MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1a61c91c28f265aed8cc451a2c38bc0dd7e83359c50ad304f68184743be88da4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: 1a61c91c28f265aed8cc451a2c38bc0dd7e83359c50ad304f68184743be88da4
SHA3-384 hash: d3830035648d5797da06eabd98078c486ae98dd5d06f3631c5581d5b1ce2a31da0899e08b5060012cd69f4b4ea1ae366
SHA1 hash: beaf6c15aa027f6b7feae8c3e875a9e7fa7a77af
MD5 hash: fc1f822b8813e45f277276d404de4cd5
humanhash: salami-video-fourteen-louisiana
File name:1.sh
Download: download sample
File size:2'989 bytes
First seen:2026-03-14 13:18:43 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:iRAhmlR2nElRJCXlRlePlRaCazvZlRa0aFvjlR9Nc9z4gelRSjclR5SvlRjCjzqC:iUmlwElmXlqPlY7zvZlY5FvjlLsz4Zlj
TLSH T116512FCB02910F71696A7717FFB98E2C318264E2A8932F4496DF34E55B8CFC87544A87
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://94.156.152.233/hiddenbin/Space.arcn/an/aelf ua-wget
http://94.156.152.233/hiddenbin/Space.x86n/an/aelf ua-wget
http://94.156.152.233/hiddenbin/Space.x86_64n/an/aelf ua-wget
http://94.156.152.233/hiddenbin/Space.i686n/an/aelf ua-wget
http://94.156.152.233/hiddenbin/Space.mipsn/an/aelf ua-wget
http://94.156.152.233/hiddenbin/Space.mips64n/an/aelf ua-wget
http://94.156.152.233/hiddenbin/Space.mpsln/an/aelf ua-wget
http://94.156.152.233/hiddenbin/Space.armn/an/aelf ua-wget
http://94.156.152.233/hiddenbin/Space.arm5n/an/aelf ua-wget
http://94.156.152.233/hiddenbin/Space.arm6n/an/aelf ua-wget
http://94.156.152.233/hiddenbin/Space.arm7n/an/aelf ua-wget
http://94.156.152.233/hiddenbin/Space.ppcn/an/aelf ua-wget
http://94.156.152.233/hiddenbin/Space.sparcn/an/aelf ua-wget
http://94.156.152.233/hiddenbin/Space.m68kn/an/aelf ua-wget
http://94.156.152.233/hiddenbin/Space.sh4n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=4b085bdc-1b00-0000-4337-8f40070b0000 pid=2823 /usr/bin/sudo guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829 /tmp/sample.bin guuid=4b085bdc-1b00-0000-4337-8f40070b0000 pid=2823->guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829 execve guuid=7b251de1-1b00-0000-4337-8f400f0b0000 pid=2831 /usr/bin/cp guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=7b251de1-1b00-0000-4337-8f400f0b0000 pid=2831 execve guuid=08f5bae2-1b00-0000-4337-8f40140b0000 pid=2836 /usr/bin/wget net send-data guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=08f5bae2-1b00-0000-4337-8f40140b0000 pid=2836 execve guuid=b7217aec-1b00-0000-4337-8f40280b0000 pid=2856 /usr/bin/curl net send-data write-file guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=b7217aec-1b00-0000-4337-8f40280b0000 pid=2856 execve guuid=b9a8d7f6-1b00-0000-4337-8f40470b0000 pid=2887 /usr/bin/cat guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=b9a8d7f6-1b00-0000-4337-8f40470b0000 pid=2887 execve guuid=77a82af7-1b00-0000-4337-8f40490b0000 pid=2889 /usr/bin/chmod guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=77a82af7-1b00-0000-4337-8f40490b0000 pid=2889 execve guuid=6dd690f7-1b00-0000-4337-8f404b0b0000 pid=2891 /usr/bin/bash guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=6dd690f7-1b00-0000-4337-8f404b0b0000 pid=2891 clone guuid=390ebcf7-1b00-0000-4337-8f404d0b0000 pid=2893 /usr/bin/wget net send-data guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=390ebcf7-1b00-0000-4337-8f404d0b0000 pid=2893 execve guuid=57df8dff-1b00-0000-4337-8f40650b0000 pid=2917 /usr/bin/curl net send-data write-file guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=57df8dff-1b00-0000-4337-8f40650b0000 pid=2917 execve guuid=f5fe1409-1c00-0000-4337-8f407c0b0000 pid=2940 /usr/bin/cat guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=f5fe1409-1c00-0000-4337-8f407c0b0000 pid=2940 execve guuid=dd0f6409-1c00-0000-4337-8f407f0b0000 pid=2943 /usr/bin/chmod guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=dd0f6409-1c00-0000-4337-8f407f0b0000 pid=2943 execve guuid=612eab09-1c00-0000-4337-8f40800b0000 pid=2944 /usr/bin/bash guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=612eab09-1c00-0000-4337-8f40800b0000 pid=2944 clone guuid=57a2cb09-1c00-0000-4337-8f40810b0000 pid=2945 /usr/bin/wget net send-data guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=57a2cb09-1c00-0000-4337-8f40810b0000 pid=2945 execve guuid=97d1d311-1c00-0000-4337-8f40940b0000 pid=2964 /usr/bin/curl net send-data write-file guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=97d1d311-1c00-0000-4337-8f40940b0000 pid=2964 execve guuid=151f2c1b-1c00-0000-4337-8f40ae0b0000 pid=2990 /usr/bin/cat guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=151f2c1b-1c00-0000-4337-8f40ae0b0000 pid=2990 execve guuid=109ba41b-1c00-0000-4337-8f40b00b0000 pid=2992 /usr/bin/chmod guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=109ba41b-1c00-0000-4337-8f40b00b0000 pid=2992 execve guuid=d9bb0d1c-1c00-0000-4337-8f40b30b0000 pid=2995 /usr/bin/bash guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=d9bb0d1c-1c00-0000-4337-8f40b30b0000 pid=2995 clone guuid=97fe381c-1c00-0000-4337-8f40b40b0000 pid=2996 /usr/bin/wget net send-data guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=97fe381c-1c00-0000-4337-8f40b40b0000 pid=2996 execve guuid=83288824-1c00-0000-4337-8f40c90b0000 pid=3017 /usr/bin/curl net send-data write-file guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=83288824-1c00-0000-4337-8f40c90b0000 pid=3017 execve guuid=7661402e-1c00-0000-4337-8f40e30b0000 pid=3043 /usr/bin/cat guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=7661402e-1c00-0000-4337-8f40e30b0000 pid=3043 execve guuid=ca95922e-1c00-0000-4337-8f40e50b0000 pid=3045 /usr/bin/chmod guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=ca95922e-1c00-0000-4337-8f40e50b0000 pid=3045 execve guuid=6048d22e-1c00-0000-4337-8f40e70b0000 pid=3047 /usr/bin/bash guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=6048d22e-1c00-0000-4337-8f40e70b0000 pid=3047 clone guuid=1af1f52e-1c00-0000-4337-8f40e90b0000 pid=3049 /usr/bin/wget net send-data guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=1af1f52e-1c00-0000-4337-8f40e90b0000 pid=3049 execve guuid=b14d8b36-1c00-0000-4337-8f40020c0000 pid=3074 /usr/bin/curl net send-data write-file guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=b14d8b36-1c00-0000-4337-8f40020c0000 pid=3074 execve guuid=e0070d40-1c00-0000-4337-8f40200c0000 pid=3104 /usr/bin/cat guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=e0070d40-1c00-0000-4337-8f40200c0000 pid=3104 execve guuid=eecc7240-1c00-0000-4337-8f40220c0000 pid=3106 /usr/bin/chmod guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=eecc7240-1c00-0000-4337-8f40220c0000 pid=3106 execve guuid=eeffc240-1c00-0000-4337-8f40240c0000 pid=3108 /usr/bin/bash guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=eeffc240-1c00-0000-4337-8f40240c0000 pid=3108 clone guuid=d1d0f640-1c00-0000-4337-8f40250c0000 pid=3109 /usr/bin/wget net send-data guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=d1d0f640-1c00-0000-4337-8f40250c0000 pid=3109 execve guuid=cc282c49-1c00-0000-4337-8f40390c0000 pid=3129 /usr/bin/curl net send-data write-file guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=cc282c49-1c00-0000-4337-8f40390c0000 pid=3129 execve guuid=0dabce51-1c00-0000-4337-8f404e0c0000 pid=3150 /usr/bin/cat guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=0dabce51-1c00-0000-4337-8f404e0c0000 pid=3150 execve guuid=cd4e2552-1c00-0000-4337-8f40500c0000 pid=3152 /usr/bin/chmod guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=cd4e2552-1c00-0000-4337-8f40500c0000 pid=3152 execve guuid=c42c7452-1c00-0000-4337-8f40520c0000 pid=3154 /usr/bin/bash guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=c42c7452-1c00-0000-4337-8f40520c0000 pid=3154 clone guuid=2d42a152-1c00-0000-4337-8f40530c0000 pid=3155 /usr/bin/wget net send-data guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=2d42a152-1c00-0000-4337-8f40530c0000 pid=3155 execve guuid=ba76ab5a-1c00-0000-4337-8f406a0c0000 pid=3178 /usr/bin/curl net send-data write-file guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=ba76ab5a-1c00-0000-4337-8f406a0c0000 pid=3178 execve guuid=124f3e64-1c00-0000-4337-8f407f0c0000 pid=3199 /usr/bin/cat guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=124f3e64-1c00-0000-4337-8f407f0c0000 pid=3199 execve guuid=a394b364-1c00-0000-4337-8f40810c0000 pid=3201 /usr/bin/chmod guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=a394b364-1c00-0000-4337-8f40810c0000 pid=3201 execve guuid=2f170e65-1c00-0000-4337-8f40830c0000 pid=3203 /usr/bin/bash guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=2f170e65-1c00-0000-4337-8f40830c0000 pid=3203 clone guuid=fe115a65-1c00-0000-4337-8f40850c0000 pid=3205 /usr/bin/wget net send-data guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=fe115a65-1c00-0000-4337-8f40850c0000 pid=3205 execve guuid=b89b376e-1c00-0000-4337-8f40950c0000 pid=3221 /usr/bin/curl net send-data write-file guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=b89b376e-1c00-0000-4337-8f40950c0000 pid=3221 execve guuid=01d57e79-1c00-0000-4337-8f40960c0000 pid=3222 /usr/bin/cat guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=01d57e79-1c00-0000-4337-8f40960c0000 pid=3222 execve guuid=e581fd79-1c00-0000-4337-8f40970c0000 pid=3223 /usr/bin/chmod guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=e581fd79-1c00-0000-4337-8f40970c0000 pid=3223 execve guuid=3150707a-1c00-0000-4337-8f40980c0000 pid=3224 /usr/bin/bash guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=3150707a-1c00-0000-4337-8f40980c0000 pid=3224 clone guuid=aba6b17a-1c00-0000-4337-8f40990c0000 pid=3225 /usr/bin/wget net send-data guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=aba6b17a-1c00-0000-4337-8f40990c0000 pid=3225 execve guuid=63a11a83-1c00-0000-4337-8f40a40c0000 pid=3236 /usr/bin/curl net send-data write-file guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=63a11a83-1c00-0000-4337-8f40a40c0000 pid=3236 execve guuid=2bf4fd8b-1c00-0000-4337-8f40bb0c0000 pid=3259 /usr/bin/cat guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=2bf4fd8b-1c00-0000-4337-8f40bb0c0000 pid=3259 execve guuid=bc4a4a8c-1c00-0000-4337-8f40bd0c0000 pid=3261 /usr/bin/chmod guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=bc4a4a8c-1c00-0000-4337-8f40bd0c0000 pid=3261 execve guuid=cf0db78c-1c00-0000-4337-8f40bf0c0000 pid=3263 /usr/bin/bash guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=cf0db78c-1c00-0000-4337-8f40bf0c0000 pid=3263 clone guuid=520ef28c-1c00-0000-4337-8f40c00c0000 pid=3264 /usr/bin/wget net send-data guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=520ef28c-1c00-0000-4337-8f40c00c0000 pid=3264 execve guuid=92942a95-1c00-0000-4337-8f40c30c0000 pid=3267 /usr/bin/curl net send-data write-file guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=92942a95-1c00-0000-4337-8f40c30c0000 pid=3267 execve guuid=bbf25ba1-1c00-0000-4337-8f40cb0c0000 pid=3275 /usr/bin/cat guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=bbf25ba1-1c00-0000-4337-8f40cb0c0000 pid=3275 execve guuid=e487c7a1-1c00-0000-4337-8f40cc0c0000 pid=3276 /usr/bin/chmod guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=e487c7a1-1c00-0000-4337-8f40cc0c0000 pid=3276 execve guuid=cd7516a2-1c00-0000-4337-8f40ce0c0000 pid=3278 /usr/bin/bash guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=cd7516a2-1c00-0000-4337-8f40ce0c0000 pid=3278 clone guuid=3ca44ea2-1c00-0000-4337-8f40cf0c0000 pid=3279 /usr/bin/wget net send-data guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=3ca44ea2-1c00-0000-4337-8f40cf0c0000 pid=3279 execve guuid=776930aa-1c00-0000-4337-8f40dd0c0000 pid=3293 /usr/bin/curl net send-data write-file guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=776930aa-1c00-0000-4337-8f40dd0c0000 pid=3293 execve guuid=39f815b6-1c00-0000-4337-8f40ed0c0000 pid=3309 /usr/bin/cat guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=39f815b6-1c00-0000-4337-8f40ed0c0000 pid=3309 execve guuid=e2f568b6-1c00-0000-4337-8f40ee0c0000 pid=3310 /usr/bin/chmod guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=e2f568b6-1c00-0000-4337-8f40ee0c0000 pid=3310 execve guuid=3f61b3b6-1c00-0000-4337-8f40f00c0000 pid=3312 /usr/bin/bash guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=3f61b3b6-1c00-0000-4337-8f40f00c0000 pid=3312 clone guuid=eae6d7b6-1c00-0000-4337-8f40f10c0000 pid=3313 /usr/bin/wget net send-data guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=eae6d7b6-1c00-0000-4337-8f40f10c0000 pid=3313 execve guuid=a75b95c0-1c00-0000-4337-8f40fe0c0000 pid=3326 /usr/bin/curl net send-data write-file guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=a75b95c0-1c00-0000-4337-8f40fe0c0000 pid=3326 execve guuid=0f54a4ca-1c00-0000-4337-8f40170d0000 pid=3351 /usr/bin/cat guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=0f54a4ca-1c00-0000-4337-8f40170d0000 pid=3351 execve guuid=22cff8ca-1c00-0000-4337-8f40180d0000 pid=3352 /usr/bin/chmod guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=22cff8ca-1c00-0000-4337-8f40180d0000 pid=3352 execve guuid=8c8b42cb-1c00-0000-4337-8f401a0d0000 pid=3354 /usr/bin/bash guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=8c8b42cb-1c00-0000-4337-8f401a0d0000 pid=3354 clone guuid=de576bcb-1c00-0000-4337-8f401b0d0000 pid=3355 /usr/bin/wget net send-data guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=de576bcb-1c00-0000-4337-8f401b0d0000 pid=3355 execve guuid=a50c5fd3-1c00-0000-4337-8f402e0d0000 pid=3374 /usr/bin/curl net send-data write-file guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=a50c5fd3-1c00-0000-4337-8f402e0d0000 pid=3374 execve guuid=e14c1add-1c00-0000-4337-8f40440d0000 pid=3396 /usr/bin/cat guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=e14c1add-1c00-0000-4337-8f40440d0000 pid=3396 execve guuid=51327edd-1c00-0000-4337-8f40450d0000 pid=3397 /usr/bin/chmod guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=51327edd-1c00-0000-4337-8f40450d0000 pid=3397 execve guuid=4c2d15de-1c00-0000-4337-8f40460d0000 pid=3398 /usr/bin/bash guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=4c2d15de-1c00-0000-4337-8f40460d0000 pid=3398 clone guuid=ef8860de-1c00-0000-4337-8f40470d0000 pid=3399 /usr/bin/wget net send-data guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=ef8860de-1c00-0000-4337-8f40470d0000 pid=3399 execve guuid=42bacde6-1c00-0000-4337-8f40480d0000 pid=3400 /usr/bin/curl net send-data write-file guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=42bacde6-1c00-0000-4337-8f40480d0000 pid=3400 execve guuid=4d1267f0-1c00-0000-4337-8f40550d0000 pid=3413 /usr/bin/cat guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=4d1267f0-1c00-0000-4337-8f40550d0000 pid=3413 execve guuid=1c9dc1f0-1c00-0000-4337-8f40570d0000 pid=3415 /usr/bin/chmod guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=1c9dc1f0-1c00-0000-4337-8f40570d0000 pid=3415 execve guuid=b4112cf1-1c00-0000-4337-8f405a0d0000 pid=3418 /usr/bin/bash guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=b4112cf1-1c00-0000-4337-8f405a0d0000 pid=3418 clone guuid=6fb667f1-1c00-0000-4337-8f405b0d0000 pid=3419 /usr/bin/wget net send-data guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=6fb667f1-1c00-0000-4337-8f405b0d0000 pid=3419 execve guuid=94aa81f9-1c00-0000-4337-8f406d0d0000 pid=3437 /usr/bin/curl net send-data write-file guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=94aa81f9-1c00-0000-4337-8f406d0d0000 pid=3437 execve guuid=998aec06-1d00-0000-4337-8f408c0d0000 pid=3468 /usr/bin/cat guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=998aec06-1d00-0000-4337-8f408c0d0000 pid=3468 execve guuid=b5d96a07-1d00-0000-4337-8f408e0d0000 pid=3470 /usr/bin/chmod guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=b5d96a07-1d00-0000-4337-8f408e0d0000 pid=3470 execve guuid=4f5c0d08-1d00-0000-4337-8f408f0d0000 pid=3471 /usr/bin/bash guuid=fe026be0-1b00-0000-4337-8f400d0b0000 pid=2829->guuid=4f5c0d08-1d00-0000-4337-8f408f0d0000 pid=3471 clone 72af6dc9-e0e7-5186-a050-4a3a967dfc62 94.156.152.233:80 guuid=08f5bae2-1b00-0000-4337-8f40140b0000 pid=2836->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 148B guuid=b7217aec-1b00-0000-4337-8f40280b0000 pid=2856->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 97B guuid=390ebcf7-1b00-0000-4337-8f404d0b0000 pid=2893->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 148B guuid=57df8dff-1b00-0000-4337-8f40650b0000 pid=2917->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 97B guuid=57a2cb09-1c00-0000-4337-8f40810b0000 pid=2945->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 151B guuid=97d1d311-1c00-0000-4337-8f40940b0000 pid=2964->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 100B guuid=97fe381c-1c00-0000-4337-8f40b40b0000 pid=2996->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 149B guuid=83288824-1c00-0000-4337-8f40c90b0000 pid=3017->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 98B guuid=1af1f52e-1c00-0000-4337-8f40e90b0000 pid=3049->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 149B guuid=b14d8b36-1c00-0000-4337-8f40020c0000 pid=3074->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 98B guuid=d1d0f640-1c00-0000-4337-8f40250c0000 pid=3109->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 151B guuid=cc282c49-1c00-0000-4337-8f40390c0000 pid=3129->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 100B guuid=2d42a152-1c00-0000-4337-8f40530c0000 pid=3155->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 149B guuid=ba76ab5a-1c00-0000-4337-8f406a0c0000 pid=3178->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 98B guuid=fe115a65-1c00-0000-4337-8f40850c0000 pid=3205->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 148B guuid=b89b376e-1c00-0000-4337-8f40950c0000 pid=3221->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 97B guuid=aba6b17a-1c00-0000-4337-8f40990c0000 pid=3225->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 149B guuid=63a11a83-1c00-0000-4337-8f40a40c0000 pid=3236->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 98B guuid=520ef28c-1c00-0000-4337-8f40c00c0000 pid=3264->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 149B guuid=92942a95-1c00-0000-4337-8f40c30c0000 pid=3267->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 98B guuid=3ca44ea2-1c00-0000-4337-8f40cf0c0000 pid=3279->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 149B guuid=776930aa-1c00-0000-4337-8f40dd0c0000 pid=3293->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 98B guuid=eae6d7b6-1c00-0000-4337-8f40f10c0000 pid=3313->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 148B guuid=a75b95c0-1c00-0000-4337-8f40fe0c0000 pid=3326->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 97B guuid=de576bcb-1c00-0000-4337-8f401b0d0000 pid=3355->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 150B guuid=a50c5fd3-1c00-0000-4337-8f402e0d0000 pid=3374->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 99B guuid=ef8860de-1c00-0000-4337-8f40470d0000 pid=3399->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 149B guuid=42bacde6-1c00-0000-4337-8f40480d0000 pid=3400->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 98B guuid=6fb667f1-1c00-0000-4337-8f405b0d0000 pid=3419->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 148B guuid=94aa81f9-1c00-0000-4337-8f406d0d0000 pid=3437->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 97B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-03-14 13:19:46 UTC
File Type:
Text (Shell)
AV detection:
16 of 23 (69.57%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 1a61c91c28f265aed8cc451a2c38bc0dd7e83359c50ad304f68184743be88da4

(this sample)

  
Delivery method
Distributed via web download

Comments