MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 75d9c9121217f1ffef50db1b1f9d815973e92c04f9755628cdf3e1b76c4cca3d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: 75d9c9121217f1ffef50db1b1f9d815973e92c04f9755628cdf3e1b76c4cca3d
SHA3-384 hash: 195ececcc5bb5623e784f8b3da48ce0be9391fd8b624903d23154740ecc8706c377f04edc6c544345cba619c9f827182
SHA1 hash: dcd38c13d7f51bc82ae88c963c8f4a335768dfc7
MD5 hash: 0eebdad82d8c1075e8da0c01e46cd777
humanhash: london-charlie-equal-salami
File name:ohshit.sh
Download: download sample
File size:2'869 bytes
First seen:2026-02-18 13:46:16 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:iqo9qqVqhpqTtTrpqflqVxqM5LqCZq55qwzqbRq8+8KquQubgq+Xqle:iqo9qqVqhpqTtTrpqflqVxqOLqCZq556
TLSH T1645141CE13936438EC65592762B44106B69099B7B9C49DDCDCE87DEFE28CE0A38C1782
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://152.89.170.85/bins/kwari.arcn/an/aelf ua-wget
http://152.89.170.85/bins/kwari.x86n/an/aelf ua-wget
http://152.89.170.85/bins/kwari.x86_64n/an/aelf ua-wget
http://152.89.170.85/bins/kwari.i686n/an/aelf ua-wget
http://152.89.170.85/bins/kwari.mipsn/an/aelf ua-wget
http://152.89.170.85/bins/kwari.mips64n/an/aelf ua-wget
http://152.89.170.85/bins/kwari.mpsln/an/aelf ua-wget
http://152.89.170.85/bins/kwari.armn/an/aelf ua-wget
http://152.89.170.85/bins/kwari.arm5n/an/aelf ua-wget
http://152.89.170.85/bins/kwari.arm6n/an/aelf ua-wget
http://152.89.170.85/bins/kwari.arm7n/an/aelf ua-wget
http://152.89.170.85/bins/kwari.ppcn/an/aelf ua-wget
http://152.89.170.85/bins/kwari.sparcn/an/aelf ua-wget
http://152.89.170.85/bins/kwari.m68kn/an/aelf ua-wget
http://152.89.170.85/bins/kwari.sh4n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
busybox medusa mirai
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=ebe2fce5-1500-0000-c13b-0e8f750b0000 pid=2933 /usr/bin/sudo guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936 /tmp/sample.bin guuid=ebe2fce5-1500-0000-c13b-0e8f750b0000 pid=2933->guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936 execve guuid=5eabb6e8-1500-0000-c13b-0e8f7d0b0000 pid=2941 /usr/bin/cp guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=5eabb6e8-1500-0000-c13b-0e8f7d0b0000 pid=2941 execve guuid=ba7a45ed-1500-0000-c13b-0e8f830b0000 pid=2947 /usr/bin/wget net send-data guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=ba7a45ed-1500-0000-c13b-0e8f830b0000 pid=2947 execve guuid=89bcc5f7-1500-0000-c13b-0e8fa00b0000 pid=2976 /usr/bin/curl net send-data write-file guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=89bcc5f7-1500-0000-c13b-0e8fa00b0000 pid=2976 execve guuid=6686940c-1600-0000-c13b-0e8fb90b0000 pid=3001 /usr/bin/cat guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=6686940c-1600-0000-c13b-0e8fb90b0000 pid=3001 execve guuid=1cacd90c-1600-0000-c13b-0e8fbb0b0000 pid=3003 /usr/bin/chmod guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=1cacd90c-1600-0000-c13b-0e8fbb0b0000 pid=3003 execve guuid=7501180d-1600-0000-c13b-0e8fbd0b0000 pid=3005 /usr/bin/bash guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=7501180d-1600-0000-c13b-0e8fbd0b0000 pid=3005 clone guuid=1dc2390d-1600-0000-c13b-0e8fbe0b0000 pid=3006 /usr/bin/wget net send-data guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=1dc2390d-1600-0000-c13b-0e8fbe0b0000 pid=3006 execve guuid=19539813-1600-0000-c13b-0e8fd00b0000 pid=3024 /usr/bin/curl net send-data write-file guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=19539813-1600-0000-c13b-0e8fd00b0000 pid=3024 execve guuid=7fd4cb1e-1600-0000-c13b-0e8ff00b0000 pid=3056 /usr/bin/cat guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=7fd4cb1e-1600-0000-c13b-0e8ff00b0000 pid=3056 execve guuid=c89b2a1f-1600-0000-c13b-0e8ff20b0000 pid=3058 /usr/bin/chmod guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=c89b2a1f-1600-0000-c13b-0e8ff20b0000 pid=3058 execve guuid=14ea7f1f-1600-0000-c13b-0e8ff30b0000 pid=3059 /usr/bin/bash guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=14ea7f1f-1600-0000-c13b-0e8ff30b0000 pid=3059 clone guuid=89e7ac1f-1600-0000-c13b-0e8ff50b0000 pid=3061 /usr/bin/wget net send-data guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=89e7ac1f-1600-0000-c13b-0e8ff50b0000 pid=3061 execve guuid=2e1ee328-1600-0000-c13b-0e8f090c0000 pid=3081 /usr/bin/curl net send-data write-file guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=2e1ee328-1600-0000-c13b-0e8f090c0000 pid=3081 execve guuid=a53fb634-1600-0000-c13b-0e8f2c0c0000 pid=3116 /usr/bin/cat guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=a53fb634-1600-0000-c13b-0e8f2c0c0000 pid=3116 execve guuid=cf9a0735-1600-0000-c13b-0e8f2f0c0000 pid=3119 /usr/bin/chmod guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=cf9a0735-1600-0000-c13b-0e8f2f0c0000 pid=3119 execve guuid=54f08635-1600-0000-c13b-0e8f310c0000 pid=3121 /usr/bin/bash guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=54f08635-1600-0000-c13b-0e8f310c0000 pid=3121 clone guuid=7515ba35-1600-0000-c13b-0e8f320c0000 pid=3122 /usr/bin/wget net send-data guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=7515ba35-1600-0000-c13b-0e8f320c0000 pid=3122 execve guuid=4938403d-1600-0000-c13b-0e8f490c0000 pid=3145 /usr/bin/curl net send-data write-file guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=4938403d-1600-0000-c13b-0e8f490c0000 pid=3145 execve guuid=31ef0245-1600-0000-c13b-0e8f5a0c0000 pid=3162 /usr/bin/cat guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=31ef0245-1600-0000-c13b-0e8f5a0c0000 pid=3162 execve guuid=837f6f45-1600-0000-c13b-0e8f5c0c0000 pid=3164 /usr/bin/chmod guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=837f6f45-1600-0000-c13b-0e8f5c0c0000 pid=3164 execve guuid=c626db45-1600-0000-c13b-0e8f5e0c0000 pid=3166 /usr/bin/bash guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=c626db45-1600-0000-c13b-0e8f5e0c0000 pid=3166 clone guuid=95d41346-1600-0000-c13b-0e8f600c0000 pid=3168 /usr/bin/wget net send-data guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=95d41346-1600-0000-c13b-0e8f600c0000 pid=3168 execve guuid=bf4a054c-1600-0000-c13b-0e8f6d0c0000 pid=3181 /usr/bin/curl net send-data write-file guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=bf4a054c-1600-0000-c13b-0e8f6d0c0000 pid=3181 execve guuid=a954f755-1600-0000-c13b-0e8f720c0000 pid=3186 /usr/bin/cat guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=a954f755-1600-0000-c13b-0e8f720c0000 pid=3186 execve guuid=c1a65b56-1600-0000-c13b-0e8f730c0000 pid=3187 /usr/bin/chmod guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=c1a65b56-1600-0000-c13b-0e8f730c0000 pid=3187 execve guuid=826db156-1600-0000-c13b-0e8f740c0000 pid=3188 /usr/bin/bash guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=826db156-1600-0000-c13b-0e8f740c0000 pid=3188 clone guuid=069fe456-1600-0000-c13b-0e8f750c0000 pid=3189 /usr/bin/wget net send-data guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=069fe456-1600-0000-c13b-0e8f750c0000 pid=3189 execve guuid=c08d935c-1600-0000-c13b-0e8f770c0000 pid=3191 /usr/bin/curl net send-data write-file guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=c08d935c-1600-0000-c13b-0e8f770c0000 pid=3191 execve guuid=eed43463-1600-0000-c13b-0e8f8a0c0000 pid=3210 /usr/bin/cat guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=eed43463-1600-0000-c13b-0e8f8a0c0000 pid=3210 execve guuid=6e5aa163-1600-0000-c13b-0e8f8b0c0000 pid=3211 /usr/bin/chmod guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=6e5aa163-1600-0000-c13b-0e8f8b0c0000 pid=3211 execve guuid=436afe63-1600-0000-c13b-0e8f8c0c0000 pid=3212 /usr/bin/bash guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=436afe63-1600-0000-c13b-0e8f8c0c0000 pid=3212 clone guuid=3f9c2f64-1600-0000-c13b-0e8f8d0c0000 pid=3213 /usr/bin/wget net send-data guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=3f9c2f64-1600-0000-c13b-0e8f8d0c0000 pid=3213 execve guuid=e63e1e6b-1600-0000-c13b-0e8f9f0c0000 pid=3231 /usr/bin/curl net send-data write-file guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=e63e1e6b-1600-0000-c13b-0e8f9f0c0000 pid=3231 execve guuid=c7ad6976-1600-0000-c13b-0e8fa00c0000 pid=3232 /usr/bin/cat guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=c7ad6976-1600-0000-c13b-0e8fa00c0000 pid=3232 execve guuid=cfffcc76-1600-0000-c13b-0e8fa10c0000 pid=3233 /usr/bin/chmod guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=cfffcc76-1600-0000-c13b-0e8fa10c0000 pid=3233 execve guuid=98391977-1600-0000-c13b-0e8fa20c0000 pid=3234 /usr/bin/bash guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=98391977-1600-0000-c13b-0e8fa20c0000 pid=3234 clone guuid=a2844577-1600-0000-c13b-0e8fa30c0000 pid=3235 /usr/bin/wget net send-data guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=a2844577-1600-0000-c13b-0e8fa30c0000 pid=3235 execve guuid=d955fa7d-1600-0000-c13b-0e8fa60c0000 pid=3238 /usr/bin/curl net send-data write-file guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=d955fa7d-1600-0000-c13b-0e8fa60c0000 pid=3238 execve guuid=3df1f184-1600-0000-c13b-0e8fb30c0000 pid=3251 /usr/bin/cat guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=3df1f184-1600-0000-c13b-0e8fb30c0000 pid=3251 execve guuid=f1008f85-1600-0000-c13b-0e8fb40c0000 pid=3252 /usr/bin/chmod guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=f1008f85-1600-0000-c13b-0e8fb40c0000 pid=3252 execve guuid=603f1586-1600-0000-c13b-0e8fb50c0000 pid=3253 /usr/bin/bash guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=603f1586-1600-0000-c13b-0e8fb50c0000 pid=3253 clone guuid=7eec4d86-1600-0000-c13b-0e8fb70c0000 pid=3255 /usr/bin/wget net send-data guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=7eec4d86-1600-0000-c13b-0e8fb70c0000 pid=3255 execve guuid=9b3cea8d-1600-0000-c13b-0e8fc00c0000 pid=3264 /usr/bin/curl net send-data write-file guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=9b3cea8d-1600-0000-c13b-0e8fc00c0000 pid=3264 execve guuid=4cf66f98-1600-0000-c13b-0e8fd40c0000 pid=3284 /usr/bin/cat guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=4cf66f98-1600-0000-c13b-0e8fd40c0000 pid=3284 execve guuid=07118899-1600-0000-c13b-0e8fd50c0000 pid=3285 /usr/bin/chmod guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=07118899-1600-0000-c13b-0e8fd50c0000 pid=3285 execve guuid=ead0d899-1600-0000-c13b-0e8fd70c0000 pid=3287 /usr/bin/bash guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=ead0d899-1600-0000-c13b-0e8fd70c0000 pid=3287 clone guuid=d4310c9a-1600-0000-c13b-0e8fd80c0000 pid=3288 /usr/bin/wget net send-data guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=d4310c9a-1600-0000-c13b-0e8fd80c0000 pid=3288 execve guuid=690f46a0-1600-0000-c13b-0e8fe80c0000 pid=3304 /usr/bin/curl net send-data write-file guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=690f46a0-1600-0000-c13b-0e8fe80c0000 pid=3304 execve guuid=0ff963a9-1600-0000-c13b-0e8ffd0c0000 pid=3325 /usr/bin/cat guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=0ff963a9-1600-0000-c13b-0e8ffd0c0000 pid=3325 execve guuid=211bdda9-1600-0000-c13b-0e8f000d0000 pid=3328 /usr/bin/chmod guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=211bdda9-1600-0000-c13b-0e8f000d0000 pid=3328 execve guuid=9ba56eaa-1600-0000-c13b-0e8f020d0000 pid=3330 /usr/bin/bash guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=9ba56eaa-1600-0000-c13b-0e8f020d0000 pid=3330 clone guuid=9f1db0aa-1600-0000-c13b-0e8f030d0000 pid=3331 /usr/bin/wget net send-data guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=9f1db0aa-1600-0000-c13b-0e8f030d0000 pid=3331 execve guuid=d977f0b0-1600-0000-c13b-0e8f100d0000 pid=3344 /usr/bin/curl net send-data write-file guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=d977f0b0-1600-0000-c13b-0e8f100d0000 pid=3344 execve guuid=d8d70cba-1600-0000-c13b-0e8f250d0000 pid=3365 /usr/bin/cat guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=d8d70cba-1600-0000-c13b-0e8f250d0000 pid=3365 execve guuid=69aad7ba-1600-0000-c13b-0e8f260d0000 pid=3366 /usr/bin/chmod guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=69aad7ba-1600-0000-c13b-0e8f260d0000 pid=3366 execve guuid=49e485bb-1600-0000-c13b-0e8f270d0000 pid=3367 /usr/bin/bash guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=49e485bb-1600-0000-c13b-0e8f270d0000 pid=3367 clone guuid=8fb1ecbb-1600-0000-c13b-0e8f280d0000 pid=3368 /usr/bin/wget net send-data guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=8fb1ecbb-1600-0000-c13b-0e8f280d0000 pid=3368 execve guuid=080c6dc2-1600-0000-c13b-0e8f290d0000 pid=3369 /usr/bin/curl net send-data write-file guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=080c6dc2-1600-0000-c13b-0e8f290d0000 pid=3369 execve guuid=793b5ecb-1600-0000-c13b-0e8f360d0000 pid=3382 /usr/bin/cat guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=793b5ecb-1600-0000-c13b-0e8f360d0000 pid=3382 execve guuid=0ca9b6cb-1600-0000-c13b-0e8f370d0000 pid=3383 /usr/bin/chmod guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=0ca9b6cb-1600-0000-c13b-0e8f370d0000 pid=3383 execve guuid=226600cc-1600-0000-c13b-0e8f380d0000 pid=3384 /usr/bin/bash guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=226600cc-1600-0000-c13b-0e8f380d0000 pid=3384 clone guuid=d9fc21cc-1600-0000-c13b-0e8f3a0d0000 pid=3386 /usr/bin/wget net send-data guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=d9fc21cc-1600-0000-c13b-0e8f3a0d0000 pid=3386 execve guuid=c3ddc4d1-1600-0000-c13b-0e8f460d0000 pid=3398 /usr/bin/curl net send-data write-file guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=c3ddc4d1-1600-0000-c13b-0e8f460d0000 pid=3398 execve guuid=544cd3dc-1600-0000-c13b-0e8f570d0000 pid=3415 /usr/bin/cat guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=544cd3dc-1600-0000-c13b-0e8f570d0000 pid=3415 execve guuid=0b6e2bdd-1600-0000-c13b-0e8f590d0000 pid=3417 /usr/bin/chmod guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=0b6e2bdd-1600-0000-c13b-0e8f590d0000 pid=3417 execve guuid=73217fdd-1600-0000-c13b-0e8f5b0d0000 pid=3419 /usr/bin/bash guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=73217fdd-1600-0000-c13b-0e8f5b0d0000 pid=3419 clone guuid=43b5aedd-1600-0000-c13b-0e8f5c0d0000 pid=3420 /usr/bin/wget net send-data guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=43b5aedd-1600-0000-c13b-0e8f5c0d0000 pid=3420 execve guuid=d5b694e5-1600-0000-c13b-0e8f730d0000 pid=3443 /usr/bin/curl net send-data write-file guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=d5b694e5-1600-0000-c13b-0e8f730d0000 pid=3443 execve guuid=04c819ec-1600-0000-c13b-0e8f870d0000 pid=3463 /usr/bin/cat guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=04c819ec-1600-0000-c13b-0e8f870d0000 pid=3463 execve guuid=341c84ec-1600-0000-c13b-0e8f890d0000 pid=3465 /usr/bin/chmod guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=341c84ec-1600-0000-c13b-0e8f890d0000 pid=3465 execve guuid=4e85d7ec-1600-0000-c13b-0e8f8a0d0000 pid=3466 /usr/bin/bash guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=4e85d7ec-1600-0000-c13b-0e8f8a0d0000 pid=3466 clone guuid=7a5310ed-1600-0000-c13b-0e8f8c0d0000 pid=3468 /usr/bin/wget net send-data guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=7a5310ed-1600-0000-c13b-0e8f8c0d0000 pid=3468 execve guuid=c60616f3-1600-0000-c13b-0e8f9c0d0000 pid=3484 /usr/bin/curl net send-data write-file guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=c60616f3-1600-0000-c13b-0e8f9c0d0000 pid=3484 execve guuid=592943fb-1600-0000-c13b-0e8fb10d0000 pid=3505 /usr/bin/cat guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=592943fb-1600-0000-c13b-0e8fb10d0000 pid=3505 execve guuid=46c7cafb-1600-0000-c13b-0e8fb20d0000 pid=3506 /usr/bin/chmod guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=46c7cafb-1600-0000-c13b-0e8fb20d0000 pid=3506 execve guuid=57e553fc-1600-0000-c13b-0e8fb40d0000 pid=3508 /usr/bin/bash guuid=b92a88e7-1500-0000-c13b-0e8f780b0000 pid=2936->guuid=57e553fc-1600-0000-c13b-0e8fb40d0000 pid=3508 clone ae3ee878-f2d0-572a-9693-fbc558232a57 152.89.170.85:80 guuid=ba7a45ed-1500-0000-c13b-0e8f830b0000 pid=2947->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 142B guuid=89bcc5f7-1500-0000-c13b-0e8fa00b0000 pid=2976->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 91B guuid=1dc2390d-1600-0000-c13b-0e8fbe0b0000 pid=3006->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 142B guuid=19539813-1600-0000-c13b-0e8fd00b0000 pid=3024->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 91B guuid=89e7ac1f-1600-0000-c13b-0e8ff50b0000 pid=3061->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 145B guuid=2e1ee328-1600-0000-c13b-0e8f090c0000 pid=3081->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 94B guuid=7515ba35-1600-0000-c13b-0e8f320c0000 pid=3122->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 143B guuid=4938403d-1600-0000-c13b-0e8f490c0000 pid=3145->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 92B guuid=95d41346-1600-0000-c13b-0e8f600c0000 pid=3168->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 143B guuid=bf4a054c-1600-0000-c13b-0e8f6d0c0000 pid=3181->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 92B guuid=069fe456-1600-0000-c13b-0e8f750c0000 pid=3189->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 145B guuid=c08d935c-1600-0000-c13b-0e8f770c0000 pid=3191->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 94B guuid=3f9c2f64-1600-0000-c13b-0e8f8d0c0000 pid=3213->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 143B guuid=e63e1e6b-1600-0000-c13b-0e8f9f0c0000 pid=3231->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 92B guuid=a2844577-1600-0000-c13b-0e8fa30c0000 pid=3235->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 142B guuid=d955fa7d-1600-0000-c13b-0e8fa60c0000 pid=3238->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 91B guuid=7eec4d86-1600-0000-c13b-0e8fb70c0000 pid=3255->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 143B guuid=9b3cea8d-1600-0000-c13b-0e8fc00c0000 pid=3264->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 92B guuid=d4310c9a-1600-0000-c13b-0e8fd80c0000 pid=3288->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 143B guuid=690f46a0-1600-0000-c13b-0e8fe80c0000 pid=3304->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 92B guuid=9f1db0aa-1600-0000-c13b-0e8f030d0000 pid=3331->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 143B guuid=d977f0b0-1600-0000-c13b-0e8f100d0000 pid=3344->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 92B guuid=8fb1ecbb-1600-0000-c13b-0e8f280d0000 pid=3368->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 142B guuid=080c6dc2-1600-0000-c13b-0e8f290d0000 pid=3369->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 91B guuid=d9fc21cc-1600-0000-c13b-0e8f3a0d0000 pid=3386->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 144B guuid=c3ddc4d1-1600-0000-c13b-0e8f460d0000 pid=3398->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 93B guuid=43b5aedd-1600-0000-c13b-0e8f5c0d0000 pid=3420->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 143B guuid=d5b694e5-1600-0000-c13b-0e8f730d0000 pid=3443->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 92B guuid=7a5310ed-1600-0000-c13b-0e8f8c0d0000 pid=3468->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 142B guuid=c60616f3-1600-0000-c13b-0e8f9c0d0000 pid=3484->ae3ee878-f2d0-572a-9693-fbc558232a57 send: 91B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-02-18 14:17:52 UTC
AV detection:
22 of 38 (57.89%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 75d9c9121217f1ffef50db1b1f9d815973e92c04f9755628cdf3e1b76c4cca3d

(this sample)

  
Delivery method
Distributed via web download

Comments