MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1ce808d1d4bb89ecd9c2eb1932c1dad00de80978d13f358a4ea18f5e7074e88e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DDoSAgent


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: 1ce808d1d4bb89ecd9c2eb1932c1dad00de80978d13f358a4ea18f5e7074e88e
SHA3-384 hash: aff2474a5ef214ce9c7a1dd806310cd3811643f6b75a38f3b94b4d2a399e9c645f542429591aadf57f7dae1d895022db
SHA1 hash: 5f08c06b72641531ea026025474b304e6779d3f6
MD5 hash: ba345cf63415339e4ccd36b4483b99e3
humanhash: coffee-bacon-sierra-helium
File name:sex.sh
Download: download sample
Signature DDoSAgent
File size:1'629 bytes
First seen:2026-05-17 16:39:51 UTC
Last seen:2026-05-18 01:31:42 UTC
File type: sh
MIME type:text/plain
ssdeep 48:1ptp5pb4EpXJpZpt/p6UptpJpQfypwkpBp0:1bH94EZJvDAUb3j7Pm
TLSH T123314DCA21E15975ACF8F92732A9880479D5F1CB14CE2F596EDC38E984CDE08B051B93
Magika csv
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139.121/mips21ee3817fde179bd5212c223c12a10c053f228e9261e1b8b47964c6fcf062906 DDoSAgentDDoSAgent
http://176.65.139.121/mipseleb0f3a5689160cb8a7e003987904188e43cf1a221c8e84047967ddfe6d2d12fb DDoSAgentDDoSAgent elf opendir ua-wget
http://176.65.139.121/sh4n/an/aelf opendir ua-wget
http://176.65.139.121/x86b62c85bd2d6dee50ab46ab0691e4c8f6075b5ee4d4656a24324b5330b57e5674 Miraimirai
http://176.65.139.121/arm6191521f3f0978d2268974925857388099d0f39164b1aad6000cc36b198f06301b Gafgytgafgyt
http://176.65.139.121/i686b62c85bd2d6dee50ab46ab0691e4c8f6075b5ee4d4656a24324b5330b57e5674 Miraielf mirai opendir ua-wget
http://176.65.139.121/ppcn/an/aelf opendir ua-wget
http://176.65.139.121/586n/an/aelf opendir ua-wget
http://176.65.139.121/m68kn/an/aelf opendir ua-wget
http://176.65.139.121/dcn/an/aelf opendir ua-wget
http://176.65.139.121/dssn/an/aelf opendir ua-wget
http://176.65.139.121/con/an/aelf opendir ua-wget
http://176.65.139.121/scarn/an/aelf opendir ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
32
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
text
First seen:
2026-05-17T13:46:00Z UTC
Last seen:
2026-05-19T12:12:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=01ceecb2-1a00-0000-931f-2a8fab090000 pid=2475 /usr/bin/sudo guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482 /tmp/sample.bin guuid=01ceecb2-1a00-0000-931f-2a8fab090000 pid=2475->guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482 execve guuid=b83ae3b5-1a00-0000-931f-2a8fb4090000 pid=2484 /usr/bin/wget net send-data write-file guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=b83ae3b5-1a00-0000-931f-2a8fb4090000 pid=2484 execve guuid=e8c79fed-1a00-0000-931f-2a8f270a0000 pid=2599 /usr/bin/chmod guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=e8c79fed-1a00-0000-931f-2a8f270a0000 pid=2599 execve guuid=385bdded-1a00-0000-931f-2a8f290a0000 pid=2601 /usr/bin/dash guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=385bdded-1a00-0000-931f-2a8f290a0000 pid=2601 clone guuid=7eadebed-1a00-0000-931f-2a8f2a0a0000 pid=2602 /usr/bin/rm delete-file guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=7eadebed-1a00-0000-931f-2a8f2a0a0000 pid=2602 execve guuid=74393eee-1a00-0000-931f-2a8f2c0a0000 pid=2604 /usr/bin/wget net send-data guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=74393eee-1a00-0000-931f-2a8f2c0a0000 pid=2604 execve guuid=601839f2-1a00-0000-931f-2a8f390a0000 pid=2617 /usr/bin/chmod guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=601839f2-1a00-0000-931f-2a8f390a0000 pid=2617 execve guuid=04219ff2-1a00-0000-931f-2a8f3b0a0000 pid=2619 /usr/bin/dash guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=04219ff2-1a00-0000-931f-2a8f3b0a0000 pid=2619 clone guuid=c075aff2-1a00-0000-931f-2a8f3c0a0000 pid=2620 /usr/bin/rm guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=c075aff2-1a00-0000-931f-2a8f3c0a0000 pid=2620 execve guuid=7e3016f3-1a00-0000-931f-2a8f3e0a0000 pid=2622 /usr/bin/wget net send-data guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=7e3016f3-1a00-0000-931f-2a8f3e0a0000 pid=2622 execve guuid=8da5adf5-1a00-0000-931f-2a8f480a0000 pid=2632 /usr/bin/chmod guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=8da5adf5-1a00-0000-931f-2a8f480a0000 pid=2632 execve guuid=a2682cf6-1a00-0000-931f-2a8f4a0a0000 pid=2634 /usr/bin/dash guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=a2682cf6-1a00-0000-931f-2a8f4a0a0000 pid=2634 clone guuid=5c0e41f6-1a00-0000-931f-2a8f4c0a0000 pid=2636 /usr/bin/rm guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=5c0e41f6-1a00-0000-931f-2a8f4c0a0000 pid=2636 execve guuid=6ce293f6-1a00-0000-931f-2a8f4d0a0000 pid=2637 /usr/bin/wget net send-data write-file guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=6ce293f6-1a00-0000-931f-2a8f4d0a0000 pid=2637 execve guuid=b3bdfd15-1b00-0000-931f-2a8f9f0a0000 pid=2719 /usr/bin/chmod guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=b3bdfd15-1b00-0000-931f-2a8f9f0a0000 pid=2719 execve guuid=06a63716-1b00-0000-931f-2a8fa00a0000 pid=2720 /usr/bin/dash guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=06a63716-1b00-0000-931f-2a8fa00a0000 pid=2720 clone guuid=e61b4616-1b00-0000-931f-2a8fa10a0000 pid=2721 /usr/bin/rm delete-file guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=e61b4616-1b00-0000-931f-2a8fa10a0000 pid=2721 execve guuid=2db09316-1b00-0000-931f-2a8fa30a0000 pid=2723 /usr/bin/wget net send-data write-file guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=2db09316-1b00-0000-931f-2a8fa30a0000 pid=2723 execve guuid=1ece0221-1b00-0000-931f-2a8fbe0a0000 pid=2750 /usr/bin/chmod guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=1ece0221-1b00-0000-931f-2a8fbe0a0000 pid=2750 execve guuid=8b613f21-1b00-0000-931f-2a8fc10a0000 pid=2753 /usr/bin/dash guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=8b613f21-1b00-0000-931f-2a8fc10a0000 pid=2753 clone guuid=24485121-1b00-0000-931f-2a8fc20a0000 pid=2754 /usr/bin/rm delete-file guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=24485121-1b00-0000-931f-2a8fc20a0000 pid=2754 execve guuid=0c7ebc21-1b00-0000-931f-2a8fc40a0000 pid=2756 /usr/bin/wget net send-data guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=0c7ebc21-1b00-0000-931f-2a8fc40a0000 pid=2756 execve guuid=307d7729-1b00-0000-931f-2a8fd50a0000 pid=2773 /usr/bin/chmod guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=307d7729-1b00-0000-931f-2a8fd50a0000 pid=2773 execve guuid=2a48e329-1b00-0000-931f-2a8fd60a0000 pid=2774 /usr/bin/dash guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=2a48e329-1b00-0000-931f-2a8fd60a0000 pid=2774 clone guuid=ddb4e829-1b00-0000-931f-2a8fd80a0000 pid=2776 /usr/bin/rm guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=ddb4e829-1b00-0000-931f-2a8fd80a0000 pid=2776 execve guuid=c30a2b2a-1b00-0000-931f-2a8fd90a0000 pid=2777 /usr/bin/wget net send-data guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=c30a2b2a-1b00-0000-931f-2a8fd90a0000 pid=2777 execve guuid=5b78c72e-1b00-0000-931f-2a8fe50a0000 pid=2789 /usr/bin/chmod guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=5b78c72e-1b00-0000-931f-2a8fe50a0000 pid=2789 execve guuid=88920f2f-1b00-0000-931f-2a8fe70a0000 pid=2791 /usr/bin/dash guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=88920f2f-1b00-0000-931f-2a8fe70a0000 pid=2791 clone guuid=7973172f-1b00-0000-931f-2a8fe80a0000 pid=2792 /usr/bin/rm guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=7973172f-1b00-0000-931f-2a8fe80a0000 pid=2792 execve guuid=cdb7642f-1b00-0000-931f-2a8fea0a0000 pid=2794 /usr/bin/wget net send-data guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=cdb7642f-1b00-0000-931f-2a8fea0a0000 pid=2794 execve guuid=3c942432-1b00-0000-931f-2a8ff00a0000 pid=2800 /usr/bin/chmod guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=3c942432-1b00-0000-931f-2a8ff00a0000 pid=2800 execve guuid=54d37632-1b00-0000-931f-2a8ff20a0000 pid=2802 /usr/bin/dash guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=54d37632-1b00-0000-931f-2a8ff20a0000 pid=2802 clone guuid=e8258432-1b00-0000-931f-2a8ff30a0000 pid=2803 /usr/bin/rm guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=e8258432-1b00-0000-931f-2a8ff30a0000 pid=2803 execve guuid=2964d132-1b00-0000-931f-2a8ff50a0000 pid=2805 /usr/bin/wget net send-data guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=2964d132-1b00-0000-931f-2a8ff50a0000 pid=2805 execve guuid=fe92ad37-1b00-0000-931f-2a8fff0a0000 pid=2815 /usr/bin/chmod guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=fe92ad37-1b00-0000-931f-2a8fff0a0000 pid=2815 execve guuid=8ec7f437-1b00-0000-931f-2a8f000b0000 pid=2816 /usr/bin/dash guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=8ec7f437-1b00-0000-931f-2a8f000b0000 pid=2816 clone guuid=a17d0538-1b00-0000-931f-2a8f010b0000 pid=2817 /usr/bin/rm guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=a17d0538-1b00-0000-931f-2a8f010b0000 pid=2817 execve guuid=f52c5138-1b00-0000-931f-2a8f030b0000 pid=2819 /usr/bin/wget net send-data guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=f52c5138-1b00-0000-931f-2a8f030b0000 pid=2819 execve guuid=d53e7f3c-1b00-0000-931f-2a8f0e0b0000 pid=2830 /usr/bin/chmod guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=d53e7f3c-1b00-0000-931f-2a8f0e0b0000 pid=2830 execve guuid=7168dc3c-1b00-0000-931f-2a8f100b0000 pid=2832 /usr/bin/dash guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=7168dc3c-1b00-0000-931f-2a8f100b0000 pid=2832 clone guuid=8cc4e43c-1b00-0000-931f-2a8f110b0000 pid=2833 /usr/bin/rm guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=8cc4e43c-1b00-0000-931f-2a8f110b0000 pid=2833 execve guuid=40fa323d-1b00-0000-931f-2a8f130b0000 pid=2835 /usr/bin/wget net send-data guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=40fa323d-1b00-0000-931f-2a8f130b0000 pid=2835 execve guuid=70d95540-1b00-0000-931f-2a8f1b0b0000 pid=2843 /usr/bin/chmod guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=70d95540-1b00-0000-931f-2a8f1b0b0000 pid=2843 execve guuid=9da0b840-1b00-0000-931f-2a8f1c0b0000 pid=2844 /usr/bin/dash guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=9da0b840-1b00-0000-931f-2a8f1c0b0000 pid=2844 clone guuid=9d9fc640-1b00-0000-931f-2a8f1e0b0000 pid=2846 /usr/bin/rm guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=9d9fc640-1b00-0000-931f-2a8f1e0b0000 pid=2846 execve guuid=0b772541-1b00-0000-931f-2a8f1f0b0000 pid=2847 /usr/bin/wget net send-data guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=0b772541-1b00-0000-931f-2a8f1f0b0000 pid=2847 execve guuid=df728f47-1b00-0000-931f-2a8f2a0b0000 pid=2858 /usr/bin/chmod guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=df728f47-1b00-0000-931f-2a8f2a0b0000 pid=2858 execve guuid=5c80e047-1b00-0000-931f-2a8f2b0b0000 pid=2859 /usr/bin/dash guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=5c80e047-1b00-0000-931f-2a8f2b0b0000 pid=2859 clone guuid=4d6eeb47-1b00-0000-931f-2a8f2c0b0000 pid=2860 /usr/bin/rm guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=4d6eeb47-1b00-0000-931f-2a8f2c0b0000 pid=2860 execve guuid=d4d03148-1b00-0000-931f-2a8f2e0b0000 pid=2862 /usr/bin/wget net send-data guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=d4d03148-1b00-0000-931f-2a8f2e0b0000 pid=2862 execve guuid=d9f6eb4a-1b00-0000-931f-2a8f360b0000 pid=2870 /usr/bin/chmod guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=d9f6eb4a-1b00-0000-931f-2a8f360b0000 pid=2870 execve guuid=bb52604b-1b00-0000-931f-2a8f380b0000 pid=2872 /usr/bin/dash guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=bb52604b-1b00-0000-931f-2a8f380b0000 pid=2872 clone guuid=0be06e4b-1b00-0000-931f-2a8f390b0000 pid=2873 /usr/bin/rm guuid=d1c38eb5-1a00-0000-931f-2a8fb2090000 pid=2482->guuid=0be06e4b-1b00-0000-931f-2a8f390b0000 pid=2873 execve 1d7bf28b-6ddb-5e47-86a8-756dcbfab639 176.65.139.121:80 guuid=b83ae3b5-1a00-0000-931f-2a8fb4090000 pid=2484->1d7bf28b-6ddb-5e47-86a8-756dcbfab639 send: 133B guuid=74393eee-1a00-0000-931f-2a8f2c0a0000 pid=2604->1d7bf28b-6ddb-5e47-86a8-756dcbfab639 send: 135B guuid=7e3016f3-1a00-0000-931f-2a8f3e0a0000 pid=2622->1d7bf28b-6ddb-5e47-86a8-756dcbfab639 send: 132B guuid=6ce293f6-1a00-0000-931f-2a8f4d0a0000 pid=2637->1d7bf28b-6ddb-5e47-86a8-756dcbfab639 send: 132B guuid=2db09316-1b00-0000-931f-2a8fa30a0000 pid=2723->1d7bf28b-6ddb-5e47-86a8-756dcbfab639 send: 134B guuid=0c7ebc21-1b00-0000-931f-2a8fc40a0000 pid=2756->1d7bf28b-6ddb-5e47-86a8-756dcbfab639 send: 133B guuid=c30a2b2a-1b00-0000-931f-2a8fd90a0000 pid=2777->1d7bf28b-6ddb-5e47-86a8-756dcbfab639 send: 132B guuid=cdb7642f-1b00-0000-931f-2a8fea0a0000 pid=2794->1d7bf28b-6ddb-5e47-86a8-756dcbfab639 send: 132B guuid=2964d132-1b00-0000-931f-2a8ff50a0000 pid=2805->1d7bf28b-6ddb-5e47-86a8-756dcbfab639 send: 133B guuid=f52c5138-1b00-0000-931f-2a8f030b0000 pid=2819->1d7bf28b-6ddb-5e47-86a8-756dcbfab639 send: 131B guuid=40fa323d-1b00-0000-931f-2a8f130b0000 pid=2835->1d7bf28b-6ddb-5e47-86a8-756dcbfab639 send: 132B guuid=0b772541-1b00-0000-931f-2a8f1f0b0000 pid=2847->1d7bf28b-6ddb-5e47-86a8-756dcbfab639 send: 131B guuid=d4d03148-1b00-0000-931f-2a8f2e0b0000 pid=2862->1d7bf28b-6ddb-5e47-86a8-756dcbfab639 send: 133B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-05-17 16:40:46 UTC
File Type:
Text (Shell)
AV detection:
17 of 24 (70.83%)
Threat level:
  3/5
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

DDoSAgent

sh 1ce808d1d4bb89ecd9c2eb1932c1dad00de80978d13f358a4ea18f5e7074e88e

(this sample)

  
Delivery method
Distributed via web download

Comments