MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7d5d0777b8ead280d7a9bfee49526a55d7a3f8e9b2018c55a2953501c72e1882. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 7d5d0777b8ead280d7a9bfee49526a55d7a3f8e9b2018c55a2953501c72e1882
SHA3-384 hash: ba8f3288252da548efe57e8623d59b225b45c3807fb6219adb6db77fa508120632014bc7636d2c5027c6a66db52624c7
SHA1 hash: 9dd0aa7f5b240f9a650b257f11a9243f8b6ce446
MD5 hash: a2bab1fead7d299c82493acf7dc267f0
humanhash: friend-asparagus-avocado-kentucky
File name:h
Download: download sample
File size:2'041 bytes
First seen:2024-11-10 15:47:28 UTC
Last seen:2024-12-13 11:08:18 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:v5u5EB5m5q5gJ5W5u5S5K565kL5N05vWfsx:v5u5y5m5q5C5W5u5S5K565kL5N05Z
TLSH T12E41E38B6062EF325DF09963366BEB943090919BD1CE5F1958FC79E940CCE85A3C4D93
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
9
# of downloads :
64
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
medusa mirai
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2024-10-08 11:13:50 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 7d5d0777b8ead280d7a9bfee49526a55d7a3f8e9b2018c55a2953501c72e1882

(this sample)

Comments