00-0000-d459-01a5350a0000 pid=2613 /usr/bin/dash guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=2ae7c07f-1a00-0000-d459-01a5350a0000 pid=2613 clone guuid=2cf04680-1a00-0000-d459-01a5390a0000 pid=2617 /usr/bin/wget net send-data write-file guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=2cf04680-1a00-0000-d459-01a5390a0000 pid=2617 execve guuid=8936b08b-1a00-0000-d459-01a5550a0000 pid=2645 /usr/bin/chmod guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=8936b08b-1a00-0000-d459-01a5550a0000 pid=2645 execve guuid=7dcffe8b-1a00-0000-d459-01a5570a0000 pid=2647 /usr/bin/dash guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=7dcffe8b-1a00-0000-d459-01a5570a0000 pid=2647 clone guuid=e83bc48c-1a00-0000-d459-01a55b0a0000 pid=2651 /usr/bin/wget net send-data write-file guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=e83bc48c-1a00-0000-d459-01a55b0a0000 pid=2651 execve guuid=eea0e996-1a00-0000-d459-01a5700a0000 pid=2672 /usr/bin/chmod guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=eea0e996-1a00-0000-d459-01a5700a0000 pid=2672 execve guuid=4a9d6497-1a00-0000-d459-01a5720a0000 pid=2674 /usr/bin/dash guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=4a9d6497-1a00-0000-d459-01a5720a0000 pid=2674 clone guuid=717e3c98-1a00-0000-d459-01a5760a0000 pid=2678 /usr/bin/wget net send-data write-file guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=717e3c98-1a00-0000-d459-01a5760a0000 pid=2678 execve guuid=76c7d9a3-1a00-0000-d459-01a5950a0000 pid=2709 /usr/bin/chmod guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=76c7d9a3-1a00-0000-d459-01a5950a0000 pid=2709 execve guuid=0bd219a4-1a00-0000-d459-01a5970a0000 pid=2711 /usr/bin/dash guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=0bd219a4-1a00-0000-d459-01a5970a0000 pid=2711 clone guuid=c5ffa9a4-1a00-0000-d459-01a59b0a0000 pid=2715 /usr/bin/wget net send-data write-file guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=c5ffa9a4-1a00-0000-d459-01a59b0a0000 pid=2715 execve guuid=596184ae-1a00-0000-d459-01a5b30a0000 pid=2739 /usr/bin/chmod guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=596184ae-1a00-0000-d459-01a5b30a0000 pid=2739 execve guuid=8872c6ae-1a00-0000-d459-01a5b50a0000 pid=2741 /usr/bin/dash guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=8872c6ae-1a00-0000-d459-01a5b50a0000 pid=2741 clone guuid=af3696af-1a00-0000-d459-01a5ba0a0000 pid=2746 /usr/bin/wget net send-data write-file guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=af3696af-1a00-0000-d459-01a5ba0a0000 pid=2746 execve guuid=f0e2dabb-1a00-0000-d459-01a5d40a0000 pid=2772 /usr/bin/chmod guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=f0e2dabb-1a00-0000-d459-01a5d40a0000 pid=2772 execve guuid=e3d13cbc-1a00-0000-d459-01a5d50a0000 pid=2773 memfd: delete-file write-file guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=e3d13cbc-1a00-0000-d459-01a5d50a0000 pid=2773 execve guuid=89325dc7-1a00-0000-d459-01a5f00a0000 pid=2800 /usr/bin/wget net send-data write-file guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=89325dc7-1a00-0000-d459-01a5f00a0000 pid=2800 execve guuid=2fd151d4-1a00-0000-d459-01a50e0b0000 pid=2830 /usr/bin/chmod guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=2fd151d4-1a00-0000-d459-01a50e0b0000 pid=2830 execve guuid=7d878fd4-1a00-0000-d459-01a50f0b0000 pid=2831 memfd: write-file guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=7d878fd4-1a00-0000-d459-01a50f0b0000 pid=2831 execve guuid=1c36f3d9-1a00-0000-d459-01a5190b0000 pid=2841 /usr/bin/dash guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=1c36f3d9-1a00-0000-d459-01a5190b0000 pid=2841 clone guuid=d3d3fdd9-1a00-0000-d459-01a51a0b0000 pid=2842 /usr/bin/chmod guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=d3d3fdd9-1a00-0000-d459-01a51a0b0000 pid=2842 execve guuid=9dbb50da-1a00-0000-d459-01a51d0b0000 pid=2845 /usr/bin/dash guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=9dbb50da-1a00-0000-d459-01a51d0b0000 pid=2845 clone guuid=101e69da-1a00-0000-d459-01a51e0b0000 pid=2846 /usr/bin/dash guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=101e69da-1a00-0000-d459-01a51e0b0000 pid=2846 clone guuid=5b088cda-1a00-0000-d459-01a51f0b0000 pid=2847 /usr/bin/chmod guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=5b088cda-1a00-0000-d459-01a51f0b0000 pid=2847 execve guuid=808bd8da-1a00-0000-d459-01a5210b0000 pid=2849 /usr/bin/dash guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=808bd8da-1a00-0000-d459-01a5210b0000 pid=2849 clone guuid=1cceeeda-1a00-0000-d459-01a5220b0000 pid=2850 /usr/bin/rm delete-file guuid=c7e5e841-1a00-0000-d459-01a5b5090000 pid=2485->guuid=1cceeeda-1a00-0000-d459-01a5220b0000 pid=2850 execve bbf5bc96-9f47-54ce-aa51-70672524d0f0 176.65.139.188:80 guuid=be9c2042-1a00-0000-d459-01a5b7090000 pid=2487->bbf5bc96-9f47-54ce-aa51-70672524d0f0 send: 149B guuid=b20c2e51-1a00-0000-d459-01a5d1090000 pid=2513->bbf5bc96-9f47-54ce-aa51-70672524d0f0 send: 150B guuid=2211ea5c-1a00-0000-d459-01a5ea090000 pid=2538->bbf5bc96-9f47-54ce-aa51-70672524d0f0 send: 150B guuid=a3d1ae69-1a00-0000-d459-01a5ff090000 pid=2559->bbf5bc96-9f47-54ce-aa51-70672524d0f0 send: 150B guuid=5bcdf973-1a00-0000-d459-01a5160a0000 pid=2582->bbf5bc96-9f47-54ce-aa51-70672524d0f0 send: 153B guuid=2cf04680-1a00-0000-d459-01a5390a0000 pid=2617->bbf5bc96-9f47-54ce-aa51-70672524d0f0 send: 152B guuid=e83bc48c-1a00-0000-d459-01a55b0a0000 pid=2651->bbf5bc96-9f47-54ce-aa51-70672524d0f0 send: 150B guuid=717e3c98-1a00-0000-d459-01a5760a0000 pid=2678->bbf5bc96-9f47-54ce-aa51-70672524d0f0 send: 150B guuid=c5ffa9a4-1a00-0000-d459-01a59b0a0000 pid=2715->bbf5bc96-9f47-54ce-aa51-70672524d0f0 send: 149B guuid=af3696af-1a00-0000-d459-01a5ba0a0000 pid=2746->bbf5bc96-9f47-54ce-aa51-70672524d0f0 send: 152B guuid=60913fc5-1a00-0000-d459-01a5e70a0000 pid=2791 memfd: guuid=e3d13cbc-1a00-0000-d459-01a5d50a0000 pid=2773->guuid=60913fc5-1a00-0000-d459-01a5e70a0000 pid=2791 clone guuid=b52a0bc7-1a00-0000-d459-01a5ec0a0000 pid=2796 memfd: guuid=e3d13cbc-1a00-0000-d459-01a5d50a0000 pid=2773->guuid=b52a0bc7-1a00-0000-d459-01a5ec0a0000 pid=2796 clone guuid=b57c24c7-1a00-0000-d459-01a5ee0a0000 pid=2798 memfd: guuid=e3d13cbc-1a00-0000-d459-01a5d50a0000 pid=2773->guuid=b57c24c7-1a00-0000-d459-01a5ee0a0000 pid=2798 clone guuid=d19653c7-1a00-0000-d459-01a5ef0a0000 pid=2799 memfd: zombie guuid=e3d13cbc-1a00-0000-d459-01a5d50a0000 pid=2773->guuid=d19653c7-1a00-0000-d459-01a5ef0a0000 pid=2799 clone guuid=fd2b60c7-1a00-0000-d459-01a5f10a0000 pid=2801 memfd: guuid=d19653c7-1a00-0000-d459-01a5ef0a0000 pid=2799->guuid=fd2b60c7-1a00-0000-d459-01a5f10a0000 pid=2801 clone guuid=89325dc7-1a00-0000-d459-01a5f00a0000 pid=2800->bbf5bc96-9f47-54ce-aa51-70672524d0f0 send: 150B guuid=76796ec7-1a00-0000-d459-01a5f20a0000 pid=2802 memfd: dns net send-data write-file guuid=fd2b60c7-1a00-0000-d459-01a5f10a0000 pid=2801->guuid=76796ec7-1a00-0000-d459-01a5f20a0000 pid=2802 clone 80639f7d-8d8e-5d60-8819-65337bb0e774 criminalcloudflare.online:1337 guuid=76796ec7-1a00-0000-d459-01a5f20a0000 pid=2802->80639f7d-8d8e-5d60-8819-65337bb0e774 send: 256B a0528efd-1018-56b4-b518-221acb0fa7ca 9.9.9.9:53 guuid=76796ec7-1a00-0000-d459-01a5f20a0000 pid=2802->a0528efd-1018-56b4-b518-221acb0fa7ca send: 43B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=76796ec7-1a00-0000-d459-01a5f20a0000 pid=2802->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 43B guuid=76796ec7-1a00-0000-d459-01a5f20a0000 pid=2803 memfd: guuid=76796ec7-1a00-0000-d459-01a5f20a0000 pid=2802->guuid=76796ec7-1a00-0000-d459-01a5f20a0000 pid=2803 clone guuid=76796ec7-1a00-0000-d459-01a5f20a0000 pid=2804 memfd: guuid=76796ec7-1a00-0000-d459-01a5f20a0000 pid=2802->guuid=76796ec7-1a00-0000-d459-01a5f20a0000 pid=2804 clone guuid=76796ec7-1a00-0000-d459-01a5f20a0000 pid=2813 memfd: guuid=76796ec7-1a00-0000-d459-01a5f20a0000 pid=2802->guuid=76796ec7-1a00-0000-d459-01a5f20a0000 pid=2813 clone guuid=ba7456c4-2100-0000-d459-01a5c7140000 pid=5319 memfd: guuid=76796ec7-1a00-0000-d459-01a5f20a0000 pid=2803->guuid=ba7456c4-2100-0000-d459-01a5c7140000 pid=5319 clone
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script.Trojan.Heuristic
Status:
Malicious
First seen:
2026-05-23 00:47:03 UTC
File Type:
Text
AV detection:
12 of 36 (33.33%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh f0f33fed457fb3547e9a2f2a913a611299c5efa7efbba696d9bd00a01bcb1084

(this sample)

  
Delivery method
Distributed via web download

Comments