MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8450ca2d341154fb3d2c26a828881111757c643de2b3e4e0d0958e7aa625ad76. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: 8450ca2d341154fb3d2c26a828881111757c643de2b3e4e0d0958e7aa625ad76
SHA3-384 hash: 63569c2702f0bf60076ab9cc5b27ba010d516670980677b18742a81676f602b02aa9c80ed42e8a99414026391e9189e9
SHA1 hash: 4de7f9f1f5f906d46e1e4360133ddd9efe069454
MD5 hash: 197bd3df1cc5b5bc9668e84f1a7bf47d
humanhash: river-enemy-angel-utah
File name:bins.sh
Download: download sample
File size:2'033 bytes
First seen:2026-04-16 12:06:02 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:1OKfjEsJN/fUPsnBTTdfTf2Jsp3vSUTxX1rR37517ixcHv0:1OK7EsJtsPsBTZfTeJsZqUtld9BiIM
TLSH T10941F7CA21E23932BDB0E957B2698407B9C1949E15F76F04ACED74D6D1BCE446001F93
Magika txt
Reporter adliwahid
URLMalware sample (SHA256 hash)SignatureTags
http://2.27.12.6/Okami.mipsn/an/an/a
http://2.27.12.6/Okami.mpsln/an/aelf ua-wget
http://2.27.12.6/Okami.sh4n/an/aelf ua-wget
http://2.27.12.6/Okami.x86n/an/aelf ua-wget
http://2.27.12.6/Okami.arm6n/an/an/a
http://2.27.12.6/Okami.i686n/an/aelf ua-wget
http://2.27.12.6/Okami.ppcn/an/an/a
http://2.27.12.6/Okami.i586n/an/aelf ua-wget
http://2.27.12.6/Okami.m68kn/an/an/a
http://2.27.12.6/Okami.sparcn/an/aelf ua-wget
http://2.27.12.6/Okami.arm4n/an/an/a
http://2.27.12.6/Okami.arm5n/an/an/a
http://2.27.12.6/Okami.arm7n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
39
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
text
First seen:
2026-04-16T13:25:00Z UTC
Last seen:
2026-04-16T13:28:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen
Status:
terminated
Behavior Graph:
%3 guuid=4bfef4d5-1a00-0000-dfe8-54789d0c0000 pid=3229 /usr/bin/sudo guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235 /tmp/sample.bin guuid=4bfef4d5-1a00-0000-dfe8-54789d0c0000 pid=3229->guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235 execve guuid=0c0d83d8-1a00-0000-dfe8-5478a40c0000 pid=3236 /usr/bin/wget net send-data guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=0c0d83d8-1a00-0000-dfe8-5478a40c0000 pid=3236 execve guuid=851dd0dc-1a00-0000-dfe8-5478ae0c0000 pid=3246 /usr/bin/chmod guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=851dd0dc-1a00-0000-dfe8-5478ae0c0000 pid=3246 execve guuid=63bd3ddd-1a00-0000-dfe8-5478af0c0000 pid=3247 /usr/bin/dash guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=63bd3ddd-1a00-0000-dfe8-5478af0c0000 pid=3247 clone guuid=723e7bdd-1a00-0000-dfe8-5478b00c0000 pid=3248 /usr/bin/rm guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=723e7bdd-1a00-0000-dfe8-5478b00c0000 pid=3248 execve guuid=50e334de-1a00-0000-dfe8-5478b10c0000 pid=3249 /usr/bin/wget net send-data guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=50e334de-1a00-0000-dfe8-5478b10c0000 pid=3249 execve guuid=307630e1-1a00-0000-dfe8-5478b80c0000 pid=3256 /usr/bin/chmod guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=307630e1-1a00-0000-dfe8-5478b80c0000 pid=3256 execve guuid=199fc4e1-1a00-0000-dfe8-5478b90c0000 pid=3257 /usr/bin/dash guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=199fc4e1-1a00-0000-dfe8-5478b90c0000 pid=3257 clone guuid=f52fd8e1-1a00-0000-dfe8-5478ba0c0000 pid=3258 /usr/bin/rm guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=f52fd8e1-1a00-0000-dfe8-5478ba0c0000 pid=3258 execve guuid=ade85de2-1a00-0000-dfe8-5478bb0c0000 pid=3259 /usr/bin/wget net send-data guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=ade85de2-1a00-0000-dfe8-5478bb0c0000 pid=3259 execve guuid=80f477e5-1a00-0000-dfe8-5478bc0c0000 pid=3260 /usr/bin/chmod guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=80f477e5-1a00-0000-dfe8-5478bc0c0000 pid=3260 execve guuid=033c3be6-1a00-0000-dfe8-5478bd0c0000 pid=3261 /usr/bin/dash guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=033c3be6-1a00-0000-dfe8-5478bd0c0000 pid=3261 clone guuid=8c7b50e6-1a00-0000-dfe8-5478be0c0000 pid=3262 /usr/bin/rm guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=8c7b50e6-1a00-0000-dfe8-5478be0c0000 pid=3262 execve guuid=303db2e6-1a00-0000-dfe8-5478bf0c0000 pid=3263 /usr/bin/wget net send-data guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=303db2e6-1a00-0000-dfe8-5478bf0c0000 pid=3263 execve guuid=1dcb97e9-1a00-0000-dfe8-5478c10c0000 pid=3265 /usr/bin/chmod guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=1dcb97e9-1a00-0000-dfe8-5478c10c0000 pid=3265 execve guuid=679ef6e9-1a00-0000-dfe8-5478c20c0000 pid=3266 /usr/bin/dash guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=679ef6e9-1a00-0000-dfe8-5478c20c0000 pid=3266 clone guuid=b2ad06ea-1a00-0000-dfe8-5478c30c0000 pid=3267 /usr/bin/rm guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=b2ad06ea-1a00-0000-dfe8-5478c30c0000 pid=3267 execve guuid=2ad850ea-1a00-0000-dfe8-5478c40c0000 pid=3268 /usr/bin/wget net send-data guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=2ad850ea-1a00-0000-dfe8-5478c40c0000 pid=3268 execve guuid=6b9b38ed-1a00-0000-dfe8-5478cc0c0000 pid=3276 /usr/bin/chmod guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=6b9b38ed-1a00-0000-dfe8-5478cc0c0000 pid=3276 execve guuid=17bb77ed-1a00-0000-dfe8-5478ce0c0000 pid=3278 /usr/bin/dash guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=17bb77ed-1a00-0000-dfe8-5478ce0c0000 pid=3278 clone guuid=3f5c8ded-1a00-0000-dfe8-5478cf0c0000 pid=3279 /usr/bin/rm guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=3f5c8ded-1a00-0000-dfe8-5478cf0c0000 pid=3279 execve guuid=eb8ad2ed-1a00-0000-dfe8-5478d10c0000 pid=3281 /usr/bin/wget net send-data guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=eb8ad2ed-1a00-0000-dfe8-5478d10c0000 pid=3281 execve guuid=50e577f0-1a00-0000-dfe8-5478d80c0000 pid=3288 /usr/bin/chmod guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=50e577f0-1a00-0000-dfe8-5478d80c0000 pid=3288 execve guuid=e715c7f0-1a00-0000-dfe8-5478da0c0000 pid=3290 /usr/bin/dash guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=e715c7f0-1a00-0000-dfe8-5478da0c0000 pid=3290 clone guuid=df36d9f0-1a00-0000-dfe8-5478db0c0000 pid=3291 /usr/bin/rm guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=df36d9f0-1a00-0000-dfe8-5478db0c0000 pid=3291 execve guuid=3b391cf1-1a00-0000-dfe8-5478dd0c0000 pid=3293 /usr/bin/wget net send-data guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=3b391cf1-1a00-0000-dfe8-5478dd0c0000 pid=3293 execve guuid=343acef3-1a00-0000-dfe8-5478e10c0000 pid=3297 /usr/bin/chmod guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=343acef3-1a00-0000-dfe8-5478e10c0000 pid=3297 execve guuid=ad9948f4-1a00-0000-dfe8-5478e20c0000 pid=3298 /usr/bin/dash guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=ad9948f4-1a00-0000-dfe8-5478e20c0000 pid=3298 clone guuid=c12864f4-1a00-0000-dfe8-5478e30c0000 pid=3299 /usr/bin/rm guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=c12864f4-1a00-0000-dfe8-5478e30c0000 pid=3299 execve guuid=fec4c2f4-1a00-0000-dfe8-5478e40c0000 pid=3300 /usr/bin/wget net send-data guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=fec4c2f4-1a00-0000-dfe8-5478e40c0000 pid=3300 execve guuid=1e66cef7-1a00-0000-dfe8-5478e60c0000 pid=3302 /usr/bin/chmod guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=1e66cef7-1a00-0000-dfe8-5478e60c0000 pid=3302 execve guuid=e6df22f8-1a00-0000-dfe8-5478e70c0000 pid=3303 /usr/bin/dash guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=e6df22f8-1a00-0000-dfe8-5478e70c0000 pid=3303 clone guuid=96752af8-1a00-0000-dfe8-5478e80c0000 pid=3304 /usr/bin/rm guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=96752af8-1a00-0000-dfe8-5478e80c0000 pid=3304 execve guuid=968b7cf8-1a00-0000-dfe8-5478e90c0000 pid=3305 /usr/bin/wget net send-data guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=968b7cf8-1a00-0000-dfe8-5478e90c0000 pid=3305 execve guuid=98ebecfc-1a00-0000-dfe8-5478f30c0000 pid=3315 /usr/bin/chmod guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=98ebecfc-1a00-0000-dfe8-5478f30c0000 pid=3315 execve guuid=40e648fd-1a00-0000-dfe8-5478f50c0000 pid=3317 /usr/bin/dash guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=40e648fd-1a00-0000-dfe8-5478f50c0000 pid=3317 clone guuid=c01659fd-1a00-0000-dfe8-5478f60c0000 pid=3318 /usr/bin/rm guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=c01659fd-1a00-0000-dfe8-5478f60c0000 pid=3318 execve guuid=1a0db3fd-1a00-0000-dfe8-5478f80c0000 pid=3320 /usr/bin/wget net send-data guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=1a0db3fd-1a00-0000-dfe8-5478f80c0000 pid=3320 execve guuid=e93c5801-1b00-0000-dfe8-5478000d0000 pid=3328 /usr/bin/chmod guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=e93c5801-1b00-0000-dfe8-5478000d0000 pid=3328 execve guuid=2b36fb01-1b00-0000-dfe8-5478020d0000 pid=3330 /usr/bin/dash guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=2b36fb01-1b00-0000-dfe8-5478020d0000 pid=3330 clone guuid=e8cc1e02-1b00-0000-dfe8-5478030d0000 pid=3331 /usr/bin/rm guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=e8cc1e02-1b00-0000-dfe8-5478030d0000 pid=3331 execve guuid=1718a102-1b00-0000-dfe8-5478040d0000 pid=3332 /usr/bin/wget net send-data guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=1718a102-1b00-0000-dfe8-5478040d0000 pid=3332 execve guuid=fbd7cf06-1b00-0000-dfe8-54780d0d0000 pid=3341 /usr/bin/chmod guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=fbd7cf06-1b00-0000-dfe8-54780d0d0000 pid=3341 execve guuid=63313907-1b00-0000-dfe8-54780f0d0000 pid=3343 /usr/bin/dash guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=63313907-1b00-0000-dfe8-54780f0d0000 pid=3343 clone guuid=4a0c4607-1b00-0000-dfe8-5478100d0000 pid=3344 /usr/bin/rm guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=4a0c4607-1b00-0000-dfe8-5478100d0000 pid=3344 execve guuid=0c428a07-1b00-0000-dfe8-5478120d0000 pid=3346 /usr/bin/wget net send-data guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=0c428a07-1b00-0000-dfe8-5478120d0000 pid=3346 execve guuid=fdcc9b0c-1b00-0000-dfe8-54781c0d0000 pid=3356 /usr/bin/chmod guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=fdcc9b0c-1b00-0000-dfe8-54781c0d0000 pid=3356 execve guuid=3d29f80c-1b00-0000-dfe8-54781e0d0000 pid=3358 /usr/bin/dash guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=3d29f80c-1b00-0000-dfe8-54781e0d0000 pid=3358 clone guuid=42da040d-1b00-0000-dfe8-5478200d0000 pid=3360 /usr/bin/rm guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=42da040d-1b00-0000-dfe8-5478200d0000 pid=3360 execve guuid=0e405f0d-1b00-0000-dfe8-5478210d0000 pid=3361 /usr/bin/wget net send-data guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=0e405f0d-1b00-0000-dfe8-5478210d0000 pid=3361 execve guuid=b1173110-1b00-0000-dfe8-5478270d0000 pid=3367 /usr/bin/chmod guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=b1173110-1b00-0000-dfe8-5478270d0000 pid=3367 execve guuid=d94e8810-1b00-0000-dfe8-5478280d0000 pid=3368 /usr/bin/dash guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=d94e8810-1b00-0000-dfe8-5478280d0000 pid=3368 clone guuid=b74f9f10-1b00-0000-dfe8-5478290d0000 pid=3369 /usr/bin/rm guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=b74f9f10-1b00-0000-dfe8-5478290d0000 pid=3369 execve guuid=53000311-1b00-0000-dfe8-54782b0d0000 pid=3371 /usr/bin/wget net send-data guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=53000311-1b00-0000-dfe8-54782b0d0000 pid=3371 execve guuid=b614fe14-1b00-0000-dfe8-5478350d0000 pid=3381 /usr/bin/chmod guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=b614fe14-1b00-0000-dfe8-5478350d0000 pid=3381 execve guuid=33ed5515-1b00-0000-dfe8-5478370d0000 pid=3383 /usr/bin/dash guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=33ed5515-1b00-0000-dfe8-5478370d0000 pid=3383 clone guuid=447e5f15-1b00-0000-dfe8-5478380d0000 pid=3384 /usr/bin/rm guuid=944b4ad8-1a00-0000-dfe8-5478a30c0000 pid=3235->guuid=447e5f15-1b00-0000-dfe8-5478380d0000 pid=3384 execve 7343de6d-830d-56b8-ab45-cbaef8a44ba8 2.27.12.6:80 guuid=0c0d83d8-1a00-0000-dfe8-5478a40c0000 pid=3236->7343de6d-830d-56b8-ab45-cbaef8a44ba8 send: 134B guuid=50e334de-1a00-0000-dfe8-5478b10c0000 pid=3249->7343de6d-830d-56b8-ab45-cbaef8a44ba8 send: 134B guuid=ade85de2-1a00-0000-dfe8-5478bb0c0000 pid=3259->7343de6d-830d-56b8-ab45-cbaef8a44ba8 send: 133B guuid=303db2e6-1a00-0000-dfe8-5478bf0c0000 pid=3263->7343de6d-830d-56b8-ab45-cbaef8a44ba8 send: 133B guuid=2ad850ea-1a00-0000-dfe8-5478c40c0000 pid=3268->7343de6d-830d-56b8-ab45-cbaef8a44ba8 send: 134B guuid=eb8ad2ed-1a00-0000-dfe8-5478d10c0000 pid=3281->7343de6d-830d-56b8-ab45-cbaef8a44ba8 send: 134B guuid=3b391cf1-1a00-0000-dfe8-5478dd0c0000 pid=3293->7343de6d-830d-56b8-ab45-cbaef8a44ba8 send: 133B guuid=fec4c2f4-1a00-0000-dfe8-5478e40c0000 pid=3300->7343de6d-830d-56b8-ab45-cbaef8a44ba8 send: 134B guuid=968b7cf8-1a00-0000-dfe8-5478e90c0000 pid=3305->7343de6d-830d-56b8-ab45-cbaef8a44ba8 send: 134B guuid=1a0db3fd-1a00-0000-dfe8-5478f80c0000 pid=3320->7343de6d-830d-56b8-ab45-cbaef8a44ba8 send: 135B guuid=1718a102-1b00-0000-dfe8-5478040d0000 pid=3332->7343de6d-830d-56b8-ab45-cbaef8a44ba8 send: 134B guuid=0c428a07-1b00-0000-dfe8-5478120d0000 pid=3346->7343de6d-830d-56b8-ab45-cbaef8a44ba8 send: 134B guuid=0e405f0d-1b00-0000-dfe8-5478210d0000 pid=3361->7343de6d-830d-56b8-ab45-cbaef8a44ba8 send: 134B guuid=53000311-1b00-0000-dfe8-54782b0d0000 pid=3371->7343de6d-830d-56b8-ab45-cbaef8a44ba8 send: 133B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-04-16 03:12:10 UTC
File Type:
Text (Shell)
AV detection:
24 of 38 (63.16%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments