MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5f7720e307f1bbad9eff1f864cff714f5af0ab268e149da0cbc8695033ebcf64. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: 5f7720e307f1bbad9eff1f864cff714f5af0ab268e149da0cbc8695033ebcf64
SHA3-384 hash: b2177cdbbbafae04a0129be4bc34410c1750fbc07a3cc5d8a3690f87d2b5d300b31c42d7c3cae8d1856398513ddb422a
SHA1 hash: 477dbdd8de9c1a7d839a0feb244ec3f4930bf331
MD5 hash: 8fa71c049649a56bf904a81bdfed1de5
humanhash: asparagus-lake-magnesium-floor
File name:Pandora.sh
Download: download sample
File size:2'043 bytes
First seen:2026-08-04 06:38:35 UTC
Last seen:2026-08-04 10:59:59 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:v7X5Xe7XsXPo7XaEX+7XhnXhVZ0h7Xh8XheH7XhRXhpG7Xh+XhAV7X6XO7XFX27W:v7X5Xe7XsXQ7XhX+7XBX+h7XuXw7XXXu
TLSH T16B4164E6374109F66EE99DB272E50204F08551E73BC42ED8D4EC34B7A48CED875C4A6B
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://180.93.116.41/Pandoras_Box/pandora.x86n/an/acensys elf ua-wget
http://180.93.116.41/Pandoras_Box/pandora.mipsn/an/acensys elf ua-wget
http://180.93.116.41/Pandoras_Box/pandora.mpsln/an/acensys elf ua-wget
http://180.93.116.41/Pandoras_Box/pandora.arm4n/an/acensys elf ua-wget
http://180.93.116.41/Pandoras_Box/pandora.arm5n/an/acensys elf ua-wget
http://180.93.116.41/Pandoras_Box/pandora.arm6n/an/acensys elf ua-wget
http://180.93.116.41/Pandoras_Box/pandora.arm7n/an/acensys elf ua-wget
http://180.93.116.41/Pandoras_Box/pandora.ppcn/an/acensys elf ua-wget
http://180.93.116.41/Pandoras_Box/pandora.m68kn/an/acensys elf ua-wget
http://180.93.116.41/Pandoras_Box/pandora.sh4n/an/acensys elf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
62
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-08-04T03:44:00Z UTC
Last seen:
2026-08-04T12:58:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=60d15b2a-1a00-0000-7be3-2900cf070000 pid=1999 /usr/bin/sudo guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011 /tmp/sample.bin guuid=60d15b2a-1a00-0000-7be3-2900cf070000 pid=1999->guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011 execve guuid=ffbd113e-1a00-0000-7be3-2900e2070000 pid=2018 /usr/bin/wget net send-data guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=ffbd113e-1a00-0000-7be3-2900e2070000 pid=2018 execve guuid=a21a2661-1a00-0000-7be3-290010080000 pid=2064 /usr/bin/curl net send-data write-file guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=a21a2661-1a00-0000-7be3-290010080000 pid=2064 execve guuid=58aee591-1a00-0000-7be3-29004a080000 pid=2122 /usr/bin/cat guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=58aee591-1a00-0000-7be3-29004a080000 pid=2122 execve guuid=9fcf7e92-1a00-0000-7be3-29004c080000 pid=2124 /usr/bin/chmod guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=9fcf7e92-1a00-0000-7be3-29004c080000 pid=2124 execve guuid=72683293-1a00-0000-7be3-29004d080000 pid=2125 /usr/bin/bash guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=72683293-1a00-0000-7be3-29004d080000 pid=2125 clone guuid=256f7293-1a00-0000-7be3-29004f080000 pid=2127 /usr/bin/wget net send-data guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=256f7293-1a00-0000-7be3-29004f080000 pid=2127 execve guuid=12e98bb2-1a00-0000-7be3-290069080000 pid=2153 /usr/bin/curl net send-data write-file guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=12e98bb2-1a00-0000-7be3-290069080000 pid=2153 execve guuid=abb8aeda-1a00-0000-7be3-290087080000 pid=2183 /usr/bin/cat guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=abb8aeda-1a00-0000-7be3-290087080000 pid=2183 execve guuid=cf63b6db-1a00-0000-7be3-290089080000 pid=2185 /usr/bin/chmod guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=cf63b6db-1a00-0000-7be3-290089080000 pid=2185 execve guuid=e6b76fdc-1a00-0000-7be3-29008c080000 pid=2188 /usr/bin/bash guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=e6b76fdc-1a00-0000-7be3-29008c080000 pid=2188 clone guuid=445b22dd-1a00-0000-7be3-29008e080000 pid=2190 /usr/bin/wget net send-data guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=445b22dd-1a00-0000-7be3-29008e080000 pid=2190 execve guuid=513f52fc-1a00-0000-7be3-2900aa080000 pid=2218 /usr/bin/curl net send-data write-file guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=513f52fc-1a00-0000-7be3-2900aa080000 pid=2218 execve guuid=c884bc1d-1b00-0000-7be3-2900c6080000 pid=2246 /usr/bin/cat guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=c884bc1d-1b00-0000-7be3-2900c6080000 pid=2246 execve guuid=8350e91e-1b00-0000-7be3-2900c7080000 pid=2247 /usr/bin/chmod guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=8350e91e-1b00-0000-7be3-2900c7080000 pid=2247 execve guuid=94807b1f-1b00-0000-7be3-2900c8080000 pid=2248 /usr/bin/bash guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=94807b1f-1b00-0000-7be3-2900c8080000 pid=2248 clone guuid=fddae31f-1b00-0000-7be3-2900ca080000 pid=2250 /usr/bin/wget net send-data guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=fddae31f-1b00-0000-7be3-2900ca080000 pid=2250 execve guuid=8b66b73e-1b00-0000-7be3-2900ef080000 pid=2287 /usr/bin/curl net send-data write-file guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=8b66b73e-1b00-0000-7be3-2900ef080000 pid=2287 execve guuid=66b71263-1b00-0000-7be3-290010090000 pid=2320 /usr/bin/cat guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=66b71263-1b00-0000-7be3-290010090000 pid=2320 execve guuid=415f0464-1b00-0000-7be3-290013090000 pid=2323 /usr/bin/chmod guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=415f0464-1b00-0000-7be3-290013090000 pid=2323 execve guuid=81430265-1b00-0000-7be3-290015090000 pid=2325 /usr/bin/bash guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=81430265-1b00-0000-7be3-290015090000 pid=2325 clone guuid=de7dca65-1b00-0000-7be3-290017090000 pid=2327 /usr/bin/wget net send-data guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=de7dca65-1b00-0000-7be3-290017090000 pid=2327 execve guuid=ec75c984-1b00-0000-7be3-290038090000 pid=2360 /usr/bin/curl net send-data write-file guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=ec75c984-1b00-0000-7be3-290038090000 pid=2360 execve guuid=7921d6a6-1b00-0000-7be3-29005c090000 pid=2396 /usr/bin/cat guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=7921d6a6-1b00-0000-7be3-29005c090000 pid=2396 execve guuid=a97fb2a7-1b00-0000-7be3-29005d090000 pid=2397 /usr/bin/chmod guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=a97fb2a7-1b00-0000-7be3-29005d090000 pid=2397 execve guuid=0c3e6fa8-1b00-0000-7be3-29005f090000 pid=2399 /usr/bin/bash guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=0c3e6fa8-1b00-0000-7be3-29005f090000 pid=2399 clone guuid=a48ed1a8-1b00-0000-7be3-290060090000 pid=2400 /usr/bin/wget net send-data guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=a48ed1a8-1b00-0000-7be3-290060090000 pid=2400 execve guuid=228f90c7-1b00-0000-7be3-290081090000 pid=2433 /usr/bin/curl net send-data write-file guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=228f90c7-1b00-0000-7be3-290081090000 pid=2433 execve guuid=cf1b0beb-1b00-0000-7be3-290082090000 pid=2434 /usr/bin/cat guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=cf1b0beb-1b00-0000-7be3-290082090000 pid=2434 execve guuid=c7097ef6-1b00-0000-7be3-29008e090000 pid=2446 /usr/bin/chmod guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=c7097ef6-1b00-0000-7be3-29008e090000 pid=2446 execve guuid=a0ec46f7-1b00-0000-7be3-29008f090000 pid=2447 /usr/bin/bash guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=a0ec46f7-1b00-0000-7be3-29008f090000 pid=2447 clone guuid=a8a392f7-1b00-0000-7be3-290090090000 pid=2448 /usr/bin/wget net send-data guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=a8a392f7-1b00-0000-7be3-290090090000 pid=2448 execve guuid=996eb016-1c00-0000-7be3-2900cc090000 pid=2508 /usr/bin/curl net send-data write-file guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=996eb016-1c00-0000-7be3-2900cc090000 pid=2508 execve guuid=0827e836-1c00-0000-7be3-2900090a0000 pid=2569 /usr/bin/cat guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=0827e836-1c00-0000-7be3-2900090a0000 pid=2569 execve guuid=354e4837-1c00-0000-7be3-29000b0a0000 pid=2571 /usr/bin/chmod guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=354e4837-1c00-0000-7be3-29000b0a0000 pid=2571 execve guuid=fe10ac37-1c00-0000-7be3-29000d0a0000 pid=2573 /usr/bin/bash guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=fe10ac37-1c00-0000-7be3-29000d0a0000 pid=2573 clone guuid=8733e437-1c00-0000-7be3-29000e0a0000 pid=2574 /usr/bin/wget net send-data guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=8733e437-1c00-0000-7be3-29000e0a0000 pid=2574 execve guuid=66398f55-1c00-0000-7be3-2900420a0000 pid=2626 /usr/bin/curl net send-data write-file guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=66398f55-1c00-0000-7be3-2900420a0000 pid=2626 execve guuid=11851276-1c00-0000-7be3-2900630a0000 pid=2659 /usr/bin/cat guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=11851276-1c00-0000-7be3-2900630a0000 pid=2659 execve guuid=57eede76-1c00-0000-7be3-2900650a0000 pid=2661 /usr/bin/chmod guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=57eede76-1c00-0000-7be3-2900650a0000 pid=2661 execve guuid=725c9477-1c00-0000-7be3-2900670a0000 pid=2663 /usr/bin/bash guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=725c9477-1c00-0000-7be3-2900670a0000 pid=2663 clone guuid=5000de77-1c00-0000-7be3-2900680a0000 pid=2664 /usr/bin/wget net send-data guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=5000de77-1c00-0000-7be3-2900680a0000 pid=2664 execve guuid=17a1a697-1c00-0000-7be3-2900870a0000 pid=2695 /usr/bin/curl net send-data write-file guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=17a1a697-1c00-0000-7be3-2900870a0000 pid=2695 execve guuid=9a97ebb7-1c00-0000-7be3-2900a80a0000 pid=2728 /usr/bin/cat guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=9a97ebb7-1c00-0000-7be3-2900a80a0000 pid=2728 execve guuid=a40479b9-1c00-0000-7be3-2900aa0a0000 pid=2730 /usr/bin/chmod guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=a40479b9-1c00-0000-7be3-2900aa0a0000 pid=2730 execve guuid=820817ba-1c00-0000-7be3-2900ac0a0000 pid=2732 /usr/bin/bash guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=820817ba-1c00-0000-7be3-2900ac0a0000 pid=2732 clone guuid=f42458ba-1c00-0000-7be3-2900ae0a0000 pid=2734 /usr/bin/wget net send-data guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=f42458ba-1c00-0000-7be3-2900ae0a0000 pid=2734 execve guuid=fa613dd8-1c00-0000-7be3-2900d10a0000 pid=2769 /usr/bin/curl net send-data write-file guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=fa613dd8-1c00-0000-7be3-2900d10a0000 pid=2769 execve guuid=97465bf9-1c00-0000-7be3-2900fb0a0000 pid=2811 /usr/bin/cat guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=97465bf9-1c00-0000-7be3-2900fb0a0000 pid=2811 execve guuid=7903f4f9-1c00-0000-7be3-2900fd0a0000 pid=2813 /usr/bin/chmod guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=7903f4f9-1c00-0000-7be3-2900fd0a0000 pid=2813 execve guuid=7e8dc4fa-1c00-0000-7be3-2900ff0a0000 pid=2815 /usr/bin/bash guuid=496ded3a-1a00-0000-7be3-2900db070000 pid=2011->guuid=7e8dc4fa-1c00-0000-7be3-2900ff0a0000 pid=2815 clone b54d4afd-a5fb-553b-83c1-09d73c60263b 180.93.116.41:80 guuid=ffbd113e-1a00-0000-7be3-2900e2070000 pid=2018->b54d4afd-a5fb-553b-83c1-09d73c60263b send: 152B guuid=a21a2661-1a00-0000-7be3-290010080000 pid=2064->b54d4afd-a5fb-553b-83c1-09d73c60263b send: 101B guuid=256f7293-1a00-0000-7be3-29004f080000 pid=2127->b54d4afd-a5fb-553b-83c1-09d73c60263b send: 153B guuid=12e98bb2-1a00-0000-7be3-290069080000 pid=2153->b54d4afd-a5fb-553b-83c1-09d73c60263b send: 102B guuid=445b22dd-1a00-0000-7be3-29008e080000 pid=2190->b54d4afd-a5fb-553b-83c1-09d73c60263b send: 153B guuid=513f52fc-1a00-0000-7be3-2900aa080000 pid=2218->b54d4afd-a5fb-553b-83c1-09d73c60263b send: 102B guuid=fddae31f-1b00-0000-7be3-2900ca080000 pid=2250->b54d4afd-a5fb-553b-83c1-09d73c60263b send: 153B guuid=8b66b73e-1b00-0000-7be3-2900ef080000 pid=2287->b54d4afd-a5fb-553b-83c1-09d73c60263b send: 102B guuid=de7dca65-1b00-0000-7be3-290017090000 pid=2327->b54d4afd-a5fb-553b-83c1-09d73c60263b send: 153B guuid=ec75c984-1b00-0000-7be3-290038090000 pid=2360->b54d4afd-a5fb-553b-83c1-09d73c60263b send: 102B guuid=a48ed1a8-1b00-0000-7be3-290060090000 pid=2400->b54d4afd-a5fb-553b-83c1-09d73c60263b send: 153B guuid=228f90c7-1b00-0000-7be3-290081090000 pid=2433->b54d4afd-a5fb-553b-83c1-09d73c60263b send: 102B guuid=a8a392f7-1b00-0000-7be3-290090090000 pid=2448->b54d4afd-a5fb-553b-83c1-09d73c60263b send: 153B guuid=996eb016-1c00-0000-7be3-2900cc090000 pid=2508->b54d4afd-a5fb-553b-83c1-09d73c60263b send: 102B guuid=8733e437-1c00-0000-7be3-29000e0a0000 pid=2574->b54d4afd-a5fb-553b-83c1-09d73c60263b send: 152B guuid=66398f55-1c00-0000-7be3-2900420a0000 pid=2626->b54d4afd-a5fb-553b-83c1-09d73c60263b send: 101B guuid=5000de77-1c00-0000-7be3-2900680a0000 pid=2664->b54d4afd-a5fb-553b-83c1-09d73c60263b send: 153B guuid=17a1a697-1c00-0000-7be3-2900870a0000 pid=2695->b54d4afd-a5fb-553b-83c1-09d73c60263b send: 102B guuid=f42458ba-1c00-0000-7be3-2900ae0a0000 pid=2734->b54d4afd-a5fb-553b-83c1-09d73c60263b send: 152B guuid=fa613dd8-1c00-0000-7be3-2900d10a0000 pid=2769->b54d4afd-a5fb-553b-83c1-09d73c60263b send: 101B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-08-04 06:42:32 UTC
File Type:
Text (Shell)
AV detection:
17 of 24 (70.83%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 5f7720e307f1bbad9eff1f864cff714f5af0ab268e149da0cbc8695033ebcf64

(this sample)

  
Delivery method
Distributed via web download

Comments