MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2d30a676418067e897f1b9989d059ca80f1baa9a95ef0d74fad3cab8021ae45c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: 2d30a676418067e897f1b9989d059ca80f1baa9a95ef0d74fad3cab8021ae45c
SHA3-384 hash: 27804feee00ab42a50207e2beef5b0a74e43e4149cc46e7cc6b2629488d21dfd594b73e41f2d4e09849a8889ce670af2
SHA1 hash: f1b22cdca01e14245fd35102c38af677abfa6362
MD5 hash: b1ca6a478d635a695c09b1940c84da39
humanhash: march-venus-coffee-xray
File name:1.sh
Download: download sample
File size:3'284 bytes
First seen:2026-01-21 22:31:21 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:ItahrhisahChBahdhPahqhlTahIhosahAhNahBLhBnJah/hfLahYhD1LahPLhPNy:ie/UL1JqjJOFLyJXN3ML2hY
TLSH T1CD617E8520424BB02C7D8F23A3AD4678B583E4F65CDF7F05E5EEA9E888ACD56F051742
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.67.244.205/windyloveyou/windy.x86n/an/aelf ua-wget
http://103.67.244.205/windyloveyou/windy.mipsn/an/aelf ua-wget
http://103.67.244.205/windyloveyou/windy.arcn/an/aelf ua-wget
http://103.67.244.205/windyloveyou/windy.i468n/an/aelf ua-wget
http://103.67.244.205/windyloveyou/windy.i686n/an/aelf ua-wget
http://103.67.244.205/windyloveyou/windy.x86_64n/an/aelf ua-wget
http://103.67.244.205/windyloveyou/windy.mpsln/an/aelf ua-wget
http://103.67.244.205/windyloveyou/windy.armn/an/aelf ua-wget
http://103.67.244.205/windyloveyou/windy.arm5n/an/aelf ua-wget
http://103.67.244.205/windyloveyou/windy.arm6n/an/aelf ua-wget
http://103.67.244.205/windyloveyou/windy.arm7n/an/aelf ua-wget
http://103.67.244.205/windyloveyou/windy.ppcn/an/aelf ua-wget
http://103.67.244.205/windyloveyou/windy.spcn/an/aelf ua-wget
http://103.67.244.205/windyloveyou/windy.m68kn/an/aelf ua-wget
http://103.67.244.205/windyloveyou/windy.sh4n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
31
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-21T15:18:00Z UTC
Last seen:
2026-01-22T12:54:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=b62488cd-2200-0000-1ded-39225d080000 pid=2141 /usr/bin/sudo guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147 /tmp/sample.bin guuid=b62488cd-2200-0000-1ded-39225d080000 pid=2141->guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147 execve guuid=04b12cd0-2200-0000-1ded-392265080000 pid=2149 /usr/bin/cp guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=04b12cd0-2200-0000-1ded-392265080000 pid=2149 execve guuid=a65962d6-2200-0000-1ded-392273080000 pid=2163 /usr/bin/wget net send-data guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=a65962d6-2200-0000-1ded-392273080000 pid=2163 execve guuid=e57254f1-2200-0000-1ded-3922bb080000 pid=2235 /usr/bin/curl net send-data write-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=e57254f1-2200-0000-1ded-3922bb080000 pid=2235 execve guuid=d07e9b0c-2300-0000-1ded-3922ed080000 pid=2285 /usr/bin/chmod guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=d07e9b0c-2300-0000-1ded-3922ed080000 pid=2285 execve guuid=bbe7fd0c-2300-0000-1ded-3922ee080000 pid=2286 /usr/bin/bash guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=bbe7fd0c-2300-0000-1ded-3922ee080000 pid=2286 clone guuid=234f2c0d-2300-0000-1ded-3922ef080000 pid=2287 /usr/bin/rm delete-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=234f2c0d-2300-0000-1ded-3922ef080000 pid=2287 execve guuid=64d7ac0d-2300-0000-1ded-3922f2080000 pid=2290 /usr/bin/wget net send-data guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=64d7ac0d-2300-0000-1ded-3922f2080000 pid=2290 execve guuid=e8e52e24-2300-0000-1ded-392228090000 pid=2344 /usr/bin/curl net send-data write-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=e8e52e24-2300-0000-1ded-392228090000 pid=2344 execve guuid=0e030c3c-2300-0000-1ded-392269090000 pid=2409 /usr/bin/chmod guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=0e030c3c-2300-0000-1ded-392269090000 pid=2409 execve guuid=3d976a3c-2300-0000-1ded-39226b090000 pid=2411 /usr/bin/bash guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=3d976a3c-2300-0000-1ded-39226b090000 pid=2411 clone guuid=2754a33c-2300-0000-1ded-39226c090000 pid=2412 /usr/bin/rm delete-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=2754a33c-2300-0000-1ded-39226c090000 pid=2412 execve guuid=7646ee3c-2300-0000-1ded-39226e090000 pid=2414 /usr/bin/wget net send-data guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=7646ee3c-2300-0000-1ded-39226e090000 pid=2414 execve guuid=0ea68653-2300-0000-1ded-3922ab090000 pid=2475 /usr/bin/curl net send-data write-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=0ea68653-2300-0000-1ded-3922ab090000 pid=2475 execve guuid=e93e776b-2300-0000-1ded-3922ee090000 pid=2542 /usr/bin/chmod guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=e93e776b-2300-0000-1ded-3922ee090000 pid=2542 execve guuid=49a0bf6b-2300-0000-1ded-3922ef090000 pid=2543 /usr/bin/bash guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=49a0bf6b-2300-0000-1ded-3922ef090000 pid=2543 clone guuid=5ab3026c-2300-0000-1ded-3922f1090000 pid=2545 /usr/bin/rm delete-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=5ab3026c-2300-0000-1ded-3922f1090000 pid=2545 execve guuid=f8d6586c-2300-0000-1ded-3922f3090000 pid=2547 /usr/bin/wget net send-data guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=f8d6586c-2300-0000-1ded-3922f3090000 pid=2547 execve guuid=b318d682-2300-0000-1ded-3922320a0000 pid=2610 /usr/bin/curl net send-data write-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=b318d682-2300-0000-1ded-3922320a0000 pid=2610 execve guuid=a2ac109b-2300-0000-1ded-39226e0a0000 pid=2670 /usr/bin/chmod guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=a2ac109b-2300-0000-1ded-39226e0a0000 pid=2670 execve guuid=3e707d9b-2300-0000-1ded-3922700a0000 pid=2672 /usr/bin/bash guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=3e707d9b-2300-0000-1ded-3922700a0000 pid=2672 clone guuid=d569c19b-2300-0000-1ded-3922710a0000 pid=2673 /usr/bin/rm delete-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=d569c19b-2300-0000-1ded-3922710a0000 pid=2673 execve guuid=84b13b9c-2300-0000-1ded-3922730a0000 pid=2675 /usr/bin/wget net send-data guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=84b13b9c-2300-0000-1ded-3922730a0000 pid=2675 execve guuid=dcd07fb5-2300-0000-1ded-3922be0a0000 pid=2750 /usr/bin/curl net send-data write-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=dcd07fb5-2300-0000-1ded-3922be0a0000 pid=2750 execve guuid=9e4b61cc-2300-0000-1ded-3922ec0a0000 pid=2796 /usr/bin/chmod guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=9e4b61cc-2300-0000-1ded-3922ec0a0000 pid=2796 execve guuid=c43cc9cc-2300-0000-1ded-3922ee0a0000 pid=2798 /usr/bin/bash guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=c43cc9cc-2300-0000-1ded-3922ee0a0000 pid=2798 clone guuid=51cbffcc-2300-0000-1ded-3922ef0a0000 pid=2799 /usr/bin/rm delete-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=51cbffcc-2300-0000-1ded-3922ef0a0000 pid=2799 execve guuid=0fd875cd-2300-0000-1ded-3922f20a0000 pid=2802 /usr/bin/wget net send-data guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=0fd875cd-2300-0000-1ded-3922f20a0000 pid=2802 execve guuid=9ce98fe4-2300-0000-1ded-3922070b0000 pid=2823 /usr/bin/curl net send-data write-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=9ce98fe4-2300-0000-1ded-3922070b0000 pid=2823 execve guuid=3a73e3fc-2300-0000-1ded-39223a0b0000 pid=2874 /usr/bin/chmod guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=3a73e3fc-2300-0000-1ded-39223a0b0000 pid=2874 execve guuid=a2f349fd-2300-0000-1ded-39223c0b0000 pid=2876 /usr/bin/bash guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=a2f349fd-2300-0000-1ded-39223c0b0000 pid=2876 clone guuid=4ead77fd-2300-0000-1ded-39223d0b0000 pid=2877 /usr/bin/rm delete-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=4ead77fd-2300-0000-1ded-39223d0b0000 pid=2877 execve guuid=8bbef2fd-2300-0000-1ded-39223f0b0000 pid=2879 /usr/bin/wget net send-data guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=8bbef2fd-2300-0000-1ded-39223f0b0000 pid=2879 execve guuid=d637ba14-2400-0000-1ded-39227b0b0000 pid=2939 /usr/bin/curl net send-data write-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=d637ba14-2400-0000-1ded-39227b0b0000 pid=2939 execve guuid=348c4d2e-2400-0000-1ded-39229e0b0000 pid=2974 /usr/bin/chmod guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=348c4d2e-2400-0000-1ded-39229e0b0000 pid=2974 execve guuid=15259e2e-2400-0000-1ded-3922a00b0000 pid=2976 /usr/bin/bash guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=15259e2e-2400-0000-1ded-3922a00b0000 pid=2976 clone guuid=6aa5c02e-2400-0000-1ded-3922a20b0000 pid=2978 /usr/bin/rm delete-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=6aa5c02e-2400-0000-1ded-3922a20b0000 pid=2978 execve guuid=31442b2f-2400-0000-1ded-3922a40b0000 pid=2980 /usr/bin/wget net send-data guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=31442b2f-2400-0000-1ded-3922a40b0000 pid=2980 execve guuid=ee095545-2400-0000-1ded-3922d10b0000 pid=3025 /usr/bin/curl net send-data write-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=ee095545-2400-0000-1ded-3922d10b0000 pid=3025 execve guuid=8819725e-2400-0000-1ded-3922170c0000 pid=3095 /usr/bin/chmod guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=8819725e-2400-0000-1ded-3922170c0000 pid=3095 execve guuid=e131ef5e-2400-0000-1ded-3922190c0000 pid=3097 /usr/bin/bash guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=e131ef5e-2400-0000-1ded-3922190c0000 pid=3097 clone guuid=54f8215f-2400-0000-1ded-39221a0c0000 pid=3098 /usr/bin/rm delete-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=54f8215f-2400-0000-1ded-39221a0c0000 pid=3098 execve guuid=b1236d5f-2400-0000-1ded-39221c0c0000 pid=3100 /usr/bin/wget net send-data guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=b1236d5f-2400-0000-1ded-39221c0c0000 pid=3100 execve guuid=0fe7fc75-2400-0000-1ded-39225a0c0000 pid=3162 /usr/bin/curl net send-data write-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=0fe7fc75-2400-0000-1ded-39225a0c0000 pid=3162 execve guuid=3e6fba8d-2400-0000-1ded-3922910c0000 pid=3217 /usr/bin/chmod guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=3e6fba8d-2400-0000-1ded-3922910c0000 pid=3217 execve guuid=8d8b1f8e-2400-0000-1ded-3922920c0000 pid=3218 /usr/bin/bash guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=8d8b1f8e-2400-0000-1ded-3922920c0000 pid=3218 clone guuid=d358588e-2400-0000-1ded-3922930c0000 pid=3219 /usr/bin/rm delete-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=d358588e-2400-0000-1ded-3922930c0000 pid=3219 execve guuid=a00d0d8f-2400-0000-1ded-3922940c0000 pid=3220 /usr/bin/wget net send-data guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=a00d0d8f-2400-0000-1ded-3922940c0000 pid=3220 execve guuid=bb7992a6-2400-0000-1ded-3922aa0c0000 pid=3242 /usr/bin/curl net send-data write-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=bb7992a6-2400-0000-1ded-3922aa0c0000 pid=3242 execve guuid=662d39be-2400-0000-1ded-3922c10c0000 pid=3265 /usr/bin/chmod guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=662d39be-2400-0000-1ded-3922c10c0000 pid=3265 execve guuid=58c2a0be-2400-0000-1ded-3922c30c0000 pid=3267 /usr/bin/bash guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=58c2a0be-2400-0000-1ded-3922c30c0000 pid=3267 clone guuid=c961e3be-2400-0000-1ded-3922c40c0000 pid=3268 /usr/bin/rm delete-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=c961e3be-2400-0000-1ded-3922c40c0000 pid=3268 execve guuid=fb9c60bf-2400-0000-1ded-3922c50c0000 pid=3269 /usr/bin/wget net send-data guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=fb9c60bf-2400-0000-1ded-3922c50c0000 pid=3269 execve guuid=3e4d77d6-2400-0000-1ded-3922e10c0000 pid=3297 /usr/bin/curl net send-data write-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=3e4d77d6-2400-0000-1ded-3922e10c0000 pid=3297 execve guuid=ba82faef-2400-0000-1ded-3922060d0000 pid=3334 /usr/bin/chmod guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=ba82faef-2400-0000-1ded-3922060d0000 pid=3334 execve guuid=4ad56bf0-2400-0000-1ded-3922080d0000 pid=3336 /usr/bin/bash guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=4ad56bf0-2400-0000-1ded-3922080d0000 pid=3336 clone guuid=d7a099f0-2400-0000-1ded-3922090d0000 pid=3337 /usr/bin/rm delete-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=d7a099f0-2400-0000-1ded-3922090d0000 pid=3337 execve guuid=2876e2f0-2400-0000-1ded-39220b0d0000 pid=3339 /usr/bin/wget net send-data guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=2876e2f0-2400-0000-1ded-39220b0d0000 pid=3339 execve guuid=1484e106-2500-0000-1ded-3922340d0000 pid=3380 /usr/bin/curl net send-data write-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=1484e106-2500-0000-1ded-3922340d0000 pid=3380 execve guuid=42adf520-2500-0000-1ded-39225a0d0000 pid=3418 /usr/bin/chmod guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=42adf520-2500-0000-1ded-39225a0d0000 pid=3418 execve guuid=5a3f5d21-2500-0000-1ded-39225b0d0000 pid=3419 /usr/bin/bash guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=5a3f5d21-2500-0000-1ded-39225b0d0000 pid=3419 clone guuid=71a08821-2500-0000-1ded-39225c0d0000 pid=3420 /usr/bin/rm delete-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=71a08821-2500-0000-1ded-39225c0d0000 pid=3420 execve guuid=24b6da21-2500-0000-1ded-39225d0d0000 pid=3421 /usr/bin/wget net send-data guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=24b6da21-2500-0000-1ded-39225d0d0000 pid=3421 execve guuid=dad75d38-2500-0000-1ded-3922910d0000 pid=3473 /usr/bin/curl net send-data write-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=dad75d38-2500-0000-1ded-3922910d0000 pid=3473 execve guuid=dc7f9250-2500-0000-1ded-3922d00d0000 pid=3536 /usr/bin/chmod guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=dc7f9250-2500-0000-1ded-3922d00d0000 pid=3536 execve guuid=06ece350-2500-0000-1ded-3922d20d0000 pid=3538 /usr/bin/bash guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=06ece350-2500-0000-1ded-3922d20d0000 pid=3538 clone guuid=d5b96a51-2500-0000-1ded-3922d30d0000 pid=3539 /usr/bin/rm delete-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=d5b96a51-2500-0000-1ded-3922d30d0000 pid=3539 execve guuid=82b1c251-2500-0000-1ded-3922d50d0000 pid=3541 /usr/bin/wget net send-data guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=82b1c251-2500-0000-1ded-3922d50d0000 pid=3541 execve guuid=11c4fc68-2500-0000-1ded-3922f70d0000 pid=3575 /usr/bin/curl net send-data write-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=11c4fc68-2500-0000-1ded-3922f70d0000 pid=3575 execve guuid=13159c82-2500-0000-1ded-3922280e0000 pid=3624 /usr/bin/chmod guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=13159c82-2500-0000-1ded-3922280e0000 pid=3624 execve guuid=1931e582-2500-0000-1ded-3922290e0000 pid=3625 /usr/bin/bash guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=1931e582-2500-0000-1ded-3922290e0000 pid=3625 clone guuid=b3ca1283-2500-0000-1ded-39222b0e0000 pid=3627 /usr/bin/rm delete-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=b3ca1283-2500-0000-1ded-39222b0e0000 pid=3627 execve guuid=ce0b4e84-2500-0000-1ded-39222d0e0000 pid=3629 /usr/bin/wget net send-data guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=ce0b4e84-2500-0000-1ded-39222d0e0000 pid=3629 execve guuid=1677179b-2500-0000-1ded-3922590e0000 pid=3673 /usr/bin/curl net send-data write-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=1677179b-2500-0000-1ded-3922590e0000 pid=3673 execve guuid=fce1f5b3-2500-0000-1ded-39229d0e0000 pid=3741 /usr/bin/chmod guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=fce1f5b3-2500-0000-1ded-39229d0e0000 pid=3741 execve guuid=05004ab4-2500-0000-1ded-39229e0e0000 pid=3742 /usr/bin/bash guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=05004ab4-2500-0000-1ded-39229e0e0000 pid=3742 clone guuid=870d89b4-2500-0000-1ded-3922a00e0000 pid=3744 /usr/bin/rm delete-file guuid=4f4c5bcf-2200-0000-1ded-392263080000 pid=2147->guuid=870d89b4-2500-0000-1ded-3922a00e0000 pid=3744 execve 76fd86ba-991a-547a-b992-1ee91e852bd6 103.67.244.205:80 guuid=a65962d6-2200-0000-1ded-392273080000 pid=2163->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 151B guuid=e57254f1-2200-0000-1ded-3922bb080000 pid=2235->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 100B guuid=64d7ac0d-2300-0000-1ded-3922f2080000 pid=2290->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 152B guuid=e8e52e24-2300-0000-1ded-392228090000 pid=2344->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 101B guuid=7646ee3c-2300-0000-1ded-39226e090000 pid=2414->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 151B guuid=0ea68653-2300-0000-1ded-3922ab090000 pid=2475->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 100B guuid=f8d6586c-2300-0000-1ded-3922f3090000 pid=2547->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 152B guuid=b318d682-2300-0000-1ded-3922320a0000 pid=2610->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 101B guuid=84b13b9c-2300-0000-1ded-3922730a0000 pid=2675->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 152B guuid=dcd07fb5-2300-0000-1ded-3922be0a0000 pid=2750->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 101B guuid=0fd875cd-2300-0000-1ded-3922f20a0000 pid=2802->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 154B guuid=9ce98fe4-2300-0000-1ded-3922070b0000 pid=2823->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 103B guuid=8bbef2fd-2300-0000-1ded-39223f0b0000 pid=2879->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 152B guuid=d637ba14-2400-0000-1ded-39227b0b0000 pid=2939->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 101B guuid=31442b2f-2400-0000-1ded-3922a40b0000 pid=2980->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 151B guuid=ee095545-2400-0000-1ded-3922d10b0000 pid=3025->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 100B guuid=b1236d5f-2400-0000-1ded-39221c0c0000 pid=3100->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 152B guuid=0fe7fc75-2400-0000-1ded-39225a0c0000 pid=3162->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 101B guuid=a00d0d8f-2400-0000-1ded-3922940c0000 pid=3220->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 152B guuid=bb7992a6-2400-0000-1ded-3922aa0c0000 pid=3242->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 101B guuid=fb9c60bf-2400-0000-1ded-3922c50c0000 pid=3269->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 152B guuid=3e4d77d6-2400-0000-1ded-3922e10c0000 pid=3297->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 101B guuid=2876e2f0-2400-0000-1ded-39220b0d0000 pid=3339->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 151B guuid=1484e106-2500-0000-1ded-3922340d0000 pid=3380->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 100B guuid=24b6da21-2500-0000-1ded-39225d0d0000 pid=3421->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 151B guuid=dad75d38-2500-0000-1ded-3922910d0000 pid=3473->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 100B guuid=82b1c251-2500-0000-1ded-3922d50d0000 pid=3541->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 152B guuid=11c4fc68-2500-0000-1ded-3922f70d0000 pid=3575->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 101B guuid=ce0b4e84-2500-0000-1ded-39222d0e0000 pid=3629->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 151B guuid=1677179b-2500-0000-1ded-3922590e0000 pid=3673->76fd86ba-991a-547a-b992-1ee91e852bd6 send: 100B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-01-21 19:22:04 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 2d30a676418067e897f1b9989d059ca80f1baa9a95ef0d74fad3cab8021ae45c

(this sample)

  
Delivery method
Distributed via web download

Comments