MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0782c2520a476fb98e6a0bd01937df57a0c730b113c8ec149e2c6be534aa91a3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: 0782c2520a476fb98e6a0bd01937df57a0c730b113c8ec149e2c6be534aa91a3
SHA3-384 hash: dd2387d597cfaa61a0652df911aae35885c35b047dcc6bb1948adf28bf06c6ff250eecbf9b7ed545e2e6e3d97082cd4d
SHA1 hash: 635997eee32bf2ffe4e25e53d206e9c540430b63
MD5 hash: 97d67632afe554ff42c5fdbb1c6de176
humanhash: missouri-network-sierra-mockingbird
File name:cache
Download: download sample
File size:4'050 bytes
First seen:2026-03-06 19:55:44 UTC
Last seen:2026-03-11 11:22:42 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:v8UrUQxlUoUOEUYUvUpUCUdUuUCU5UtUPn:v8UrUGUoUOEUYUvUpUCUdUuUCU5UtUPn
TLSH T18581CAC9715207E52F2CEA3267BFC50C5785D1CFE4C11F99FADA6AA44D8CDC82C841A2
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://180.93.52.81/m4ng0d33w1771nnmnlove/MMaaRRiiOisecTanee.x86f3a69f4e3698d502c517689116d8be4c0c08b7508d566488e17aa78dae8d0d09 Miraielf mirai ua-wget
http://180.93.52.81/m4ng0d33w1771nnmnlove/MMaaRRiiOisecTanee.mipsb0e72dd0fcbcda0198641b03148952710c8f6796dc1bb6a3b42ae6d46f1c0be1 Miraielf mirai ua-wget
http://180.93.52.81/m4ng0d33w1771nnmnlove/MMaaRRiiOisecTanee.mpsl7675c9f4af0c0f311a2427a0c1da3df9b861703478441943dea20498f2f38ce9 Miraielf mirai ua-wget
http://180.93.52.81/m4ng0d33w1771nnmnlove/MMaaRRiiOisecTanee.arm03bb7a58beb30b1b6af87beb2a3cdc136e0f5de706852ac97124926f5e0481c4 Miraielf mirai ua-wget
http://180.93.52.81/m4ng0d33w1771nnmnlove/MMaaRRiiOisecTanee.arm56a98058ab7df28cd4ea079b803987136048819ee1000a40a4b3aba8a7bfcbe26 Miraielf mirai ua-wget
http://180.93.52.81/m4ng0d33w1771nnmnlove/MMaaRRiiOisecTanee.arm69022e11457f3c00cea45af9f98fd33f7bad90c708e1d57b2e080a9e3d33f8a96 Miraielf mirai ua-wget
http://180.93.52.81/m4ng0d33w1771nnmnlove/MMaaRRiiOisecTanee.arm7e4cba3e8f78121f6fa1b5b4bcfd22e1197a82190af5faa46355cacbb9fb8f79d Miraielf mirai ua-wget
http://180.93.52.81/m4ng0d33w1771nnmnlove/MMaaRRiiOisecTanee.ppcdd0e62da03a0015aca6da4663f78fcc7a05bfcdf6f2153ca4c6fe71e5ca0dc23 Miraielf mirai ua-wget
http://180.93.52.81/m4ng0d33w1771nnmnlove/MMaaRRiiOisecTanee.m68kf95849221fd7eac9ec99afabc3e902d8a36f886a5d7a186cbc249a3f11be3bb9 Miraielf mirai ua-wget
http://180.93.52.81/m4ng0d33w1771nnmnlove/MMaaRRiiOisecTanee.sh413fef25ab468904a3ebcb98835e649d74a5939b170f16cc781db301474e70a7e Miraielf mirai ua-wget
http://180.93.52.81/m4ng0d33w1771nnmnlove/MMaaRRiiOisecTanee.spc91d5b890b235c66127222835d6da450cbab2566a6c932307457a94964f46e306 Miraielf mirai ua-wget
http://180.93.52.81/m4ng0d33w1771nnmnlove/MMaaRRiiOisecTanee.arcf99b73f2a0b2c92a645ca35f86f5c47abe394a55c5bc76078771394df47caedb Miraielf mirai ua-wget
http://180.93.52.81/m4ng0d33w1771nnmnlove/MMaaRRiiOisecTanee.x86_6498a0e5284dd13e2abe50ed156f756d2edc8d046e0d74673a87033587c19d6dbd Miraielf mirai ua-wget
http://180.93.52.81/m4ng0d33w1771nnmnlove/MMaaRRiiOisecTanee.i686c62d087263f99c28d641e6473f6ea525074ddf3c39c954b0d33be936f311101d Miraielf mirai ua-wget
http://180.93.52.81/m4ng0d33w1771nnmnlove/MMaaRRiiOisecTanee.i486c72d37ebb0026a56c683780460f0527c414704e46368e18648e3b27f13f87658 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
3
# of downloads :
84
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
medusa mirai
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=c5f92ae4-1600-0000-ff8d-c0938e0d0000 pid=3470 /usr/bin/sudo guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477 /tmp/sample.bin guuid=c5f92ae4-1600-0000-ff8d-c0938e0d0000 pid=3470->guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477 execve guuid=1cfb8de6-1600-0000-ff8d-c093970d0000 pid=3479 /usr/bin/wget net send-data guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=1cfb8de6-1600-0000-ff8d-c093970d0000 pid=3479 execve guuid=6182b804-1700-0000-ff8d-c093cb0d0000 pid=3531 /usr/bin/curl net send-data write-file guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=6182b804-1700-0000-ff8d-c093cb0d0000 pid=3531 execve guuid=55da5b25-1700-0000-ff8d-c0931f0e0000 pid=3615 /usr/bin/cat guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=55da5b25-1700-0000-ff8d-c0931f0e0000 pid=3615 execve guuid=dd1aa725-1700-0000-ff8d-c093200e0000 pid=3616 /usr/bin/chmod guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=dd1aa725-1700-0000-ff8d-c093200e0000 pid=3616 execve guuid=ebcbf325-1700-0000-ff8d-c093230e0000 pid=3619 /usr/bin/bash guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=ebcbf325-1700-0000-ff8d-c093230e0000 pid=3619 clone guuid=7dc13326-1700-0000-ff8d-c093270e0000 pid=3623 /usr/bin/wget net send-data guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=7dc13326-1700-0000-ff8d-c093270e0000 pid=3623 execve guuid=27b09d42-1700-0000-ff8d-c0936e0e0000 pid=3694 /usr/bin/curl net send-data write-file guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=27b09d42-1700-0000-ff8d-c0936e0e0000 pid=3694 execve guuid=61e02a62-1700-0000-ff8d-c093b80e0000 pid=3768 /usr/bin/cat guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=61e02a62-1700-0000-ff8d-c093b80e0000 pid=3768 execve guuid=82debe62-1700-0000-ff8d-c093ba0e0000 pid=3770 /usr/bin/chmod guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=82debe62-1700-0000-ff8d-c093ba0e0000 pid=3770 execve guuid=68dc4163-1700-0000-ff8d-c093bc0e0000 pid=3772 /usr/bin/bash guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=68dc4163-1700-0000-ff8d-c093bc0e0000 pid=3772 clone guuid=da97a263-1700-0000-ff8d-c093be0e0000 pid=3774 /usr/bin/wget net send-data guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=da97a263-1700-0000-ff8d-c093be0e0000 pid=3774 execve guuid=4462a480-1700-0000-ff8d-c093110f0000 pid=3857 /usr/bin/curl net send-data write-file guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=4462a480-1700-0000-ff8d-c093110f0000 pid=3857 execve guuid=cf6ebe9e-1700-0000-ff8d-c0937e0f0000 pid=3966 /usr/bin/cat guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=cf6ebe9e-1700-0000-ff8d-c0937e0f0000 pid=3966 execve guuid=158c509f-1700-0000-ff8d-c093820f0000 pid=3970 /usr/bin/chmod guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=158c509f-1700-0000-ff8d-c093820f0000 pid=3970 execve guuid=d14fd89f-1700-0000-ff8d-c093840f0000 pid=3972 /usr/bin/bash guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=d14fd89f-1700-0000-ff8d-c093840f0000 pid=3972 clone guuid=4b4e48a0-1700-0000-ff8d-c093880f0000 pid=3976 /usr/bin/wget net send-data guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=4b4e48a0-1700-0000-ff8d-c093880f0000 pid=3976 execve guuid=2fe4c9c8-1700-0000-ff8d-c093dd0f0000 pid=4061 /usr/bin/curl net send-data write-file guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=2fe4c9c8-1700-0000-ff8d-c093dd0f0000 pid=4061 execve guuid=e59b8ce6-1700-0000-ff8d-c09340100000 pid=4160 /usr/bin/cat guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=e59b8ce6-1700-0000-ff8d-c09340100000 pid=4160 execve guuid=8b6dffe6-1700-0000-ff8d-c09342100000 pid=4162 /usr/bin/chmod guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=8b6dffe6-1700-0000-ff8d-c09342100000 pid=4162 execve guuid=d9277de7-1700-0000-ff8d-c09345100000 pid=4165 /usr/bin/bash guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=d9277de7-1700-0000-ff8d-c09345100000 pid=4165 clone guuid=dc2efce7-1700-0000-ff8d-c09348100000 pid=4168 /usr/bin/wget net send-data guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=dc2efce7-1700-0000-ff8d-c09348100000 pid=4168 execve guuid=cd8a7c05-1800-0000-ff8d-c09393100000 pid=4243 /usr/bin/curl net send-data write-file guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=cd8a7c05-1800-0000-ff8d-c09393100000 pid=4243 execve guuid=dfe2812c-1800-0000-ff8d-c093f4100000 pid=4340 /usr/bin/cat guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=dfe2812c-1800-0000-ff8d-c093f4100000 pid=4340 execve guuid=18690b2d-1800-0000-ff8d-c093f6100000 pid=4342 /usr/bin/chmod guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=18690b2d-1800-0000-ff8d-c093f6100000 pid=4342 execve guuid=22b3902d-1800-0000-ff8d-c093f9100000 pid=4345 /usr/bin/bash guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=22b3902d-1800-0000-ff8d-c093f9100000 pid=4345 clone guuid=a6bffd2d-1800-0000-ff8d-c093fb100000 pid=4347 /usr/bin/wget net send-data guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=a6bffd2d-1800-0000-ff8d-c093fb100000 pid=4347 execve guuid=2bcc9d4a-1800-0000-ff8d-c09340110000 pid=4416 /usr/bin/curl net send-data write-file guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=2bcc9d4a-1800-0000-ff8d-c09340110000 pid=4416 execve guuid=2fdb3577-1800-0000-ff8d-c093a8110000 pid=4520 /usr/bin/cat guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=2fdb3577-1800-0000-ff8d-c093a8110000 pid=4520 execve guuid=b3f0a477-1800-0000-ff8d-c093a9110000 pid=4521 /usr/bin/chmod guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=b3f0a477-1800-0000-ff8d-c093a9110000 pid=4521 execve guuid=537afe77-1800-0000-ff8d-c093ab110000 pid=4523 /usr/bin/bash guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=537afe77-1800-0000-ff8d-c093ab110000 pid=4523 clone guuid=45e16678-1800-0000-ff8d-c093ad110000 pid=4525 /usr/bin/wget net send-data guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=45e16678-1800-0000-ff8d-c093ad110000 pid=4525 execve guuid=b8e90196-1800-0000-ff8d-c093f4110000 pid=4596 /usr/bin/curl net send-data write-file guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=b8e90196-1800-0000-ff8d-c093f4110000 pid=4596 execve guuid=283943b7-1800-0000-ff8d-c0933c120000 pid=4668 /usr/bin/cat guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=283943b7-1800-0000-ff8d-c0933c120000 pid=4668 execve guuid=dd11ddb7-1800-0000-ff8d-c0933f120000 pid=4671 /usr/bin/chmod guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=dd11ddb7-1800-0000-ff8d-c0933f120000 pid=4671 execve guuid=a997b3b8-1800-0000-ff8d-c09342120000 pid=4674 /usr/bin/bash guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=a997b3b8-1800-0000-ff8d-c09342120000 pid=4674 clone guuid=c51a2fb9-1800-0000-ff8d-c09345120000 pid=4677 /usr/bin/wget net send-data guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=c51a2fb9-1800-0000-ff8d-c09345120000 pid=4677 execve guuid=e26371d7-1800-0000-ff8d-c09399120000 pid=4761 /usr/bin/curl net send-data write-file guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=e26371d7-1800-0000-ff8d-c09399120000 pid=4761 execve guuid=5991d0f8-1800-0000-ff8d-c093f7120000 pid=4855 /usr/bin/cat guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=5991d0f8-1800-0000-ff8d-c093f7120000 pid=4855 execve guuid=e67b21f9-1800-0000-ff8d-c093fa120000 pid=4858 /usr/bin/chmod guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=e67b21f9-1800-0000-ff8d-c093fa120000 pid=4858 execve guuid=550f69f9-1800-0000-ff8d-c093fc120000 pid=4860 /usr/bin/bash guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=550f69f9-1800-0000-ff8d-c093fc120000 pid=4860 clone guuid=fbf9d4f9-1800-0000-ff8d-c093ff120000 pid=4863 /usr/bin/wget net send-data guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=fbf9d4f9-1800-0000-ff8d-c093ff120000 pid=4863 execve guuid=5a5b3016-1900-0000-ff8d-c09351130000 pid=4945 /usr/bin/curl net send-data write-file guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=5a5b3016-1900-0000-ff8d-c09351130000 pid=4945 execve guuid=44e1c734-1900-0000-ff8d-c09393130000 pid=5011 /usr/bin/cat guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=44e1c734-1900-0000-ff8d-c09393130000 pid=5011 execve guuid=fd7a6335-1900-0000-ff8d-c09395130000 pid=5013 /usr/bin/chmod guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=fd7a6335-1900-0000-ff8d-c09395130000 pid=5013 execve guuid=a597f635-1900-0000-ff8d-c09397130000 pid=5015 /usr/bin/bash guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=a597f635-1900-0000-ff8d-c09397130000 pid=5015 clone guuid=4a336b36-1900-0000-ff8d-c0939a130000 pid=5018 /usr/bin/wget net send-data guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=4a336b36-1900-0000-ff8d-c0939a130000 pid=5018 execve guuid=a2ba9c53-1900-0000-ff8d-c093d7130000 pid=5079 /usr/bin/curl net send-data write-file guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=a2ba9c53-1900-0000-ff8d-c093d7130000 pid=5079 execve guuid=1fa48e74-1900-0000-ff8d-c0932a140000 pid=5162 /usr/bin/cat guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=1fa48e74-1900-0000-ff8d-c0932a140000 pid=5162 execve guuid=d4eadd74-1900-0000-ff8d-c0932c140000 pid=5164 /usr/bin/chmod guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=d4eadd74-1900-0000-ff8d-c0932c140000 pid=5164 execve guuid=55981e75-1900-0000-ff8d-c0932e140000 pid=5166 /usr/bin/bash guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=55981e75-1900-0000-ff8d-c0932e140000 pid=5166 clone guuid=b060bf75-1900-0000-ff8d-c09331140000 pid=5169 /usr/bin/wget net send-data guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=b060bf75-1900-0000-ff8d-c09331140000 pid=5169 execve guuid=44e4cf93-1900-0000-ff8d-c09399140000 pid=5273 /usr/bin/curl net send-data write-file guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=44e4cf93-1900-0000-ff8d-c09399140000 pid=5273 execve guuid=b208e1b1-1900-0000-ff8d-c0939e140000 pid=5278 /usr/bin/cat guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=b208e1b1-1900-0000-ff8d-c0939e140000 pid=5278 execve guuid=667531b2-1900-0000-ff8d-c0939f140000 pid=5279 /usr/bin/chmod guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=667531b2-1900-0000-ff8d-c0939f140000 pid=5279 execve guuid=049f7ab2-1900-0000-ff8d-c093a0140000 pid=5280 /usr/bin/bash guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=049f7ab2-1900-0000-ff8d-c093a0140000 pid=5280 clone guuid=5d7fdeb2-1900-0000-ff8d-c093a2140000 pid=5282 /usr/bin/wget net send-data guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=5d7fdeb2-1900-0000-ff8d-c093a2140000 pid=5282 execve guuid=c3b75dda-1900-0000-ff8d-c093ab140000 pid=5291 /usr/bin/curl net send-data write-file guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=c3b75dda-1900-0000-ff8d-c093ab140000 pid=5291 execve guuid=d3cd2dfd-1900-0000-ff8d-c093ac140000 pid=5292 /usr/bin/cat guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=d3cd2dfd-1900-0000-ff8d-c093ac140000 pid=5292 execve guuid=bfa786fd-1900-0000-ff8d-c093ad140000 pid=5293 /usr/bin/chmod guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=bfa786fd-1900-0000-ff8d-c093ad140000 pid=5293 execve guuid=48f0d5fd-1900-0000-ff8d-c093ae140000 pid=5294 /usr/bin/bash guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=48f0d5fd-1900-0000-ff8d-c093ae140000 pid=5294 clone guuid=b4d12cfe-1900-0000-ff8d-c093b0140000 pid=5296 /usr/bin/wget net send-data guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=b4d12cfe-1900-0000-ff8d-c093b0140000 pid=5296 execve guuid=80b3a91b-1a00-0000-ff8d-c093b1140000 pid=5297 /usr/bin/curl net send-data write-file guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=80b3a91b-1a00-0000-ff8d-c093b1140000 pid=5297 execve guuid=b3201b41-1a00-0000-ff8d-c093b2140000 pid=5298 /usr/bin/cat guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=b3201b41-1a00-0000-ff8d-c093b2140000 pid=5298 execve guuid=0e207141-1a00-0000-ff8d-c093b3140000 pid=5299 /usr/bin/chmod guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=0e207141-1a00-0000-ff8d-c093b3140000 pid=5299 execve guuid=668ec341-1a00-0000-ff8d-c093b4140000 pid=5300 /usr/bin/bash guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=668ec341-1a00-0000-ff8d-c093b4140000 pid=5300 clone guuid=9bac0b42-1a00-0000-ff8d-c093b6140000 pid=5302 /usr/bin/wget net send-data guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=9bac0b42-1a00-0000-ff8d-c093b6140000 pid=5302 execve guuid=ffb9ef64-1a00-0000-ff8d-c093b7140000 pid=5303 /usr/bin/curl net send-data write-file guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=ffb9ef64-1a00-0000-ff8d-c093b7140000 pid=5303 execve guuid=6caa3e84-1a00-0000-ff8d-c093bf140000 pid=5311 /usr/bin/cat guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=6caa3e84-1a00-0000-ff8d-c093bf140000 pid=5311 execve guuid=d1869085-1a00-0000-ff8d-c093c0140000 pid=5312 /usr/bin/chmod guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=d1869085-1a00-0000-ff8d-c093c0140000 pid=5312 execve guuid=1f57b986-1a00-0000-ff8d-c093c1140000 pid=5313 /usr/bin/bash guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=1f57b986-1a00-0000-ff8d-c093c1140000 pid=5313 clone guuid=dda96887-1a00-0000-ff8d-c093c3140000 pid=5315 /usr/bin/wget net send-data guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=dda96887-1a00-0000-ff8d-c093c3140000 pid=5315 execve guuid=efb22ba5-1a00-0000-ff8d-c093c4140000 pid=5316 /usr/bin/curl net send-data write-file guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=efb22ba5-1a00-0000-ff8d-c093c4140000 pid=5316 execve guuid=668ea8c4-1a00-0000-ff8d-c093c5140000 pid=5317 /usr/bin/cat guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=668ea8c4-1a00-0000-ff8d-c093c5140000 pid=5317 execve guuid=3c7034c5-1a00-0000-ff8d-c093c6140000 pid=5318 /usr/bin/chmod guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=3c7034c5-1a00-0000-ff8d-c093c6140000 pid=5318 execve guuid=f735bcc5-1a00-0000-ff8d-c093c7140000 pid=5319 /usr/bin/bash guuid=083b33e6-1600-0000-ff8d-c093950d0000 pid=3477->guuid=f735bcc5-1a00-0000-ff8d-c093c7140000 pid=5319 clone 2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 180.93.52.81:80 guuid=1cfb8de6-1600-0000-ff8d-c093970d0000 pid=3479->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 171B guuid=6182b804-1700-0000-ff8d-c093cb0d0000 pid=3531->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 120B guuid=fee80b26-1700-0000-ff8d-c093250e0000 pid=3621 /usr/bin/bash guuid=ebcbf325-1700-0000-ff8d-c093230e0000 pid=3619->guuid=fee80b26-1700-0000-ff8d-c093250e0000 pid=3621 clone guuid=7dc13326-1700-0000-ff8d-c093270e0000 pid=3623->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 172B guuid=27b09d42-1700-0000-ff8d-c0936e0e0000 pid=3694->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 121B guuid=50876763-1700-0000-ff8d-c093bd0e0000 pid=3773 /usr/bin/bash guuid=68dc4163-1700-0000-ff8d-c093bc0e0000 pid=3772->guuid=50876763-1700-0000-ff8d-c093bd0e0000 pid=3773 clone guuid=da97a263-1700-0000-ff8d-c093be0e0000 pid=3774->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 172B guuid=4462a480-1700-0000-ff8d-c093110f0000 pid=3857->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 121B guuid=d091fe9f-1700-0000-ff8d-c093870f0000 pid=3975 /usr/bin/bash guuid=d14fd89f-1700-0000-ff8d-c093840f0000 pid=3972->guuid=d091fe9f-1700-0000-ff8d-c093870f0000 pid=3975 clone guuid=4b4e48a0-1700-0000-ff8d-c093880f0000 pid=3976->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 171B guuid=2fe4c9c8-1700-0000-ff8d-c093dd0f0000 pid=4061->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 120B guuid=5ff99ee7-1700-0000-ff8d-c09347100000 pid=4167 /usr/bin/bash guuid=d9277de7-1700-0000-ff8d-c09345100000 pid=4165->guuid=5ff99ee7-1700-0000-ff8d-c09347100000 pid=4167 clone guuid=dc2efce7-1700-0000-ff8d-c09348100000 pid=4168->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 172B guuid=cd8a7c05-1800-0000-ff8d-c09393100000 pid=4243->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 121B guuid=37c5be2d-1800-0000-ff8d-c093fa100000 pid=4346 /usr/bin/bash guuid=22b3902d-1800-0000-ff8d-c093f9100000 pid=4345->guuid=37c5be2d-1800-0000-ff8d-c093fa100000 pid=4346 clone guuid=a6bffd2d-1800-0000-ff8d-c093fb100000 pid=4347->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 172B guuid=2bcc9d4a-1800-0000-ff8d-c09340110000 pid=4416->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 121B guuid=80751a78-1800-0000-ff8d-c093ac110000 pid=4524 /usr/bin/bash guuid=537afe77-1800-0000-ff8d-c093ab110000 pid=4523->guuid=80751a78-1800-0000-ff8d-c093ac110000 pid=4524 clone guuid=45e16678-1800-0000-ff8d-c093ad110000 pid=4525->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 172B guuid=b8e90196-1800-0000-ff8d-c093f4110000 pid=4596->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 121B guuid=7941e1b8-1800-0000-ff8d-c09343120000 pid=4675 /usr/bin/bash guuid=a997b3b8-1800-0000-ff8d-c09342120000 pid=4674->guuid=7941e1b8-1800-0000-ff8d-c09343120000 pid=4675 clone guuid=c51a2fb9-1800-0000-ff8d-c09345120000 pid=4677->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 171B guuid=e26371d7-1800-0000-ff8d-c09399120000 pid=4761->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 120B guuid=20ce88f9-1800-0000-ff8d-c093fd120000 pid=4861 /usr/bin/bash guuid=550f69f9-1800-0000-ff8d-c093fc120000 pid=4860->guuid=20ce88f9-1800-0000-ff8d-c093fd120000 pid=4861 clone guuid=fbf9d4f9-1800-0000-ff8d-c093ff120000 pid=4863->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 172B guuid=5a5b3016-1900-0000-ff8d-c09351130000 pid=4945->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 121B guuid=efa42e36-1900-0000-ff8d-c09398130000 pid=5016 /usr/bin/bash guuid=a597f635-1900-0000-ff8d-c09397130000 pid=5015->guuid=efa42e36-1900-0000-ff8d-c09398130000 pid=5016 clone guuid=4a336b36-1900-0000-ff8d-c0939a130000 pid=5018->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 171B guuid=a2ba9c53-1900-0000-ff8d-c093d7130000 pid=5079->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 120B guuid=16337f75-1900-0000-ff8d-c09330140000 pid=5168 /usr/bin/bash guuid=55981e75-1900-0000-ff8d-c0932e140000 pid=5166->guuid=16337f75-1900-0000-ff8d-c09330140000 pid=5168 clone guuid=b060bf75-1900-0000-ff8d-c09331140000 pid=5169->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 171B guuid=44e4cf93-1900-0000-ff8d-c09399140000 pid=5273->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 120B guuid=e6a699b2-1900-0000-ff8d-c093a1140000 pid=5281 /usr/bin/bash guuid=049f7ab2-1900-0000-ff8d-c093a0140000 pid=5280->guuid=e6a699b2-1900-0000-ff8d-c093a1140000 pid=5281 clone guuid=5d7fdeb2-1900-0000-ff8d-c093a2140000 pid=5282->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 171B guuid=c3b75dda-1900-0000-ff8d-c093ab140000 pid=5291->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 120B guuid=6029effd-1900-0000-ff8d-c093af140000 pid=5295 /usr/bin/bash guuid=48f0d5fd-1900-0000-ff8d-c093ae140000 pid=5294->guuid=6029effd-1900-0000-ff8d-c093af140000 pid=5295 clone guuid=b4d12cfe-1900-0000-ff8d-c093b0140000 pid=5296->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 174B guuid=80b3a91b-1a00-0000-ff8d-c093b1140000 pid=5297->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 123B guuid=dc0cdb41-1a00-0000-ff8d-c093b5140000 pid=5301 /usr/bin/bash guuid=668ec341-1a00-0000-ff8d-c093b4140000 pid=5300->guuid=dc0cdb41-1a00-0000-ff8d-c093b5140000 pid=5301 clone guuid=9bac0b42-1a00-0000-ff8d-c093b6140000 pid=5302->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 172B guuid=ffb9ef64-1a00-0000-ff8d-c093b7140000 pid=5303->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 121B guuid=29a80c87-1a00-0000-ff8d-c093c2140000 pid=5314 /usr/bin/bash guuid=1f57b986-1a00-0000-ff8d-c093c1140000 pid=5313->guuid=29a80c87-1a00-0000-ff8d-c093c2140000 pid=5314 clone guuid=dda96887-1a00-0000-ff8d-c093c3140000 pid=5315->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 172B guuid=efb22ba5-1a00-0000-ff8d-c093c4140000 pid=5316->2e0e310a-0ce5-5fd3-aba6-01a2c70d1198 send: 121B guuid=0a35e9c5-1a00-0000-ff8d-c093c8140000 pid=5320 /usr/bin/bash guuid=f735bcc5-1a00-0000-ff8d-c093c7140000 pid=5319->guuid=0a35e9c5-1a00-0000-ff8d-c093c8140000 pid=5320 clone
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-03-06 19:56:16 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 0782c2520a476fb98e6a0bd01937df57a0c730b113c8ec149e2c6be534aa91a3

(this sample)

  
Delivery method
Distributed via web download

Comments