MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9e8a2493b96409cf70dffce708f33b4c478d80de38c98451a855648b0ffcf8a4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: 9e8a2493b96409cf70dffce708f33b4c478d80de38c98451a855648b0ffcf8a4
SHA3-384 hash: e347b8ffa5a231188d970a2c9ad694a8ed0bd867fd2f022e8b1f677e0cd9df5a7f53af302f2c9c142ba1cb59d32a51d3
SHA1 hash: fa0dfcacf9bb56c4b1ceba40c5cb8a9ef24876e8
MD5 hash: bd9b4c3a652fb3b42c001da75cec4264
humanhash: red-east-pizza-rugby
File name:1.sh
Download: download sample
File size:3'284 bytes
First seen:2025-12-26 20:10:17 UTC
Last seen:2025-12-27 02:40:17 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:It+Ars+Z6+iw+lcT+3ps+bu+O1OnJ+4QL+TA1L+414NIAks+Ru+3o3+6IL+si3+1:imZIhjjZIJqvLkJl130Lk5Y
TLSH T1A86170A5245206BA6CB5EF2732AD4614368788B63CFF3F49E5DC3DE980ACE56F440742
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://203.161.47.180/windyloveyou/windy.x86n/an/aelf ua-wget
http://203.161.47.180/windyloveyou/windy.mipsn/an/aelf ua-wget
http://203.161.47.180/windyloveyou/windy.arcn/an/aelf ua-wget
http://203.161.47.180/windyloveyou/windy.i468n/an/aelf ua-wget
http://203.161.47.180/windyloveyou/windy.i686n/an/aelf ua-wget
http://203.161.47.180/windyloveyou/windy.x86_64n/an/aelf ua-wget
http://203.161.47.180/windyloveyou/windy.mpsln/an/aelf ua-wget
http://203.161.47.180/windyloveyou/windy.armn/an/aelf ua-wget
http://203.161.47.180/windyloveyou/windy.arm5n/an/aelf ua-wget
http://203.161.47.180/windyloveyou/windy.arm6n/an/aelf ua-wget
http://203.161.47.180/windyloveyou/windy.arm7n/an/aelf ua-wget
http://203.161.47.180/windyloveyou/windy.ppcn/an/aelf ua-wget
http://203.161.47.180/windyloveyou/windy.spcn/an/aelf ua-wget
http://203.161.47.180/windyloveyou/windy.m68kn/an/aelf ua-wget
http://203.161.47.180/windyloveyou/windy.sh4n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
27
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive medusa mirai
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=8da3befc-1900-0000-3a37-bc4d8b0b0000 pid=2955 /usr/bin/sudo guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958 /tmp/sample.bin guuid=8da3befc-1900-0000-3a37-bc4d8b0b0000 pid=2955->guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958 execve guuid=aa042b01-1a00-0000-3a37-bc4d920b0000 pid=2962 /usr/bin/cp guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=aa042b01-1a00-0000-3a37-bc4d920b0000 pid=2962 execve guuid=186b1409-1a00-0000-3a37-bc4d9d0b0000 pid=2973 /usr/bin/wget net send-data guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=186b1409-1a00-0000-3a37-bc4d9d0b0000 pid=2973 execve guuid=f29f411e-1a00-0000-3a37-bc4dca0b0000 pid=3018 /usr/bin/curl net send-data write-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=f29f411e-1a00-0000-3a37-bc4dca0b0000 pid=3018 execve guuid=dd915737-1a00-0000-3a37-bc4d110c0000 pid=3089 /usr/bin/chmod guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=dd915737-1a00-0000-3a37-bc4d110c0000 pid=3089 execve guuid=8d499a37-1a00-0000-3a37-bc4d130c0000 pid=3091 /usr/bin/bash guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=8d499a37-1a00-0000-3a37-bc4d130c0000 pid=3091 clone guuid=5049b837-1a00-0000-3a37-bc4d140c0000 pid=3092 /usr/bin/rm delete-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=5049b837-1a00-0000-3a37-bc4d140c0000 pid=3092 execve guuid=89270438-1a00-0000-3a37-bc4d150c0000 pid=3093 /usr/bin/wget net send-data guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=89270438-1a00-0000-3a37-bc4d150c0000 pid=3093 execve guuid=0a51ff49-1a00-0000-3a37-bc4d430c0000 pid=3139 /usr/bin/curl net send-data write-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=0a51ff49-1a00-0000-3a37-bc4d430c0000 pid=3139 execve guuid=5adecc60-1a00-0000-3a37-bc4d740c0000 pid=3188 /usr/bin/chmod guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=5adecc60-1a00-0000-3a37-bc4d740c0000 pid=3188 execve guuid=651b3d61-1a00-0000-3a37-bc4d770c0000 pid=3191 /usr/bin/bash guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=651b3d61-1a00-0000-3a37-bc4d770c0000 pid=3191 clone guuid=94a86061-1a00-0000-3a37-bc4d780c0000 pid=3192 /usr/bin/rm delete-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=94a86061-1a00-0000-3a37-bc4d780c0000 pid=3192 execve guuid=233ccc61-1a00-0000-3a37-bc4d7a0c0000 pid=3194 /usr/bin/wget net send-data guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=233ccc61-1a00-0000-3a37-bc4d7a0c0000 pid=3194 execve guuid=4465b873-1a00-0000-3a37-bc4d860c0000 pid=3206 /usr/bin/curl net send-data write-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=4465b873-1a00-0000-3a37-bc4d860c0000 pid=3206 execve guuid=c29fba87-1a00-0000-3a37-bc4da10c0000 pid=3233 /usr/bin/chmod guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=c29fba87-1a00-0000-3a37-bc4da10c0000 pid=3233 execve guuid=62dd4e88-1a00-0000-3a37-bc4da20c0000 pid=3234 /usr/bin/bash guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=62dd4e88-1a00-0000-3a37-bc4da20c0000 pid=3234 clone guuid=50d68988-1a00-0000-3a37-bc4da30c0000 pid=3235 /usr/bin/rm delete-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=50d68988-1a00-0000-3a37-bc4da30c0000 pid=3235 execve guuid=7baef388-1a00-0000-3a37-bc4da40c0000 pid=3236 /usr/bin/wget net send-data guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=7baef388-1a00-0000-3a37-bc4da40c0000 pid=3236 execve guuid=d9c95e9b-1a00-0000-3a37-bc4db30c0000 pid=3251 /usr/bin/curl net send-data write-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=d9c95e9b-1a00-0000-3a37-bc4db30c0000 pid=3251 execve guuid=899a73ae-1a00-0000-3a37-bc4dc70c0000 pid=3271 /usr/bin/chmod guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=899a73ae-1a00-0000-3a37-bc4dc70c0000 pid=3271 execve guuid=79c9daae-1a00-0000-3a37-bc4dc90c0000 pid=3273 /usr/bin/bash guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=79c9daae-1a00-0000-3a37-bc4dc90c0000 pid=3273 clone guuid=fcd708af-1a00-0000-3a37-bc4dca0c0000 pid=3274 /usr/bin/rm delete-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=fcd708af-1a00-0000-3a37-bc4dca0c0000 pid=3274 execve guuid=bf357aaf-1a00-0000-3a37-bc4dcc0c0000 pid=3276 /usr/bin/wget net send-data guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=bf357aaf-1a00-0000-3a37-bc4dcc0c0000 pid=3276 execve guuid=2bd614c2-1a00-0000-3a37-bc4de80c0000 pid=3304 /usr/bin/curl net send-data write-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=2bd614c2-1a00-0000-3a37-bc4de80c0000 pid=3304 execve guuid=cb8223d6-1a00-0000-3a37-bc4d020d0000 pid=3330 /usr/bin/chmod guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=cb8223d6-1a00-0000-3a37-bc4d020d0000 pid=3330 execve guuid=775b6ed6-1a00-0000-3a37-bc4d030d0000 pid=3331 /usr/bin/bash guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=775b6ed6-1a00-0000-3a37-bc4d030d0000 pid=3331 clone guuid=4dda24d7-1a00-0000-3a37-bc4d050d0000 pid=3333 /usr/bin/rm delete-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=4dda24d7-1a00-0000-3a37-bc4d050d0000 pid=3333 execve guuid=36c487d7-1a00-0000-3a37-bc4d060d0000 pid=3334 /usr/bin/wget net send-data guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=36c487d7-1a00-0000-3a37-bc4d060d0000 pid=3334 execve guuid=33bb92ea-1a00-0000-3a37-bc4d200d0000 pid=3360 /usr/bin/curl net send-data write-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=33bb92ea-1a00-0000-3a37-bc4d200d0000 pid=3360 execve guuid=499addfd-1a00-0000-3a37-bc4d450d0000 pid=3397 /usr/bin/chmod guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=499addfd-1a00-0000-3a37-bc4d450d0000 pid=3397 execve guuid=b37129fe-1a00-0000-3a37-bc4d460d0000 pid=3398 /usr/bin/bash guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=b37129fe-1a00-0000-3a37-bc4d460d0000 pid=3398 clone guuid=e29858fe-1a00-0000-3a37-bc4d470d0000 pid=3399 /usr/bin/rm delete-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=e29858fe-1a00-0000-3a37-bc4d470d0000 pid=3399 execve guuid=92e9abfe-1a00-0000-3a37-bc4d490d0000 pid=3401 /usr/bin/wget net send-data guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=92e9abfe-1a00-0000-3a37-bc4d490d0000 pid=3401 execve guuid=3e0e9d10-1b00-0000-3a37-bc4d6c0d0000 pid=3436 /usr/bin/curl net send-data write-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=3e0e9d10-1b00-0000-3a37-bc4d6c0d0000 pid=3436 execve guuid=fd223723-1b00-0000-3a37-bc4da20d0000 pid=3490 /usr/bin/chmod guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=fd223723-1b00-0000-3a37-bc4da20d0000 pid=3490 execve guuid=2c67a623-1b00-0000-3a37-bc4da40d0000 pid=3492 /usr/bin/bash guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=2c67a623-1b00-0000-3a37-bc4da40d0000 pid=3492 clone guuid=c959e523-1b00-0000-3a37-bc4da60d0000 pid=3494 /usr/bin/rm delete-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=c959e523-1b00-0000-3a37-bc4da60d0000 pid=3494 execve guuid=18454924-1b00-0000-3a37-bc4da80d0000 pid=3496 /usr/bin/wget net send-data guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=18454924-1b00-0000-3a37-bc4da80d0000 pid=3496 execve guuid=5fd83936-1b00-0000-3a37-bc4dcd0d0000 pid=3533 /usr/bin/curl net send-data write-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=5fd83936-1b00-0000-3a37-bc4dcd0d0000 pid=3533 execve guuid=274d5149-1b00-0000-3a37-bc4de90d0000 pid=3561 /usr/bin/chmod guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=274d5149-1b00-0000-3a37-bc4de90d0000 pid=3561 execve guuid=9c38bb49-1b00-0000-3a37-bc4dea0d0000 pid=3562 /usr/bin/bash guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=9c38bb49-1b00-0000-3a37-bc4dea0d0000 pid=3562 clone guuid=1982ed49-1b00-0000-3a37-bc4dec0d0000 pid=3564 /usr/bin/rm delete-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=1982ed49-1b00-0000-3a37-bc4dec0d0000 pid=3564 execve guuid=d27d344a-1b00-0000-3a37-bc4dee0d0000 pid=3566 /usr/bin/wget net send-data guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=d27d344a-1b00-0000-3a37-bc4dee0d0000 pid=3566 execve guuid=d3fea15d-1b00-0000-3a37-bc4d1d0e0000 pid=3613 /usr/bin/curl net send-data write-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=d3fea15d-1b00-0000-3a37-bc4d1d0e0000 pid=3613 execve guuid=9816e771-1b00-0000-3a37-bc4d430e0000 pid=3651 /usr/bin/chmod guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=9816e771-1b00-0000-3a37-bc4d430e0000 pid=3651 execve guuid=7ed75172-1b00-0000-3a37-bc4d440e0000 pid=3652 /usr/bin/bash guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=7ed75172-1b00-0000-3a37-bc4d440e0000 pid=3652 clone guuid=a9519172-1b00-0000-3a37-bc4d460e0000 pid=3654 /usr/bin/rm delete-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=a9519172-1b00-0000-3a37-bc4d460e0000 pid=3654 execve guuid=117c1173-1b00-0000-3a37-bc4d480e0000 pid=3656 /usr/bin/wget net send-data guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=117c1173-1b00-0000-3a37-bc4d480e0000 pid=3656 execve guuid=21062d86-1b00-0000-3a37-bc4d7f0e0000 pid=3711 /usr/bin/curl net send-data write-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=21062d86-1b00-0000-3a37-bc4d7f0e0000 pid=3711 execve guuid=e2dbd99a-1b00-0000-3a37-bc4d970e0000 pid=3735 /usr/bin/chmod guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=e2dbd99a-1b00-0000-3a37-bc4d970e0000 pid=3735 execve guuid=e39e419b-1b00-0000-3a37-bc4d990e0000 pid=3737 /usr/bin/bash guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=e39e419b-1b00-0000-3a37-bc4d990e0000 pid=3737 clone guuid=573a6e9b-1b00-0000-3a37-bc4d9b0e0000 pid=3739 /usr/bin/rm delete-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=573a6e9b-1b00-0000-3a37-bc4d9b0e0000 pid=3739 execve guuid=0261d09b-1b00-0000-3a37-bc4d9d0e0000 pid=3741 /usr/bin/wget net send-data guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=0261d09b-1b00-0000-3a37-bc4d9d0e0000 pid=3741 execve guuid=3b6ad6ad-1b00-0000-3a37-bc4dd70e0000 pid=3799 /usr/bin/curl net send-data write-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=3b6ad6ad-1b00-0000-3a37-bc4dd70e0000 pid=3799 execve guuid=d94a15c5-1b00-0000-3a37-bc4d240f0000 pid=3876 /usr/bin/chmod guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=d94a15c5-1b00-0000-3a37-bc4d240f0000 pid=3876 execve guuid=6e2089c5-1b00-0000-3a37-bc4d270f0000 pid=3879 /usr/bin/bash guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=6e2089c5-1b00-0000-3a37-bc4d270f0000 pid=3879 clone guuid=0155c8c5-1b00-0000-3a37-bc4d280f0000 pid=3880 /usr/bin/rm delete-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=0155c8c5-1b00-0000-3a37-bc4d280f0000 pid=3880 execve guuid=88a219c6-1b00-0000-3a37-bc4d2a0f0000 pid=3882 /usr/bin/wget net send-data guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=88a219c6-1b00-0000-3a37-bc4d2a0f0000 pid=3882 execve guuid=43d866d8-1b00-0000-3a37-bc4d5e0f0000 pid=3934 /usr/bin/curl net send-data write-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=43d866d8-1b00-0000-3a37-bc4d5e0f0000 pid=3934 execve guuid=e69119ec-1b00-0000-3a37-bc4d960f0000 pid=3990 /usr/bin/chmod guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=e69119ec-1b00-0000-3a37-bc4d960f0000 pid=3990 execve guuid=fcc865ec-1b00-0000-3a37-bc4d980f0000 pid=3992 /usr/bin/bash guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=fcc865ec-1b00-0000-3a37-bc4d980f0000 pid=3992 clone guuid=bf0487ec-1b00-0000-3a37-bc4d990f0000 pid=3993 /usr/bin/rm delete-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=bf0487ec-1b00-0000-3a37-bc4d990f0000 pid=3993 execve guuid=1f56d1ec-1b00-0000-3a37-bc4d9c0f0000 pid=3996 /usr/bin/wget net send-data guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=1f56d1ec-1b00-0000-3a37-bc4d9c0f0000 pid=3996 execve guuid=1f3031fe-1b00-0000-3a37-bc4dcc0f0000 pid=4044 /usr/bin/curl net send-data write-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=1f3031fe-1b00-0000-3a37-bc4dcc0f0000 pid=4044 execve guuid=5968bb34-1c00-0000-3a37-bc4d83100000 pid=4227 /usr/bin/chmod guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=5968bb34-1c00-0000-3a37-bc4d83100000 pid=4227 execve guuid=e987fa34-1c00-0000-3a37-bc4d87100000 pid=4231 /usr/bin/bash guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=e987fa34-1c00-0000-3a37-bc4d87100000 pid=4231 clone guuid=1a721b35-1c00-0000-3a37-bc4d88100000 pid=4232 /usr/bin/rm delete-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=1a721b35-1c00-0000-3a37-bc4d88100000 pid=4232 execve guuid=da8b6435-1c00-0000-3a37-bc4d8c100000 pid=4236 /usr/bin/wget net send-data guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=da8b6435-1c00-0000-3a37-bc4d8c100000 pid=4236 execve guuid=c4856d47-1c00-0000-3a37-bc4dce100000 pid=4302 /usr/bin/curl net send-data write-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=c4856d47-1c00-0000-3a37-bc4dce100000 pid=4302 execve guuid=12a4b65a-1c00-0000-3a37-bc4d1a110000 pid=4378 /usr/bin/chmod guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=12a4b65a-1c00-0000-3a37-bc4d1a110000 pid=4378 execve guuid=dfae005b-1c00-0000-3a37-bc4d1c110000 pid=4380 /usr/bin/bash guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=dfae005b-1c00-0000-3a37-bc4d1c110000 pid=4380 clone guuid=ba272c5b-1c00-0000-3a37-bc4d1e110000 pid=4382 /usr/bin/rm delete-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=ba272c5b-1c00-0000-3a37-bc4d1e110000 pid=4382 execve guuid=f4db805b-1c00-0000-3a37-bc4d1f110000 pid=4383 /usr/bin/wget net send-data guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=f4db805b-1c00-0000-3a37-bc4d1f110000 pid=4383 execve guuid=aa5e406e-1c00-0000-3a37-bc4d2d110000 pid=4397 /usr/bin/curl net send-data write-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=aa5e406e-1c00-0000-3a37-bc4d2d110000 pid=4397 execve guuid=f82e6d82-1c00-0000-3a37-bc4d71110000 pid=4465 /usr/bin/chmod guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=f82e6d82-1c00-0000-3a37-bc4d71110000 pid=4465 execve guuid=7e55ca82-1c00-0000-3a37-bc4d73110000 pid=4467 /usr/bin/bash guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=7e55ca82-1c00-0000-3a37-bc4d73110000 pid=4467 clone guuid=92deee82-1c00-0000-3a37-bc4d74110000 pid=4468 /usr/bin/rm delete-file guuid=bbe10400-1a00-0000-3a37-bc4d8e0b0000 pid=2958->guuid=92deee82-1c00-0000-3a37-bc4d74110000 pid=4468 execve d6442b31-9bf5-5e4b-b97b-8743732504de 203.161.47.180:80 guuid=186b1409-1a00-0000-3a37-bc4d9d0b0000 pid=2973->d6442b31-9bf5-5e4b-b97b-8743732504de send: 151B guuid=f29f411e-1a00-0000-3a37-bc4dca0b0000 pid=3018->d6442b31-9bf5-5e4b-b97b-8743732504de send: 100B guuid=89270438-1a00-0000-3a37-bc4d150c0000 pid=3093->d6442b31-9bf5-5e4b-b97b-8743732504de send: 152B guuid=0a51ff49-1a00-0000-3a37-bc4d430c0000 pid=3139->d6442b31-9bf5-5e4b-b97b-8743732504de send: 101B guuid=233ccc61-1a00-0000-3a37-bc4d7a0c0000 pid=3194->d6442b31-9bf5-5e4b-b97b-8743732504de send: 151B guuid=4465b873-1a00-0000-3a37-bc4d860c0000 pid=3206->d6442b31-9bf5-5e4b-b97b-8743732504de send: 100B guuid=7baef388-1a00-0000-3a37-bc4da40c0000 pid=3236->d6442b31-9bf5-5e4b-b97b-8743732504de send: 152B guuid=d9c95e9b-1a00-0000-3a37-bc4db30c0000 pid=3251->d6442b31-9bf5-5e4b-b97b-8743732504de send: 101B guuid=bf357aaf-1a00-0000-3a37-bc4dcc0c0000 pid=3276->d6442b31-9bf5-5e4b-b97b-8743732504de send: 152B guuid=2bd614c2-1a00-0000-3a37-bc4de80c0000 pid=3304->d6442b31-9bf5-5e4b-b97b-8743732504de send: 101B guuid=36c487d7-1a00-0000-3a37-bc4d060d0000 pid=3334->d6442b31-9bf5-5e4b-b97b-8743732504de send: 154B guuid=33bb92ea-1a00-0000-3a37-bc4d200d0000 pid=3360->d6442b31-9bf5-5e4b-b97b-8743732504de send: 103B guuid=92e9abfe-1a00-0000-3a37-bc4d490d0000 pid=3401->d6442b31-9bf5-5e4b-b97b-8743732504de send: 152B guuid=3e0e9d10-1b00-0000-3a37-bc4d6c0d0000 pid=3436->d6442b31-9bf5-5e4b-b97b-8743732504de send: 101B guuid=18454924-1b00-0000-3a37-bc4da80d0000 pid=3496->d6442b31-9bf5-5e4b-b97b-8743732504de send: 151B guuid=5fd83936-1b00-0000-3a37-bc4dcd0d0000 pid=3533->d6442b31-9bf5-5e4b-b97b-8743732504de send: 100B guuid=d27d344a-1b00-0000-3a37-bc4dee0d0000 pid=3566->d6442b31-9bf5-5e4b-b97b-8743732504de send: 152B guuid=d3fea15d-1b00-0000-3a37-bc4d1d0e0000 pid=3613->d6442b31-9bf5-5e4b-b97b-8743732504de send: 101B guuid=117c1173-1b00-0000-3a37-bc4d480e0000 pid=3656->d6442b31-9bf5-5e4b-b97b-8743732504de send: 152B guuid=21062d86-1b00-0000-3a37-bc4d7f0e0000 pid=3711->d6442b31-9bf5-5e4b-b97b-8743732504de send: 101B guuid=0261d09b-1b00-0000-3a37-bc4d9d0e0000 pid=3741->d6442b31-9bf5-5e4b-b97b-8743732504de send: 152B guuid=3b6ad6ad-1b00-0000-3a37-bc4dd70e0000 pid=3799->d6442b31-9bf5-5e4b-b97b-8743732504de send: 101B guuid=88a219c6-1b00-0000-3a37-bc4d2a0f0000 pid=3882->d6442b31-9bf5-5e4b-b97b-8743732504de send: 151B guuid=43d866d8-1b00-0000-3a37-bc4d5e0f0000 pid=3934->d6442b31-9bf5-5e4b-b97b-8743732504de send: 100B guuid=1f56d1ec-1b00-0000-3a37-bc4d9c0f0000 pid=3996->d6442b31-9bf5-5e4b-b97b-8743732504de send: 151B guuid=1f3031fe-1b00-0000-3a37-bc4dcc0f0000 pid=4044->d6442b31-9bf5-5e4b-b97b-8743732504de send: 100B guuid=da8b6435-1c00-0000-3a37-bc4d8c100000 pid=4236->d6442b31-9bf5-5e4b-b97b-8743732504de send: 152B guuid=c4856d47-1c00-0000-3a37-bc4dce100000 pid=4302->d6442b31-9bf5-5e4b-b97b-8743732504de send: 101B guuid=f4db805b-1c00-0000-3a37-bc4d1f110000 pid=4383->d6442b31-9bf5-5e4b-b97b-8743732504de send: 151B guuid=aa5e406e-1c00-0000-3a37-bc4d2d110000 pid=4397->d6442b31-9bf5-5e4b-b97b-8743732504de send: 100B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-12-26 20:11:15 UTC
File Type:
Text (Shell)
AV detection:
21 of 36 (58.33%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 9e8a2493b96409cf70dffce708f33b4c478d80de38c98451a855648b0ffcf8a4

(this sample)

  
Delivery method
Distributed via web download

Comments