🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f9daa6bd950dc24556dbb0d9854ad46aa1bb3f0926ef80b4f90fa36f1eb095ca. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: f9daa6bd950dc24556dbb0d9854ad46aa1bb3f0926ef80b4f90fa36f1eb095ca
SHA3-384 hash: 5ca835bc1ca68c0d99145f4ea87dc8425849b230b428cf039a7c66f0b5da383737e92d227d46d53a30bc36551831ba0e
SHA1 hash: a312e5c362eb5e2b4a3a6493d737b6c0b475af9e
MD5 hash: 09d0cfb9a01194421d67ec9e0eb128b0
humanhash: coffee-muppet-speaker-snake
File name:massload
Download: download sample
File size:331 bytes
First seen:2026-09-18 08:38:02 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 6:L6FTWXph11anGKbV6FnGjph1btFa626V6FTWXph12NbT2V6FnGjph1xNKIey:wuph80GjphLcN6auphc5T20GjphHNb
TLSH T102E048EE64163B06411AEE04607AC579B032EFDA65403F8CEEEC11A9C89C818B021EC9
Magika javascript
Reporter adliwahid
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://217.60.195.239/x863461b097ea026c9161113f0f590e75c47908cebd3d6a30de3b821c10a85ea9fc Mirai32-bit elf mirai x86-32
http://217.60.195.239/arm7n/an/an/a
http://217.60.195.239/mipsn/an/an/a
http://217.60.195.239/mpsln/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
33
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Status:
terminated
Behavior Graph:
%3 guuid=8fd9f6d5-1700-0000-dbe2-bb31ba0c0000 pid=3258 /usr/bin/sudo guuid=a1f337d8-1700-0000-dbe2-bb31c10c0000 pid=3265 /tmp/sample.bin guuid=8fd9f6d5-1700-0000-dbe2-bb31ba0c0000 pid=3258->guuid=a1f337d8-1700-0000-dbe2-bb31c10c0000 pid=3265 execve guuid=994093d8-1700-0000-dbe2-bb31c20c0000 pid=3266 /usr/bin/rm guuid=a1f337d8-1700-0000-dbe2-bb31c10c0000 pid=3265->guuid=994093d8-1700-0000-dbe2-bb31c20c0000 pid=3266 execve guuid=b4262ed9-1700-0000-dbe2-bb31c30c0000 pid=3267 /usr/bin/wget net send-data guuid=a1f337d8-1700-0000-dbe2-bb31c10c0000 pid=3265->guuid=b4262ed9-1700-0000-dbe2-bb31c30c0000 pid=3267 execve guuid=8adf88de-1700-0000-dbe2-bb31d00c0000 pid=3280 /usr/bin/chmod guuid=a1f337d8-1700-0000-dbe2-bb31c10c0000 pid=3265->guuid=8adf88de-1700-0000-dbe2-bb31d00c0000 pid=3280 execve guuid=40930ee0-1700-0000-dbe2-bb31d40c0000 pid=3284 /usr/bin/dash guuid=a1f337d8-1700-0000-dbe2-bb31c10c0000 pid=3265->guuid=40930ee0-1700-0000-dbe2-bb31d40c0000 pid=3284 clone guuid=e9a63be0-1700-0000-dbe2-bb31d60c0000 pid=3286 /usr/bin/rm guuid=a1f337d8-1700-0000-dbe2-bb31c10c0000 pid=3265->guuid=e9a63be0-1700-0000-dbe2-bb31d60c0000 pid=3286 execve guuid=9068d6e0-1700-0000-dbe2-bb31d80c0000 pid=3288 /usr/bin/wget net send-data guuid=a1f337d8-1700-0000-dbe2-bb31c10c0000 pid=3265->guuid=9068d6e0-1700-0000-dbe2-bb31d80c0000 pid=3288 execve guuid=bd4e95e5-1700-0000-dbe2-bb31e20c0000 pid=3298 /usr/bin/chmod guuid=a1f337d8-1700-0000-dbe2-bb31c10c0000 pid=3265->guuid=bd4e95e5-1700-0000-dbe2-bb31e20c0000 pid=3298 execve guuid=590501e6-1700-0000-dbe2-bb31e40c0000 pid=3300 /usr/bin/dash guuid=a1f337d8-1700-0000-dbe2-bb31c10c0000 pid=3265->guuid=590501e6-1700-0000-dbe2-bb31e40c0000 pid=3300 clone guuid=73b01ee6-1700-0000-dbe2-bb31e50c0000 pid=3301 /usr/bin/rm guuid=a1f337d8-1700-0000-dbe2-bb31c10c0000 pid=3265->guuid=73b01ee6-1700-0000-dbe2-bb31e50c0000 pid=3301 execve guuid=c4fa8ee6-1700-0000-dbe2-bb31e70c0000 pid=3303 /usr/bin/wget net send-data guuid=a1f337d8-1700-0000-dbe2-bb31c10c0000 pid=3265->guuid=c4fa8ee6-1700-0000-dbe2-bb31e70c0000 pid=3303 execve guuid=b093bfe9-1700-0000-dbe2-bb31ef0c0000 pid=3311 /usr/bin/chmod guuid=a1f337d8-1700-0000-dbe2-bb31c10c0000 pid=3265->guuid=b093bfe9-1700-0000-dbe2-bb31ef0c0000 pid=3311 execve guuid=bd2433ea-1700-0000-dbe2-bb31f10c0000 pid=3313 /usr/bin/dash guuid=a1f337d8-1700-0000-dbe2-bb31c10c0000 pid=3265->guuid=bd2433ea-1700-0000-dbe2-bb31f10c0000 pid=3313 clone guuid=402c4dea-1700-0000-dbe2-bb31f20c0000 pid=3314 /usr/bin/rm guuid=a1f337d8-1700-0000-dbe2-bb31c10c0000 pid=3265->guuid=402c4dea-1700-0000-dbe2-bb31f20c0000 pid=3314 execve guuid=d4b7c5ea-1700-0000-dbe2-bb31f40c0000 pid=3316 /usr/bin/wget net send-data guuid=a1f337d8-1700-0000-dbe2-bb31c10c0000 pid=3265->guuid=d4b7c5ea-1700-0000-dbe2-bb31f40c0000 pid=3316 execve guuid=e0898cef-1700-0000-dbe2-bb31050d0000 pid=3333 /usr/bin/chmod guuid=a1f337d8-1700-0000-dbe2-bb31c10c0000 pid=3265->guuid=e0898cef-1700-0000-dbe2-bb31050d0000 pid=3333 execve guuid=364ed0ef-1700-0000-dbe2-bb31060d0000 pid=3334 /usr/bin/dash guuid=a1f337d8-1700-0000-dbe2-bb31c10c0000 pid=3265->guuid=364ed0ef-1700-0000-dbe2-bb31060d0000 pid=3334 clone 994e7b7a-2a7d-5c31-b3a1-2f51d816fa00 217.60.195.239:80 guuid=b4262ed9-1700-0000-dbe2-bb31c30c0000 pid=3267->994e7b7a-2a7d-5c31-b3a1-2f51d816fa00 send: 132B guuid=9068d6e0-1700-0000-dbe2-bb31d80c0000 pid=3288->994e7b7a-2a7d-5c31-b3a1-2f51d816fa00 send: 133B guuid=c4fa8ee6-1700-0000-dbe2-bb31e70c0000 pid=3303->994e7b7a-2a7d-5c31-b3a1-2f51d816fa00 send: 133B guuid=d4b7c5ea-1700-0000-dbe2-bb31f40c0000 pid=3316->994e7b7a-2a7d-5c31-b3a1-2f51d816fa00 send: 133B
Threat name:
Document-HTML.Downloader.Heuristic
Status:
Malicious
First seen:
2026-09-18 09:10:16 UTC
File Type:
Text (Shell)
AV detection:
5 of 36 (13.89%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

sh f9daa6bd950dc24556dbb0d9854ad46aa1bb3f0926ef80b4f90fa36f1eb095ca

(this sample)

Comments