🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f79f81089f28cb3cf9c9508295d4c5ee7261e6b337286fc25e5af20a078ed0aa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: f79f81089f28cb3cf9c9508295d4c5ee7261e6b337286fc25e5af20a078ed0aa
SHA3-384 hash: 192c9f986815939719a5bc6b75a617944adf57257b5e2c56fafe12865ff034fcc7a7a450a273c832b1436728bced8496
SHA1 hash: feb007bf1dc16be9579508119a9edbb6347d578a
MD5 hash: 58181e8b583ecf2fdf5af206b28f5982
humanhash: october-mexico-white-avocado
File name:f79f81089f28cb3cf9c9508295d4c5ee7261e6b337286fc25e5af20a078ed0aa
Download: download sample
File size:1'431 bytes
First seen:2026-10-03 09:23:36 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:VmEiwaUS5rRLhK9n0ZLsKBu/iswrTWyvCD+LZFm6JZ7+9pQOJr0gtR:VDNaUS5rRLhuneLsSuKswrbMOXm6JZ7M
TLSH T183217B2B36A234B2A35E08AE477E21165497012B04347E98B2EE17356FBDA367C79B11
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter spydisec
Tags:cowrie dropper honeypot sh


Avatar
spydisec
Captured by an SSH/Telnet honeypot (cowrie). Downloaded from http://2.27.248.149/lotus.sh; attacker IP(s): 82.25.63.191; first seen 2026-10-03T09:05:37Z.

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
Vendor Threat Intelligence
No detections
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-09-24T18:26:00Z UTC
Last seen:
2026-09-30T12:39:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=0851df64-1900-0000-65da-06ca2d0a0000 pid=2605 /usr/bin/sudo guuid=2df4c067-1900-0000-65da-06ca330a0000 pid=2611 /tmp/sample.bin guuid=0851df64-1900-0000-65da-06ca2d0a0000 pid=2605->guuid=2df4c067-1900-0000-65da-06ca330a0000 pid=2611 execve guuid=64af0568-1900-0000-65da-06ca350a0000 pid=2613 /usr/bin/uname guuid=2df4c067-1900-0000-65da-06ca330a0000 pid=2611->guuid=64af0568-1900-0000-65da-06ca350a0000 pid=2613 execve guuid=94938168-1900-0000-65da-06ca380a0000 pid=2616 /usr/bin/wget net send-data write-file guuid=2df4c067-1900-0000-65da-06ca330a0000 pid=2611->guuid=94938168-1900-0000-65da-06ca380a0000 pid=2616 execve guuid=055725c0-1900-0000-65da-06cae80a0000 pid=2792 /usr/bin/chmod guuid=2df4c067-1900-0000-65da-06ca330a0000 pid=2611->guuid=055725c0-1900-0000-65da-06cae80a0000 pid=2792 execve guuid=79f86cc0-1900-0000-65da-06caea0a0000 pid=2794 /tmp/.lotus mprotect-exec zombie guuid=2df4c067-1900-0000-65da-06ca330a0000 pid=2611->guuid=79f86cc0-1900-0000-65da-06caea0a0000 pid=2794 execve guuid=26ee70c0-1900-0000-65da-06caeb0a0000 pid=2795 /usr/bin/rm delete-file guuid=2df4c067-1900-0000-65da-06ca330a0000 pid=2611->guuid=26ee70c0-1900-0000-65da-06caeb0a0000 pid=2795 execve ff376e05-9b1a-5a8a-aee2-d5d387287679 2.27.248.149:80 guuid=94938168-1900-0000-65da-06ca380a0000 pid=2616->ff376e05-9b1a-5a8a-aee2-d5d387287679 send: 138B guuid=07bbd9c1-1900-0000-65da-06caed0a0000 pid=2797 /tmp/.lotus zombie guuid=79f86cc0-1900-0000-65da-06caea0a0000 pid=2794->guuid=07bbd9c1-1900-0000-65da-06caed0a0000 pid=2797 clone guuid=625aecc1-1900-0000-65da-06caef0a0000 pid=2799 /tmp/.lotus net send-data zombie guuid=07bbd9c1-1900-0000-65da-06caed0a0000 pid=2797->guuid=625aecc1-1900-0000-65da-06caef0a0000 pid=2799 clone 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=625aecc1-1900-0000-65da-06caef0a0000 pid=2799->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con ce90c105-84ee-5300-a313-29389217557b 2.27.248.149:11121 guuid=625aecc1-1900-0000-65da-06caef0a0000 pid=2799->ce90c105-84ee-5300-a313-29389217557b send: 10B guuid=7a7211ca-1900-0000-65da-06cafa0a0000 pid=2810 /tmp/.lotus guuid=625aecc1-1900-0000-65da-06caef0a0000 pid=2799->guuid=7a7211ca-1900-0000-65da-06cafa0a0000 pid=2810 clone
Threat name:
Script-BAT.Trojan.Heuristic
Status:
Malicious
First seen:
2026-09-25 05:47:00 UTC
File Type:
Text (Shell)
AV detection:
8 of 23 (34.78%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
UPX packed file
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh f79f81089f28cb3cf9c9508295d4c5ee7261e6b337286fc25e5af20a078ed0aa

(this sample)

  
Delivery method
Distributed via web download

Comments