MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a067ca095a064d38fdeb9bfbc2411617249e4e1f90480b28d2bb3a417bc55794. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: a067ca095a064d38fdeb9bfbc2411617249e4e1f90480b28d2bb3a417bc55794
SHA3-384 hash: 7ac744d0ccd85edbc6f74cc190725ce76e4c26f7677513c3eef7ef8c37063f38c1e03de53a11ad3d96d582871f4d8df9
SHA1 hash: 54678733707eb4e47897828a9fae8c94081f3a37
MD5 hash: ce60113b7edb6c514304c5460da208be
humanhash: crazy-white-bacon-kansas
File name:ohshit.sh
Download: download sample
File size:2'224 bytes
First seen:2026-03-05 16:45:45 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:ipKevUp9yevUp93evUpVevUpPevUp1evUp/OevUpkevUpBevUpYevUpHevUp7ev2:i/vUlvUKvUivUcvUqvUjvUxvUSvUdvU/
TLSH T1AF4118C951D25032ECF6E922B2F9898072C094C7A4CA3E5CE8DC39F5D4DCD48B666B97
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139.20//n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
51
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=6c8f60fd-1800-0000-973a-36330c0a0000 pid=2572 /usr/bin/sudo guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578 /tmp/sample.bin guuid=6c8f60fd-1800-0000-973a-36330c0a0000 pid=2572->guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578 execve guuid=72336fff-1800-0000-973a-3633140a0000 pid=2580 /usr/bin/cp guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=72336fff-1800-0000-973a-3633140a0000 pid=2580 execve guuid=a808ff03-1900-0000-973a-3633200a0000 pid=2592 /usr/bin/wget net send-data write-file guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=a808ff03-1900-0000-973a-3633200a0000 pid=2592 execve guuid=a364b40a-1900-0000-973a-3633370a0000 pid=2615 /usr/bin/curl guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=a364b40a-1900-0000-973a-3633370a0000 pid=2615 execve guuid=6ac58012-1900-0000-973a-36334d0a0000 pid=2637 /usr/bin/chmod guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=6ac58012-1900-0000-973a-36334d0a0000 pid=2637 execve guuid=7e6ed312-1900-0000-973a-36334f0a0000 pid=2639 /usr/bin/bash guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=7e6ed312-1900-0000-973a-36334f0a0000 pid=2639 clone guuid=451e5d15-1900-0000-973a-3633590a0000 pid=2649 /usr/bin/wget net send-data write-file guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=451e5d15-1900-0000-973a-3633590a0000 pid=2649 execve guuid=6f84b518-1900-0000-973a-3633640a0000 pid=2660 /usr/bin/curl guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=6f84b518-1900-0000-973a-3633640a0000 pid=2660 execve guuid=b2743d1a-1900-0000-973a-3633690a0000 pid=2665 /usr/bin/chmod guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=b2743d1a-1900-0000-973a-3633690a0000 pid=2665 execve guuid=b759af1a-1900-0000-973a-36336b0a0000 pid=2667 /usr/bin/bash guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=b759af1a-1900-0000-973a-36336b0a0000 pid=2667 clone guuid=f49a821b-1900-0000-973a-36336f0a0000 pid=2671 /usr/bin/wget net send-data write-file guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=f49a821b-1900-0000-973a-36336f0a0000 pid=2671 execve guuid=09e91e20-1900-0000-973a-36337f0a0000 pid=2687 /usr/bin/curl guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=09e91e20-1900-0000-973a-36337f0a0000 pid=2687 execve guuid=ca27f121-1900-0000-973a-3633860a0000 pid=2694 /usr/bin/chmod guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=ca27f121-1900-0000-973a-3633860a0000 pid=2694 execve guuid=685c3c22-1900-0000-973a-3633880a0000 pid=2696 /usr/bin/bash guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=685c3c22-1900-0000-973a-3633880a0000 pid=2696 clone guuid=f3770624-1900-0000-973a-36338f0a0000 pid=2703 /usr/bin/wget net send-data write-file guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=f3770624-1900-0000-973a-36338f0a0000 pid=2703 execve guuid=e9cb9527-1900-0000-973a-36339b0a0000 pid=2715 /usr/bin/curl guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=e9cb9527-1900-0000-973a-36339b0a0000 pid=2715 execve guuid=d5962829-1900-0000-973a-3633a20a0000 pid=2722 /usr/bin/chmod guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=d5962829-1900-0000-973a-3633a20a0000 pid=2722 execve guuid=b8fb6929-1900-0000-973a-3633a40a0000 pid=2724 /usr/bin/bash guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=b8fb6929-1900-0000-973a-3633a40a0000 pid=2724 clone guuid=6090342b-1900-0000-973a-3633ac0a0000 pid=2732 /usr/bin/wget net send-data write-file guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=6090342b-1900-0000-973a-3633ac0a0000 pid=2732 execve guuid=38e7a42f-1900-0000-973a-3633bc0a0000 pid=2748 /usr/bin/curl guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=38e7a42f-1900-0000-973a-3633bc0a0000 pid=2748 execve guuid=e27b5f32-1900-0000-973a-3633c10a0000 pid=2753 /usr/bin/chmod guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=e27b5f32-1900-0000-973a-3633c10a0000 pid=2753 execve guuid=40f8cc32-1900-0000-973a-3633c30a0000 pid=2755 /usr/bin/bash guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=40f8cc32-1900-0000-973a-3633c30a0000 pid=2755 clone guuid=35185433-1900-0000-973a-3633c70a0000 pid=2759 /usr/bin/wget net send-data guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=35185433-1900-0000-973a-3633c70a0000 pid=2759 execve guuid=c7d6e535-1900-0000-973a-3633ce0a0000 pid=2766 /usr/bin/curl guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=c7d6e535-1900-0000-973a-3633ce0a0000 pid=2766 execve guuid=efe4e437-1900-0000-973a-3633d40a0000 pid=2772 /usr/bin/chmod guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=efe4e437-1900-0000-973a-3633d40a0000 pid=2772 execve guuid=91cf3338-1900-0000-973a-3633d60a0000 pid=2774 /usr/bin/bash guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=91cf3338-1900-0000-973a-3633d60a0000 pid=2774 clone guuid=9d6c8439-1900-0000-973a-3633db0a0000 pid=2779 /usr/bin/wget net send-data write-file guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=9d6c8439-1900-0000-973a-3633db0a0000 pid=2779 execve guuid=accba73d-1900-0000-973a-3633e50a0000 pid=2789 /usr/bin/curl guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=accba73d-1900-0000-973a-3633e50a0000 pid=2789 execve guuid=39498142-1900-0000-973a-3633e60a0000 pid=2790 /usr/bin/chmod guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=39498142-1900-0000-973a-3633e60a0000 pid=2790 execve guuid=0bf0d542-1900-0000-973a-3633e70a0000 pid=2791 /usr/bin/bash guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=0bf0d542-1900-0000-973a-3633e70a0000 pid=2791 clone guuid=72fd8043-1900-0000-973a-3633ea0a0000 pid=2794 /usr/bin/wget net send-data guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=72fd8043-1900-0000-973a-3633ea0a0000 pid=2794 execve guuid=6cb5b147-1900-0000-973a-3633f20a0000 pid=2802 /usr/bin/curl guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=6cb5b147-1900-0000-973a-3633f20a0000 pid=2802 execve guuid=2acd4849-1900-0000-973a-3633f60a0000 pid=2806 /usr/bin/chmod guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=2acd4849-1900-0000-973a-3633f60a0000 pid=2806 execve guuid=e9888f49-1900-0000-973a-3633f80a0000 pid=2808 /usr/bin/bash guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=e9888f49-1900-0000-973a-3633f80a0000 pid=2808 clone guuid=d602314a-1900-0000-973a-3633fc0a0000 pid=2812 /usr/bin/wget net send-data guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=d602314a-1900-0000-973a-3633fc0a0000 pid=2812 execve guuid=c06bcd4c-1900-0000-973a-3633010b0000 pid=2817 /usr/bin/curl guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=c06bcd4c-1900-0000-973a-3633010b0000 pid=2817 execve guuid=aae7dd4e-1900-0000-973a-3633060b0000 pid=2822 /usr/bin/chmod guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=aae7dd4e-1900-0000-973a-3633060b0000 pid=2822 execve guuid=671e2f4f-1900-0000-973a-3633070b0000 pid=2823 /usr/bin/bash guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=671e2f4f-1900-0000-973a-3633070b0000 pid=2823 clone guuid=d8cdc04f-1900-0000-973a-36330b0b0000 pid=2827 /usr/bin/wget net send-data guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=d8cdc04f-1900-0000-973a-36330b0b0000 pid=2827 execve guuid=ab3f4a52-1900-0000-973a-3633120b0000 pid=2834 /usr/bin/curl guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=ab3f4a52-1900-0000-973a-3633120b0000 pid=2834 execve guuid=cd19c853-1900-0000-973a-3633150b0000 pid=2837 /usr/bin/chmod guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=cd19c853-1900-0000-973a-3633150b0000 pid=2837 execve guuid=8d6f0854-1900-0000-973a-3633170b0000 pid=2839 /usr/bin/bash guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=8d6f0854-1900-0000-973a-3633170b0000 pid=2839 clone guuid=c12d8a54-1900-0000-973a-3633190b0000 pid=2841 /usr/bin/wget net send-data guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=c12d8a54-1900-0000-973a-3633190b0000 pid=2841 execve guuid=f0fb3f57-1900-0000-973a-3633200b0000 pid=2848 /usr/bin/curl guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=f0fb3f57-1900-0000-973a-3633200b0000 pid=2848 execve guuid=e275bf59-1900-0000-973a-3633210b0000 pid=2849 /usr/bin/chmod guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=e275bf59-1900-0000-973a-3633210b0000 pid=2849 execve guuid=a5cf085a-1900-0000-973a-3633230b0000 pid=2851 /usr/bin/bash guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=a5cf085a-1900-0000-973a-3633230b0000 pid=2851 clone guuid=a09fac5a-1900-0000-973a-3633250b0000 pid=2853 /usr/bin/wget net send-data write-file guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=a09fac5a-1900-0000-973a-3633250b0000 pid=2853 execve guuid=6efee65e-1900-0000-973a-36332d0b0000 pid=2861 /usr/bin/curl guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=6efee65e-1900-0000-973a-36332d0b0000 pid=2861 execve guuid=d5a3bb61-1900-0000-973a-3633330b0000 pid=2867 /usr/bin/chmod guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=d5a3bb61-1900-0000-973a-3633330b0000 pid=2867 execve guuid=f1190462-1900-0000-973a-3633350b0000 pid=2869 /usr/bin/bash guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=f1190462-1900-0000-973a-3633350b0000 pid=2869 clone guuid=6accdf62-1900-0000-973a-3633390b0000 pid=2873 /usr/bin/wget net send-data guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=6accdf62-1900-0000-973a-3633390b0000 pid=2873 execve guuid=a100f365-1900-0000-973a-36333f0b0000 pid=2879 /usr/bin/curl guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=a100f365-1900-0000-973a-36333f0b0000 pid=2879 execve guuid=7b1a7b67-1900-0000-973a-3633430b0000 pid=2883 /usr/bin/chmod guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=7b1a7b67-1900-0000-973a-3633430b0000 pid=2883 execve guuid=8f3ec367-1900-0000-973a-3633440b0000 pid=2884 /usr/bin/bash guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=8f3ec367-1900-0000-973a-3633440b0000 pid=2884 clone guuid=4c011569-1900-0000-973a-36334a0b0000 pid=2890 /usr/bin/wget net send-data write-file guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=4c011569-1900-0000-973a-36334a0b0000 pid=2890 execve guuid=bf266c6d-1900-0000-973a-3633550b0000 pid=2901 /usr/bin/curl guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=bf266c6d-1900-0000-973a-3633550b0000 pid=2901 execve guuid=5e823670-1900-0000-973a-36335c0b0000 pid=2908 /usr/bin/chmod guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=5e823670-1900-0000-973a-36335c0b0000 pid=2908 execve guuid=2913b470-1900-0000-973a-36335d0b0000 pid=2909 /usr/bin/bash guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=2913b470-1900-0000-973a-36335d0b0000 pid=2909 clone guuid=453d5471-1900-0000-973a-3633600b0000 pid=2912 /usr/bin/wget net send-data write-file guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=453d5471-1900-0000-973a-3633600b0000 pid=2912 execve guuid=8c71f474-1900-0000-973a-3633670b0000 pid=2919 /usr/bin/curl guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=8c71f474-1900-0000-973a-3633670b0000 pid=2919 execve guuid=79a88f76-1900-0000-973a-36336c0b0000 pid=2924 /usr/bin/chmod guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=79a88f76-1900-0000-973a-36336c0b0000 pid=2924 execve guuid=8427df76-1900-0000-973a-36336f0b0000 pid=2927 /usr/bin/bash guuid=c5f516ff-1800-0000-973a-3633120a0000 pid=2578->guuid=8427df76-1900-0000-973a-36336f0b0000 pid=2927 clone c4df3de5-aa34-5ca6-a182-7abf89fe7219 176.65.139.20:80 guuid=a808ff03-1900-0000-973a-3633200a0000 pid=2592->c4df3de5-aa34-5ca6-a182-7abf89fe7219 send: 132B guuid=451e5d15-1900-0000-973a-3633590a0000 pid=2649->c4df3de5-aa34-5ca6-a182-7abf89fe7219 send: 132B guuid=f49a821b-1900-0000-973a-36336f0a0000 pid=2671->c4df3de5-aa34-5ca6-a182-7abf89fe7219 send: 135B guuid=f3770624-1900-0000-973a-36338f0a0000 pid=2703->c4df3de5-aa34-5ca6-a182-7abf89fe7219 send: 133B guuid=6090342b-1900-0000-973a-3633ac0a0000 pid=2732->c4df3de5-aa34-5ca6-a182-7abf89fe7219 send: 133B guuid=35185433-1900-0000-973a-3633c70a0000 pid=2759->c4df3de5-aa34-5ca6-a182-7abf89fe7219 send: 135B guuid=9d6c8439-1900-0000-973a-3633db0a0000 pid=2779->c4df3de5-aa34-5ca6-a182-7abf89fe7219 send: 133B guuid=72fd8043-1900-0000-973a-3633ea0a0000 pid=2794->c4df3de5-aa34-5ca6-a182-7abf89fe7219 send: 132B guuid=d602314a-1900-0000-973a-3633fc0a0000 pid=2812->c4df3de5-aa34-5ca6-a182-7abf89fe7219 send: 133B guuid=d8cdc04f-1900-0000-973a-36330b0b0000 pid=2827->c4df3de5-aa34-5ca6-a182-7abf89fe7219 send: 133B guuid=c12d8a54-1900-0000-973a-3633190b0000 pid=2841->c4df3de5-aa34-5ca6-a182-7abf89fe7219 send: 133B guuid=a09fac5a-1900-0000-973a-3633250b0000 pid=2853->c4df3de5-aa34-5ca6-a182-7abf89fe7219 send: 132B guuid=6accdf62-1900-0000-973a-3633390b0000 pid=2873->c4df3de5-aa34-5ca6-a182-7abf89fe7219 send: 134B guuid=4c011569-1900-0000-973a-36334a0b0000 pid=2890->c4df3de5-aa34-5ca6-a182-7abf89fe7219 send: 133B guuid=453d5471-1900-0000-973a-3633600b0000 pid=2912->c4df3de5-aa34-5ca6-a182-7abf89fe7219 send: 132B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-03-05 16:46:46 UTC
File Type:
Text (Shell)
AV detection:
20 of 36 (55.56%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh a067ca095a064d38fdeb9bfbc2411617249e4e1f90480b28d2bb3a417bc55794

(this sample)

  
Delivery method
Distributed via web download

Comments