MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f2e2ffc024ab99eb49fa207756481aa80713398142f30888aebace5706909b36. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA 1 File information Comments

SHA256 hash: f2e2ffc024ab99eb49fa207756481aa80713398142f30888aebace5706909b36
SHA3-384 hash: 887926bf4871f8a85b7d70895368088a0e490045cda9fc9c8ff1c5c467f391e137003dfc64873e19af8a6f0e5dc226dd
SHA1 hash: 40e2278c49d112b0037d97f8819bc49e91898901
MD5 hash: e47fdbb60152c2dc8d364d6dfb8df4fc
humanhash: spring-fix-nitrogen-queen
File name:twget.sh
Download: download sample
File size:697 bytes
First seen:2026-08-07 20:40:48 UTC
Last seen:2026-08-08 19:23:24 UTC
File type: sh
MIME type:text/plain
ssdeep 12:my+KWK4GqYEeREe5vEebmEevEeRI3vEeL:mjbHiE8EOE6mE6E4I3vEk
TLSH T1500167CC41611971CC82CDEAB663DD7554C4EDC42BD14E5CAECC24B1908CDD5F961F98
Magika batch
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://2.26.136.128/lul.mipsn/an/aelf mips ua-wget
http://2.26.136.128/lul.mpsl1bcc7b001a6f2aa432fe718147fdf91c3d8a59662ca7fc7bf0cbca5e98ab014d Miraielf mips ua-wget
http://2.26.136.128/lul.armf70cbd866b3f1482610603ed98948f76215012abd559f9e857c321305ff46f66 Mirai2-26-136-128 elf mirai
http://2.26.136.128/lul.arm5af523b32e0c961edf7b21d921ca2842c6376e5e82ebc950ebd47c9bdf3c763e8 Mirai2-26-136-128 elf mirai
http://2.26.136.128/lul.arm6e7a04b15aaf8b43f5bfd55fc8befac199b0b43db1befdd420f732eaff6f5923a Miraiarm elf mirai ua-wget
http://2.26.136.128/lul.arm7827aa0a0191b7820d50c6c6c69d0e57ae95d5902d7b800b295ac52c5a1501bc4 Mirai2-26-136-128 elf

Intelligence


File Origin
# of uploads :
3
# of downloads :
55
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox
Status:
terminated
Behavior Graph:
%3 guuid=0072ebbc-1a00-0000-800f-73c93f0c0000 pid=3135 /usr/bin/sudo guuid=a5ded9c1-1a00-0000-800f-73c9400c0000 pid=3136 /tmp/sample.bin guuid=0072ebbc-1a00-0000-800f-73c93f0c0000 pid=3135->guuid=a5ded9c1-1a00-0000-800f-73c9400c0000 pid=3136 execve guuid=9b08ffc2-1a00-0000-800f-73c9410c0000 pid=3137 /usr/bin/busybox net send-data write-file guuid=a5ded9c1-1a00-0000-800f-73c9400c0000 pid=3136->guuid=9b08ffc2-1a00-0000-800f-73c9410c0000 pid=3137 execve guuid=5123cccc-1a00-0000-800f-73c9500c0000 pid=3152 /usr/bin/chmod guuid=a5ded9c1-1a00-0000-800f-73c9400c0000 pid=3136->guuid=5123cccc-1a00-0000-800f-73c9500c0000 pid=3152 execve guuid=fcbf09cd-1a00-0000-800f-73c9510c0000 pid=3153 /usr/bin/dash guuid=a5ded9c1-1a00-0000-800f-73c9400c0000 pid=3136->guuid=fcbf09cd-1a00-0000-800f-73c9510c0000 pid=3153 clone guuid=516089ce-1a00-0000-800f-73c9540c0000 pid=3156 /usr/bin/busybox net send-data write-file guuid=a5ded9c1-1a00-0000-800f-73c9400c0000 pid=3136->guuid=516089ce-1a00-0000-800f-73c9540c0000 pid=3156 execve guuid=7c3ec4d8-1a00-0000-800f-73c96a0c0000 pid=3178 /usr/bin/chmod guuid=a5ded9c1-1a00-0000-800f-73c9400c0000 pid=3136->guuid=7c3ec4d8-1a00-0000-800f-73c96a0c0000 pid=3178 execve guuid=96c10fd9-1a00-0000-800f-73c96b0c0000 pid=3179 /usr/bin/dash guuid=a5ded9c1-1a00-0000-800f-73c9400c0000 pid=3136->guuid=96c10fd9-1a00-0000-800f-73c96b0c0000 pid=3179 clone guuid=21a278da-1a00-0000-800f-73c9700c0000 pid=3184 /usr/bin/busybox net send-data write-file guuid=a5ded9c1-1a00-0000-800f-73c9400c0000 pid=3136->guuid=21a278da-1a00-0000-800f-73c9700c0000 pid=3184 execve guuid=abfa3ae3-1a00-0000-800f-73c97d0c0000 pid=3197 /usr/bin/chmod guuid=a5ded9c1-1a00-0000-800f-73c9400c0000 pid=3136->guuid=abfa3ae3-1a00-0000-800f-73c97d0c0000 pid=3197 execve guuid=5dc77de3-1a00-0000-800f-73c97e0c0000 pid=3198 /usr/bin/dash guuid=a5ded9c1-1a00-0000-800f-73c9400c0000 pid=3136->guuid=5dc77de3-1a00-0000-800f-73c97e0c0000 pid=3198 clone guuid=065a20e4-1a00-0000-800f-73c9810c0000 pid=3201 /usr/bin/busybox net send-data write-file guuid=a5ded9c1-1a00-0000-800f-73c9400c0000 pid=3136->guuid=065a20e4-1a00-0000-800f-73c9810c0000 pid=3201 execve guuid=8326b7ec-1a00-0000-800f-73c98f0c0000 pid=3215 /usr/bin/chmod guuid=a5ded9c1-1a00-0000-800f-73c9400c0000 pid=3136->guuid=8326b7ec-1a00-0000-800f-73c98f0c0000 pid=3215 execve guuid=b79e1aed-1a00-0000-800f-73c9900c0000 pid=3216 /usr/bin/dash guuid=a5ded9c1-1a00-0000-800f-73c9400c0000 pid=3136->guuid=b79e1aed-1a00-0000-800f-73c9900c0000 pid=3216 clone guuid=5e6492ee-1a00-0000-800f-73c9960c0000 pid=3222 /usr/bin/busybox net send-data write-file guuid=a5ded9c1-1a00-0000-800f-73c9400c0000 pid=3136->guuid=5e6492ee-1a00-0000-800f-73c9960c0000 pid=3222 execve guuid=050585f7-1a00-0000-800f-73c9990c0000 pid=3225 /usr/bin/chmod guuid=a5ded9c1-1a00-0000-800f-73c9400c0000 pid=3136->guuid=050585f7-1a00-0000-800f-73c9990c0000 pid=3225 execve guuid=e96804f8-1a00-0000-800f-73c99a0c0000 pid=3226 /usr/bin/dash guuid=a5ded9c1-1a00-0000-800f-73c9400c0000 pid=3136->guuid=e96804f8-1a00-0000-800f-73c99a0c0000 pid=3226 clone guuid=a9185cf9-1a00-0000-800f-73c99c0c0000 pid=3228 /usr/bin/busybox net send-data write-file guuid=a5ded9c1-1a00-0000-800f-73c9400c0000 pid=3136->guuid=a9185cf9-1a00-0000-800f-73c99c0c0000 pid=3228 execve guuid=9d1cc701-1b00-0000-800f-73c9aa0c0000 pid=3242 /usr/bin/chmod guuid=a5ded9c1-1a00-0000-800f-73c9400c0000 pid=3136->guuid=9d1cc701-1b00-0000-800f-73c9aa0c0000 pid=3242 execve guuid=1f050402-1b00-0000-800f-73c9ac0c0000 pid=3244 /usr/bin/dash guuid=a5ded9c1-1a00-0000-800f-73c9400c0000 pid=3136->guuid=1f050402-1b00-0000-800f-73c9ac0c0000 pid=3244 clone a80e0999-ea5c-5189-8a9c-c0fa305b83d4 2.26.136.128:80 guuid=9b08ffc2-1a00-0000-800f-73c9410c0000 pid=3137->a80e0999-ea5c-5189-8a9c-c0fa305b83d4 send: 83B guuid=516089ce-1a00-0000-800f-73c9540c0000 pid=3156->a80e0999-ea5c-5189-8a9c-c0fa305b83d4 send: 83B guuid=21a278da-1a00-0000-800f-73c9700c0000 pid=3184->a80e0999-ea5c-5189-8a9c-c0fa305b83d4 send: 82B guuid=065a20e4-1a00-0000-800f-73c9810c0000 pid=3201->a80e0999-ea5c-5189-8a9c-c0fa305b83d4 send: 83B guuid=5e6492ee-1a00-0000-800f-73c9960c0000 pid=3222->a80e0999-ea5c-5189-8a9c-c0fa305b83d4 send: 83B guuid=a9185cf9-1a00-0000-800f-73c99c0c0000 pid=3228->a80e0999-ea5c-5189-8a9c-c0fa305b83d4 send: 83B
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh f2e2ffc024ab99eb49fa207756481aa80713398142f30888aebace5706909b36

(this sample)

  
Delivery method
Distributed via web download

Comments