MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6571d64d37801add3108b1029251a86a113b032d0347174edcd6f51de55a6e9d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: 6571d64d37801add3108b1029251a86a113b032d0347174edcd6f51de55a6e9d
SHA3-384 hash: fa50ffea9a6f6406f35970adc1c59150169da31df0c380076dcef255359758751fd2b0f4efcf52c3a5292ec830dcf9a8
SHA1 hash: 1c5de1795deab4049c91b051a8f08fc68c265d60
MD5 hash: 47155d5c20390e9c73da6b220527e96c
humanhash: zulu-minnesota-bluebird-pennsylvania
File name:1.sh
Download: download sample
File size:3'374 bytes
First seen:2026-01-17 17:33:55 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:iXXyXmkXJyX6EXUsX8YXDuX/CXkGLXByXqwXsoXxiX0q0BgJsX4ck:5vBgJ7
TLSH T18B617FFA02905D3B5CAACAD3A1F80644658158AB18CE0F714BDD2CF83E4CFC83C5AE45
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://109.104.154.249/00101010101001/morte.x86n/an/an/a
http://109.104.154.249/00101010101001/morte.mipsn/an/an/a
http://109.104.154.249/00101010101001/morte.arcn/an/an/a
http://109.104.154.249/00101010101001/morte.i468n/an/an/a
http://109.104.154.249/00101010101001/morte.i686n/an/an/a
http://109.104.154.249/00101010101001/morte.x86_64n/an/an/a
http://109.104.154.249/00101010101001/morte.mpsln/an/an/a
http://109.104.154.249/00101010101001/morte.armn/an/an/a
http://109.104.154.249/00101010101001/morte.arm5n/an/an/a
http://109.104.154.249/00101010101001/morte.arm6n/an/an/a
http://109.104.154.249/00101010101001/morte.arm7n/an/an/a
http://109.104.154.249/00101010101001/morte.ppcn/an/an/a
http://109.104.154.249/00101010101001/morte.spcn/an/an/a
http://109.104.154.249/00101010101001/morte.m68kn/an/an/a
http://109.104.154.249/00101010101001/morte.sh4n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
31
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=aea09a4d-1a00-0000-4bb1-d33b710c0000 pid=3185 /usr/bin/sudo guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193 /tmp/sample.bin guuid=aea09a4d-1a00-0000-4bb1-d33b710c0000 pid=3185->guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193 execve guuid=7ef25050-1a00-0000-4bb1-d33b7b0c0000 pid=3195 /usr/bin/cp guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=7ef25050-1a00-0000-4bb1-d33b7b0c0000 pid=3195 execve guuid=5a390755-1a00-0000-4bb1-d33b850c0000 pid=3205 /usr/bin/wget net send-data guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=5a390755-1a00-0000-4bb1-d33b850c0000 pid=3205 execve guuid=59a33559-1a00-0000-4bb1-d33b8e0c0000 pid=3214 /usr/bin/curl net send-data write-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=59a33559-1a00-0000-4bb1-d33b8e0c0000 pid=3214 execve guuid=93293a65-1a00-0000-4bb1-d33b990c0000 pid=3225 /usr/bin/chmod guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=93293a65-1a00-0000-4bb1-d33b990c0000 pid=3225 execve guuid=756ddc65-1a00-0000-4bb1-d33b9a0c0000 pid=3226 /usr/bin/bash guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=756ddc65-1a00-0000-4bb1-d33b9a0c0000 pid=3226 clone guuid=d6121e66-1a00-0000-4bb1-d33b9b0c0000 pid=3227 /usr/bin/rm delete-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=d6121e66-1a00-0000-4bb1-d33b9b0c0000 pid=3227 execve guuid=b8df9866-1a00-0000-4bb1-d33b9c0c0000 pid=3228 /usr/bin/wget net send-data guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=b8df9866-1a00-0000-4bb1-d33b9c0c0000 pid=3228 execve guuid=fe3b6969-1a00-0000-4bb1-d33b9d0c0000 pid=3229 /usr/bin/curl net send-data write-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=fe3b6969-1a00-0000-4bb1-d33b9d0c0000 pid=3229 execve guuid=f6e0dc6c-1a00-0000-4bb1-d33b9e0c0000 pid=3230 /usr/bin/chmod guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=f6e0dc6c-1a00-0000-4bb1-d33b9e0c0000 pid=3230 execve guuid=fd4a3b6d-1a00-0000-4bb1-d33b9f0c0000 pid=3231 /usr/bin/bash guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=fd4a3b6d-1a00-0000-4bb1-d33b9f0c0000 pid=3231 clone guuid=72b3716d-1a00-0000-4bb1-d33ba00c0000 pid=3232 /usr/bin/rm delete-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=72b3716d-1a00-0000-4bb1-d33ba00c0000 pid=3232 execve guuid=fc4fcd6d-1a00-0000-4bb1-d33ba10c0000 pid=3233 /usr/bin/wget net send-data guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=fc4fcd6d-1a00-0000-4bb1-d33ba10c0000 pid=3233 execve guuid=60989e70-1a00-0000-4bb1-d33ba20c0000 pid=3234 /usr/bin/curl net send-data write-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=60989e70-1a00-0000-4bb1-d33ba20c0000 pid=3234 execve guuid=f59fc975-1a00-0000-4bb1-d33ba80c0000 pid=3240 /usr/bin/chmod guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=f59fc975-1a00-0000-4bb1-d33ba80c0000 pid=3240 execve guuid=9c290d76-1a00-0000-4bb1-d33baa0c0000 pid=3242 /usr/bin/bash guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=9c290d76-1a00-0000-4bb1-d33baa0c0000 pid=3242 clone guuid=ddaf2f76-1a00-0000-4bb1-d33bac0c0000 pid=3244 /usr/bin/rm delete-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=ddaf2f76-1a00-0000-4bb1-d33bac0c0000 pid=3244 execve guuid=06dd7a76-1a00-0000-4bb1-d33bad0c0000 pid=3245 /usr/bin/wget net send-data guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=06dd7a76-1a00-0000-4bb1-d33bad0c0000 pid=3245 execve guuid=5c4bd678-1a00-0000-4bb1-d33baf0c0000 pid=3247 /usr/bin/curl net send-data write-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=5c4bd678-1a00-0000-4bb1-d33baf0c0000 pid=3247 execve guuid=2ee1887c-1a00-0000-4bb1-d33bb70c0000 pid=3255 /usr/bin/chmod guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=2ee1887c-1a00-0000-4bb1-d33bb70c0000 pid=3255 execve guuid=9a3f217d-1a00-0000-4bb1-d33bb80c0000 pid=3256 /usr/bin/bash guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=9a3f217d-1a00-0000-4bb1-d33bb80c0000 pid=3256 clone guuid=c19f507d-1a00-0000-4bb1-d33bb90c0000 pid=3257 /usr/bin/rm delete-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=c19f507d-1a00-0000-4bb1-d33bb90c0000 pid=3257 execve guuid=7dfdc57d-1a00-0000-4bb1-d33bbb0c0000 pid=3259 /usr/bin/wget net send-data guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=7dfdc57d-1a00-0000-4bb1-d33bbb0c0000 pid=3259 execve guuid=aba0d880-1a00-0000-4bb1-d33bc10c0000 pid=3265 /usr/bin/curl net send-data write-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=aba0d880-1a00-0000-4bb1-d33bc10c0000 pid=3265 execve guuid=b6ecb785-1a00-0000-4bb1-d33bc60c0000 pid=3270 /usr/bin/chmod guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=b6ecb785-1a00-0000-4bb1-d33bc60c0000 pid=3270 execve guuid=459f1086-1a00-0000-4bb1-d33bc70c0000 pid=3271 /usr/bin/bash guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=459f1086-1a00-0000-4bb1-d33bc70c0000 pid=3271 clone guuid=76933a86-1a00-0000-4bb1-d33bc90c0000 pid=3273 /usr/bin/rm delete-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=76933a86-1a00-0000-4bb1-d33bc90c0000 pid=3273 execve guuid=c1288386-1a00-0000-4bb1-d33bca0c0000 pid=3274 /usr/bin/wget net send-data guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=c1288386-1a00-0000-4bb1-d33bca0c0000 pid=3274 execve guuid=38988f88-1a00-0000-4bb1-d33bce0c0000 pid=3278 /usr/bin/curl net send-data write-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=38988f88-1a00-0000-4bb1-d33bce0c0000 pid=3278 execve guuid=21058f8b-1a00-0000-4bb1-d33bd50c0000 pid=3285 /usr/bin/chmod guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=21058f8b-1a00-0000-4bb1-d33bd50c0000 pid=3285 execve guuid=15a2fc8b-1a00-0000-4bb1-d33bd70c0000 pid=3287 /usr/bin/bash guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=15a2fc8b-1a00-0000-4bb1-d33bd70c0000 pid=3287 clone guuid=71c0288c-1a00-0000-4bb1-d33bd80c0000 pid=3288 /usr/bin/rm delete-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=71c0288c-1a00-0000-4bb1-d33bd80c0000 pid=3288 execve guuid=4ad4888c-1a00-0000-4bb1-d33bd90c0000 pid=3289 /usr/bin/wget net send-data guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=4ad4888c-1a00-0000-4bb1-d33bd90c0000 pid=3289 execve guuid=24a11090-1a00-0000-4bb1-d33be00c0000 pid=3296 /usr/bin/curl net send-data write-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=24a11090-1a00-0000-4bb1-d33be00c0000 pid=3296 execve guuid=3a153595-1a00-0000-4bb1-d33be10c0000 pid=3297 /usr/bin/chmod guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=3a153595-1a00-0000-4bb1-d33be10c0000 pid=3297 execve guuid=3b328a95-1a00-0000-4bb1-d33be30c0000 pid=3299 /usr/bin/bash guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=3b328a95-1a00-0000-4bb1-d33be30c0000 pid=3299 clone guuid=c040ef95-1a00-0000-4bb1-d33be40c0000 pid=3300 /usr/bin/rm delete-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=c040ef95-1a00-0000-4bb1-d33be40c0000 pid=3300 execve guuid=867fae96-1a00-0000-4bb1-d33be50c0000 pid=3301 /usr/bin/wget net send-data guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=867fae96-1a00-0000-4bb1-d33be50c0000 pid=3301 execve guuid=cb37c198-1a00-0000-4bb1-d33be90c0000 pid=3305 /usr/bin/curl net send-data write-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=cb37c198-1a00-0000-4bb1-d33be90c0000 pid=3305 execve guuid=e1d77f9c-1a00-0000-4bb1-d33bf20c0000 pid=3314 /usr/bin/chmod guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=e1d77f9c-1a00-0000-4bb1-d33bf20c0000 pid=3314 execve guuid=42f7069d-1a00-0000-4bb1-d33bf40c0000 pid=3316 /usr/bin/bash guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=42f7069d-1a00-0000-4bb1-d33bf40c0000 pid=3316 clone guuid=41a85b9d-1a00-0000-4bb1-d33bf60c0000 pid=3318 /usr/bin/rm delete-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=41a85b9d-1a00-0000-4bb1-d33bf60c0000 pid=3318 execve guuid=16e8ad9d-1a00-0000-4bb1-d33bf80c0000 pid=3320 /usr/bin/wget net send-data guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=16e8ad9d-1a00-0000-4bb1-d33bf80c0000 pid=3320 execve guuid=b64c3fa1-1a00-0000-4bb1-d33b010d0000 pid=3329 /usr/bin/curl net send-data write-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=b64c3fa1-1a00-0000-4bb1-d33b010d0000 pid=3329 execve guuid=200beda7-1a00-0000-4bb1-d33b160d0000 pid=3350 /usr/bin/chmod guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=200beda7-1a00-0000-4bb1-d33b160d0000 pid=3350 execve guuid=245530a8-1a00-0000-4bb1-d33b180d0000 pid=3352 /usr/bin/bash guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=245530a8-1a00-0000-4bb1-d33b180d0000 pid=3352 clone guuid=b2a15da8-1a00-0000-4bb1-d33b190d0000 pid=3353 /usr/bin/rm delete-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=b2a15da8-1a00-0000-4bb1-d33b190d0000 pid=3353 execve guuid=2564aaa8-1a00-0000-4bb1-d33b1b0d0000 pid=3355 /usr/bin/wget net send-data guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=2564aaa8-1a00-0000-4bb1-d33b1b0d0000 pid=3355 execve guuid=666ab5aa-1a00-0000-4bb1-d33b210d0000 pid=3361 /usr/bin/curl net send-data write-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=666ab5aa-1a00-0000-4bb1-d33b210d0000 pid=3361 execve guuid=fb592bae-1a00-0000-4bb1-d33b2f0d0000 pid=3375 /usr/bin/chmod guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=fb592bae-1a00-0000-4bb1-d33b2f0d0000 pid=3375 execve guuid=d29973ae-1a00-0000-4bb1-d33b300d0000 pid=3376 /usr/bin/bash guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=d29973ae-1a00-0000-4bb1-d33b300d0000 pid=3376 clone guuid=a0d699ae-1a00-0000-4bb1-d33b310d0000 pid=3377 /usr/bin/rm delete-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=a0d699ae-1a00-0000-4bb1-d33b310d0000 pid=3377 execve guuid=d56b21af-1a00-0000-4bb1-d33b330d0000 pid=3379 /usr/bin/wget net send-data guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=d56b21af-1a00-0000-4bb1-d33b330d0000 pid=3379 execve guuid=f5371eb3-1a00-0000-4bb1-d33b390d0000 pid=3385 /usr/bin/curl net send-data write-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=f5371eb3-1a00-0000-4bb1-d33b390d0000 pid=3385 execve guuid=d89c1ab9-1a00-0000-4bb1-d33b3c0d0000 pid=3388 /usr/bin/chmod guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=d89c1ab9-1a00-0000-4bb1-d33b3c0d0000 pid=3388 execve guuid=7c687ab9-1a00-0000-4bb1-d33b3d0d0000 pid=3389 /usr/bin/bash guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=7c687ab9-1a00-0000-4bb1-d33b3d0d0000 pid=3389 clone guuid=eaa6bcb9-1a00-0000-4bb1-d33b3e0d0000 pid=3390 /usr/bin/rm delete-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=eaa6bcb9-1a00-0000-4bb1-d33b3e0d0000 pid=3390 execve guuid=6c1027ba-1a00-0000-4bb1-d33b3f0d0000 pid=3391 /usr/bin/wget net send-data guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=6c1027ba-1a00-0000-4bb1-d33b3f0d0000 pid=3391 execve guuid=1d1d0cbd-1a00-0000-4bb1-d33b420d0000 pid=3394 /usr/bin/curl net send-data write-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=1d1d0cbd-1a00-0000-4bb1-d33b420d0000 pid=3394 execve guuid=8fb20dc3-1a00-0000-4bb1-d33b530d0000 pid=3411 /usr/bin/chmod guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=8fb20dc3-1a00-0000-4bb1-d33b530d0000 pid=3411 execve guuid=33295bc3-1a00-0000-4bb1-d33b550d0000 pid=3413 /usr/bin/bash guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=33295bc3-1a00-0000-4bb1-d33b550d0000 pid=3413 clone guuid=de3d88c3-1a00-0000-4bb1-d33b560d0000 pid=3414 /usr/bin/rm delete-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=de3d88c3-1a00-0000-4bb1-d33b560d0000 pid=3414 execve guuid=972fefc3-1a00-0000-4bb1-d33b570d0000 pid=3415 /usr/bin/wget net send-data guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=972fefc3-1a00-0000-4bb1-d33b570d0000 pid=3415 execve guuid=4bb501c7-1a00-0000-4bb1-d33b5d0d0000 pid=3421 /usr/bin/curl net send-data write-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=4bb501c7-1a00-0000-4bb1-d33b5d0d0000 pid=3421 execve guuid=a47ce9ca-1a00-0000-4bb1-d33b690d0000 pid=3433 /usr/bin/chmod guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=a47ce9ca-1a00-0000-4bb1-d33b690d0000 pid=3433 execve guuid=2d115acb-1a00-0000-4bb1-d33b6b0d0000 pid=3435 /usr/bin/bash guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=2d115acb-1a00-0000-4bb1-d33b6b0d0000 pid=3435 clone guuid=4ab086cb-1a00-0000-4bb1-d33b6d0d0000 pid=3437 /usr/bin/rm delete-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=4ab086cb-1a00-0000-4bb1-d33b6d0d0000 pid=3437 execve guuid=65e0f4cb-1a00-0000-4bb1-d33b6e0d0000 pid=3438 /usr/bin/wget net send-data guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=65e0f4cb-1a00-0000-4bb1-d33b6e0d0000 pid=3438 execve guuid=778d01ce-1a00-0000-4bb1-d33b740d0000 pid=3444 /usr/bin/curl net send-data write-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=778d01ce-1a00-0000-4bb1-d33b740d0000 pid=3444 execve guuid=b34c3ed3-1a00-0000-4bb1-d33b7d0d0000 pid=3453 /usr/bin/chmod guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=b34c3ed3-1a00-0000-4bb1-d33b7d0d0000 pid=3453 execve guuid=87bea1d3-1a00-0000-4bb1-d33b7e0d0000 pid=3454 /usr/bin/bash guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=87bea1d3-1a00-0000-4bb1-d33b7e0d0000 pid=3454 clone guuid=afb1d1d3-1a00-0000-4bb1-d33b800d0000 pid=3456 /usr/bin/rm delete-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=afb1d1d3-1a00-0000-4bb1-d33b800d0000 pid=3456 execve guuid=5e3b29d4-1a00-0000-4bb1-d33b820d0000 pid=3458 /usr/bin/wget net send-data guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=5e3b29d4-1a00-0000-4bb1-d33b820d0000 pid=3458 execve guuid=d1cdc1d6-1a00-0000-4bb1-d33b8b0d0000 pid=3467 /usr/bin/curl net send-data write-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=d1cdc1d6-1a00-0000-4bb1-d33b8b0d0000 pid=3467 execve guuid=b903cbdb-1a00-0000-4bb1-d33b980d0000 pid=3480 /usr/bin/chmod guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=b903cbdb-1a00-0000-4bb1-d33b980d0000 pid=3480 execve guuid=2cd433dc-1a00-0000-4bb1-d33b9b0d0000 pid=3483 /usr/bin/bash guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=2cd433dc-1a00-0000-4bb1-d33b9b0d0000 pid=3483 clone guuid=8c7f9ddc-1a00-0000-4bb1-d33b9d0d0000 pid=3485 /usr/bin/rm delete-file guuid=4dd1f74f-1a00-0000-4bb1-d33b790c0000 pid=3193->guuid=8c7f9ddc-1a00-0000-4bb1-d33b9d0d0000 pid=3485 execve f20cdb82-43f0-5559-9e7a-a227883a4d7b 109.104.154.249:80 guuid=5a390755-1a00-0000-4bb1-d33b850c0000 pid=3205->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 154B guuid=59a33559-1a00-0000-4bb1-d33b8e0c0000 pid=3214->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 103B guuid=b8df9866-1a00-0000-4bb1-d33b9c0c0000 pid=3228->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 155B guuid=fe3b6969-1a00-0000-4bb1-d33b9d0c0000 pid=3229->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 104B guuid=fc4fcd6d-1a00-0000-4bb1-d33ba10c0000 pid=3233->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 154B guuid=60989e70-1a00-0000-4bb1-d33ba20c0000 pid=3234->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 103B guuid=06dd7a76-1a00-0000-4bb1-d33bad0c0000 pid=3245->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 155B guuid=5c4bd678-1a00-0000-4bb1-d33baf0c0000 pid=3247->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 104B guuid=7dfdc57d-1a00-0000-4bb1-d33bbb0c0000 pid=3259->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 155B guuid=aba0d880-1a00-0000-4bb1-d33bc10c0000 pid=3265->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 104B guuid=c1288386-1a00-0000-4bb1-d33bca0c0000 pid=3274->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 157B guuid=38988f88-1a00-0000-4bb1-d33bce0c0000 pid=3278->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 106B guuid=4ad4888c-1a00-0000-4bb1-d33bd90c0000 pid=3289->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 155B guuid=24a11090-1a00-0000-4bb1-d33be00c0000 pid=3296->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 104B guuid=867fae96-1a00-0000-4bb1-d33be50c0000 pid=3301->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 154B guuid=cb37c198-1a00-0000-4bb1-d33be90c0000 pid=3305->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 103B guuid=16e8ad9d-1a00-0000-4bb1-d33bf80c0000 pid=3320->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 155B guuid=b64c3fa1-1a00-0000-4bb1-d33b010d0000 pid=3329->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 104B guuid=2564aaa8-1a00-0000-4bb1-d33b1b0d0000 pid=3355->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 155B guuid=666ab5aa-1a00-0000-4bb1-d33b210d0000 pid=3361->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 104B guuid=d56b21af-1a00-0000-4bb1-d33b330d0000 pid=3379->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 155B guuid=f5371eb3-1a00-0000-4bb1-d33b390d0000 pid=3385->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 104B guuid=6c1027ba-1a00-0000-4bb1-d33b3f0d0000 pid=3391->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 154B guuid=1d1d0cbd-1a00-0000-4bb1-d33b420d0000 pid=3394->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 103B guuid=972fefc3-1a00-0000-4bb1-d33b570d0000 pid=3415->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 154B guuid=4bb501c7-1a00-0000-4bb1-d33b5d0d0000 pid=3421->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 103B guuid=65e0f4cb-1a00-0000-4bb1-d33b6e0d0000 pid=3438->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 155B guuid=778d01ce-1a00-0000-4bb1-d33b740d0000 pid=3444->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 104B guuid=5e3b29d4-1a00-0000-4bb1-d33b820d0000 pid=3458->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 154B guuid=d1cdc1d6-1a00-0000-4bb1-d33b8b0d0000 pid=3467->f20cdb82-43f0-5559-9e7a-a227883a4d7b send: 103B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-01-17 17:34:40 UTC
File Type:
Text (Shell)
AV detection:
17 of 24 (70.83%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 6571d64d37801add3108b1029251a86a113b032d0347174edcd6f51de55a6e9d

(this sample)

  
Delivery method
Distributed via web download

Comments