MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 08fe41363db1d915cc9b0d0c1cb821ccf67f4c54fa75bb0bb0d79b2f310d1636. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 08fe41363db1d915cc9b0d0c1cb821ccf67f4c54fa75bb0bb0d79b2f310d1636
SHA3-384 hash: 5d3cee07971780c8cbac70a2d1293de8e9644f0ee1492dd9a60d8d7522c2857656582ac75224ff9ba638e6c5190a2488
SHA1 hash: b2486ec0b1f24f83c46d5d5d91e0643808013c54
MD5 hash: 8887a8b3c5475d2536c6547d48634840
humanhash: september-carbon-pennsylvania-south
File name:kla.sh
Download: download sample
File size:1'800 bytes
First seen:2026-01-22 09:28:21 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:It42lROS4bOIOS4KD1woOS4eXpOS4t/OS4ED8GOS4bLOS4BqeOS4KlOS4yCt9Ol:iXRWRNBR9pR8RUGRORiRrR2e
TLSH T1483141CA635207B52ED7DD2775E68804B188F0DAADC0DA18E5DCB8FA954EF083C45A53
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.148.120.23/bins/x86n/an/aelf ua-wget
http://45.148.120.23/bins/mipsn/an/aelf ua-wget
http://45.148.120.23/bins/mpsln/an/aelf ua-wget
http://45.148.120.23/bins/arm4n/an/aelf ua-wget
http://45.148.120.23/bins/arm5n/an/aelf ua-wget
http://45.148.120.23/bins/arm6n/an/aelf ua-wget
http://45.148.120.23/bins/arm7n/an/aelf ua-wget
http://45.148.120.23/bins/ppcn/an/aelf ua-wget
http://45.148.120.23/bins/m68kn/an/aelf ua-wget
http://45.148.120.23/bins/sh4n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
30
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox medusa mirai
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=f86f1c08-1800-0000-317d-6a118d0c0000 pid=3213 /usr/bin/sudo guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217 /tmp/sample.bin guuid=f86f1c08-1800-0000-317d-6a118d0c0000 pid=3213->guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217 execve guuid=ca0da70a-1800-0000-317d-6a11920c0000 pid=3218 /usr/bin/cp guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=ca0da70a-1800-0000-317d-6a11920c0000 pid=3218 execve guuid=942dfe0f-1800-0000-317d-6a119d0c0000 pid=3229 /usr/bin/wget net send-data guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=942dfe0f-1800-0000-317d-6a119d0c0000 pid=3229 execve guuid=450be713-1800-0000-317d-6a11a10c0000 pid=3233 /usr/bin/curl net send-data write-file guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=450be713-1800-0000-317d-6a11a10c0000 pid=3233 execve guuid=4a4b6f1d-1800-0000-317d-6a11ab0c0000 pid=3243 /usr/bin/cat guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=4a4b6f1d-1800-0000-317d-6a11ab0c0000 pid=3243 execve guuid=1b07011e-1800-0000-317d-6a11ae0c0000 pid=3246 /usr/bin/chmod guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=1b07011e-1800-0000-317d-6a11ae0c0000 pid=3246 execve guuid=3da1481e-1800-0000-317d-6a11af0c0000 pid=3247 /usr/bin/bash guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=3da1481e-1800-0000-317d-6a11af0c0000 pid=3247 clone guuid=42fa841e-1800-0000-317d-6a11b10c0000 pid=3249 /usr/bin/wget net send-data guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=42fa841e-1800-0000-317d-6a11b10c0000 pid=3249 execve guuid=13d40e21-1800-0000-317d-6a11b50c0000 pid=3253 /usr/bin/curl net send-data write-file guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=13d40e21-1800-0000-317d-6a11b50c0000 pid=3253 execve guuid=00ffe024-1800-0000-317d-6a11bc0c0000 pid=3260 /usr/bin/cat guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=00ffe024-1800-0000-317d-6a11bc0c0000 pid=3260 execve guuid=90a45425-1800-0000-317d-6a11bd0c0000 pid=3261 /usr/bin/chmod guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=90a45425-1800-0000-317d-6a11bd0c0000 pid=3261 execve guuid=332db525-1800-0000-317d-6a11be0c0000 pid=3262 /usr/bin/bash guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=332db525-1800-0000-317d-6a11be0c0000 pid=3262 clone guuid=d0c6e825-1800-0000-317d-6a11bf0c0000 pid=3263 /usr/bin/wget net send-data guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=d0c6e825-1800-0000-317d-6a11bf0c0000 pid=3263 execve guuid=b98a9028-1800-0000-317d-6a11c00c0000 pid=3264 /usr/bin/curl net send-data write-file guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=b98a9028-1800-0000-317d-6a11c00c0000 pid=3264 execve guuid=d305442c-1800-0000-317d-6a11ca0c0000 pid=3274 /usr/bin/cat guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=d305442c-1800-0000-317d-6a11ca0c0000 pid=3274 execve guuid=240b922c-1800-0000-317d-6a11cc0c0000 pid=3276 /usr/bin/chmod guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=240b922c-1800-0000-317d-6a11cc0c0000 pid=3276 execve guuid=7a10da2c-1800-0000-317d-6a11ce0c0000 pid=3278 /usr/bin/bash guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=7a10da2c-1800-0000-317d-6a11ce0c0000 pid=3278 clone guuid=daf5fa2c-1800-0000-317d-6a11cf0c0000 pid=3279 /usr/bin/wget net send-data guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=daf5fa2c-1800-0000-317d-6a11cf0c0000 pid=3279 execve guuid=bd406a2f-1800-0000-317d-6a11d80c0000 pid=3288 /usr/bin/curl net send-data write-file guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=bd406a2f-1800-0000-317d-6a11d80c0000 pid=3288 execve guuid=a5f34b34-1800-0000-317d-6a11e20c0000 pid=3298 /usr/bin/cat guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=a5f34b34-1800-0000-317d-6a11e20c0000 pid=3298 execve guuid=fc709134-1800-0000-317d-6a11e40c0000 pid=3300 /usr/bin/chmod guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=fc709134-1800-0000-317d-6a11e40c0000 pid=3300 execve guuid=fa0ddb34-1800-0000-317d-6a11e60c0000 pid=3302 /usr/bin/bash guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=fa0ddb34-1800-0000-317d-6a11e60c0000 pid=3302 clone guuid=85580f35-1800-0000-317d-6a11e80c0000 pid=3304 /usr/bin/wget net send-data guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=85580f35-1800-0000-317d-6a11e80c0000 pid=3304 execve guuid=92bd3c39-1800-0000-317d-6a11f20c0000 pid=3314 /usr/bin/curl net send-data write-file guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=92bd3c39-1800-0000-317d-6a11f20c0000 pid=3314 execve guuid=f66eaa3c-1800-0000-317d-6a11fc0c0000 pid=3324 /usr/bin/cat guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=f66eaa3c-1800-0000-317d-6a11fc0c0000 pid=3324 execve guuid=65f5f13c-1800-0000-317d-6a11fe0c0000 pid=3326 /usr/bin/chmod guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=65f5f13c-1800-0000-317d-6a11fe0c0000 pid=3326 execve guuid=6989333d-1800-0000-317d-6a11000d0000 pid=3328 /usr/bin/bash guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=6989333d-1800-0000-317d-6a11000d0000 pid=3328 clone guuid=803b553d-1800-0000-317d-6a11010d0000 pid=3329 /usr/bin/wget net send-data guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=803b553d-1800-0000-317d-6a11010d0000 pid=3329 execve guuid=5e919640-1800-0000-317d-6a110a0d0000 pid=3338 /usr/bin/curl net send-data write-file guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=5e919640-1800-0000-317d-6a110a0d0000 pid=3338 execve guuid=c76b5944-1800-0000-317d-6a11140d0000 pid=3348 /usr/bin/cat guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=c76b5944-1800-0000-317d-6a11140d0000 pid=3348 execve guuid=03b6aa44-1800-0000-317d-6a11160d0000 pid=3350 /usr/bin/chmod guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=03b6aa44-1800-0000-317d-6a11160d0000 pid=3350 execve guuid=33fef244-1800-0000-317d-6a11170d0000 pid=3351 /usr/bin/bash guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=33fef244-1800-0000-317d-6a11170d0000 pid=3351 clone guuid=130f2e45-1800-0000-317d-6a11190d0000 pid=3353 /usr/bin/wget net send-data guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=130f2e45-1800-0000-317d-6a11190d0000 pid=3353 execve guuid=a7f42d48-1800-0000-317d-6a111b0d0000 pid=3355 /usr/bin/curl net send-data write-file guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=a7f42d48-1800-0000-317d-6a111b0d0000 pid=3355 execve guuid=97a8244e-1800-0000-317d-6a111d0d0000 pid=3357 /usr/bin/cat guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=97a8244e-1800-0000-317d-6a111d0d0000 pid=3357 execve guuid=baa28a4e-1800-0000-317d-6a111e0d0000 pid=3358 /usr/bin/chmod guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=baa28a4e-1800-0000-317d-6a111e0d0000 pid=3358 execve guuid=2489dc4e-1800-0000-317d-6a111f0d0000 pid=3359 /usr/bin/bash guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=2489dc4e-1800-0000-317d-6a111f0d0000 pid=3359 clone guuid=9597044f-1800-0000-317d-6a11210d0000 pid=3361 /usr/bin/wget net send-data guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=9597044f-1800-0000-317d-6a11210d0000 pid=3361 execve guuid=6dcd6451-1800-0000-317d-6a11280d0000 pid=3368 /usr/bin/curl net send-data write-file guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=6dcd6451-1800-0000-317d-6a11280d0000 pid=3368 execve guuid=1a211358-1800-0000-317d-6a113b0d0000 pid=3387 /usr/bin/cat guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=1a211358-1800-0000-317d-6a113b0d0000 pid=3387 execve guuid=b72f5c58-1800-0000-317d-6a113d0d0000 pid=3389 /usr/bin/chmod guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=b72f5c58-1800-0000-317d-6a113d0d0000 pid=3389 execve guuid=b8509c58-1800-0000-317d-6a113f0d0000 pid=3391 /usr/bin/bash guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=b8509c58-1800-0000-317d-6a113f0d0000 pid=3391 clone guuid=e28ac058-1800-0000-317d-6a11410d0000 pid=3393 /usr/bin/wget net send-data guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=e28ac058-1800-0000-317d-6a11410d0000 pid=3393 execve guuid=3c212d5b-1800-0000-317d-6a11480d0000 pid=3400 /usr/bin/curl net send-data write-file guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=3c212d5b-1800-0000-317d-6a11480d0000 pid=3400 execve guuid=b0a1845e-1800-0000-317d-6a114f0d0000 pid=3407 /usr/bin/cat guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=b0a1845e-1800-0000-317d-6a114f0d0000 pid=3407 execve guuid=b85ecb5e-1800-0000-317d-6a11500d0000 pid=3408 /usr/bin/chmod guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=b85ecb5e-1800-0000-317d-6a11500d0000 pid=3408 execve guuid=c6270e5f-1800-0000-317d-6a11520d0000 pid=3410 /usr/bin/bash guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=c6270e5f-1800-0000-317d-6a11520d0000 pid=3410 clone guuid=6ac62b5f-1800-0000-317d-6a11530d0000 pid=3411 /usr/bin/wget net send-data guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=6ac62b5f-1800-0000-317d-6a11530d0000 pid=3411 execve guuid=2f17d761-1800-0000-317d-6a115d0d0000 pid=3421 /usr/bin/curl net send-data write-file guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=2f17d761-1800-0000-317d-6a115d0d0000 pid=3421 execve guuid=33634267-1800-0000-317d-6a116f0d0000 pid=3439 /usr/bin/cat guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=33634267-1800-0000-317d-6a116f0d0000 pid=3439 execve guuid=ca079067-1800-0000-317d-6a11700d0000 pid=3440 /usr/bin/chmod guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=ca079067-1800-0000-317d-6a11700d0000 pid=3440 execve guuid=9a2ce267-1800-0000-317d-6a11720d0000 pid=3442 /usr/bin/bash guuid=cd53e909-1800-0000-317d-6a11910c0000 pid=3217->guuid=9a2ce267-1800-0000-317d-6a11720d0000 pid=3442 clone cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 45.148.120.23:80 guuid=942dfe0f-1800-0000-317d-6a119d0c0000 pid=3229->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 136B guuid=450be713-1800-0000-317d-6a11a10c0000 pid=3233->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 85B guuid=42fa841e-1800-0000-317d-6a11b10c0000 pid=3249->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 137B guuid=13d40e21-1800-0000-317d-6a11b50c0000 pid=3253->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 86B guuid=d0c6e825-1800-0000-317d-6a11bf0c0000 pid=3263->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 137B guuid=b98a9028-1800-0000-317d-6a11c00c0000 pid=3264->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 86B guuid=daf5fa2c-1800-0000-317d-6a11cf0c0000 pid=3279->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 137B guuid=bd406a2f-1800-0000-317d-6a11d80c0000 pid=3288->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 86B guuid=85580f35-1800-0000-317d-6a11e80c0000 pid=3304->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 137B guuid=92bd3c39-1800-0000-317d-6a11f20c0000 pid=3314->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 86B guuid=803b553d-1800-0000-317d-6a11010d0000 pid=3329->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 137B guuid=5e919640-1800-0000-317d-6a110a0d0000 pid=3338->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 86B guuid=130f2e45-1800-0000-317d-6a11190d0000 pid=3353->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 137B guuid=a7f42d48-1800-0000-317d-6a111b0d0000 pid=3355->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 86B guuid=9597044f-1800-0000-317d-6a11210d0000 pid=3361->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 136B guuid=6dcd6451-1800-0000-317d-6a11280d0000 pid=3368->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 85B guuid=e28ac058-1800-0000-317d-6a11410d0000 pid=3393->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 137B guuid=3c212d5b-1800-0000-317d-6a11480d0000 pid=3400->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 86B guuid=6ac62b5f-1800-0000-317d-6a11530d0000 pid=3411->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 136B guuid=2f17d761-1800-0000-317d-6a115d0d0000 pid=3421->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 85B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-01-22 09:28:52 UTC
File Type:
Text (Shell)
AV detection:
21 of 36 (58.33%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 08fe41363db1d915cc9b0d0c1cb821ccf67f4c54fa75bb0bb0d79b2f310d1636

(this sample)

  
Delivery method
Distributed via web download

Comments