MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b5426740520fd58c7501b938acdb81ea0fff8ad57c6e1333bb4af34722edfa1a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: b5426740520fd58c7501b938acdb81ea0fff8ad57c6e1333bb4af34722edfa1a
SHA3-384 hash: 94e9ecb506664d21a3ea8a461091c4f3b4ca2f65e1071e2dcd3655dc32068fa4cc26bc6751e6779e1392d2b2dbe62ce0
SHA1 hash: 18e9429454c0fedd290ad4f0f7083c4522484e97
MD5 hash: a94f2672d6a67262ef77fc2a014bc3ab
humanhash: steak-utah-nitrogen-jig
File name:bins.sh
Download: download sample
File size:2'089 bytes
First seen:2026-03-17 20:22:33 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:1QKfjEsjN/fUPsRBTVddTf2Jsj3JSUlxR19R3N5n78xcHJ0:1QK7EsjtsPsrTLdTeJsT8UHfnX78IC
TLSH T18041E7C710E13931BCB0A957B2798407B6C4909F08FBAF466CED78E6E1BCE546415E93
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://83.229.17.114/Okami.mipsn/an/aelf ua-wget
http://83.229.17.114/Okami.mpsln/an/aelf ua-wget
http://83.229.17.114/Okami.sh4n/an/aelf ua-wget
http://83.229.17.114/Okami.x86n/an/aelf ua-wget
http://83.229.17.114/Okami.arm6n/an/aelf ua-wget
http://83.229.17.114/Okami.i686n/an/aelf ua-wget
http://83.229.17.114/Okami.ppcn/an/aelf ua-wget
http://83.229.17.114/Okami.i586n/an/aelf ua-wget
http://83.229.17.114/Okami.m68kn/an/aelf ua-wget
http://83.229.17.114/Okami.sparcn/an/aelf ua-wget
http://83.229.17.114/Okami.arm4n/an/aelf ua-wget
http://83.229.17.114/Okami.arm5n/an/aelf ua-wget
http://83.229.17.114/Okami.arm7n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
55
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive medusa mirai
Verdict:
Malicious
File Type:
text
Detections:
HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=62b24f60-1800-0000-4f9d-59da900c0000 pid=3216 /usr/bin/sudo guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221 /tmp/sample.bin guuid=62b24f60-1800-0000-4f9d-59da900c0000 pid=3216->guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221 execve guuid=45cab462-1800-0000-4f9d-59da970c0000 pid=3223 /usr/bin/wget net send-data guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=45cab462-1800-0000-4f9d-59da970c0000 pid=3223 execve guuid=70841b76-1800-0000-4f9d-59daad0c0000 pid=3245 /usr/bin/chmod guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=70841b76-1800-0000-4f9d-59daad0c0000 pid=3245 execve guuid=53286276-1800-0000-4f9d-59daaf0c0000 pid=3247 /usr/bin/dash guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=53286276-1800-0000-4f9d-59daaf0c0000 pid=3247 clone guuid=b1077676-1800-0000-4f9d-59dab00c0000 pid=3248 /usr/bin/rm guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=b1077676-1800-0000-4f9d-59dab00c0000 pid=3248 execve guuid=c003dc76-1800-0000-4f9d-59dab20c0000 pid=3250 /usr/bin/wget net send-data guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=c003dc76-1800-0000-4f9d-59dab20c0000 pid=3250 execve guuid=cb9db487-1800-0000-4f9d-59dabf0c0000 pid=3263 /usr/bin/chmod guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=cb9db487-1800-0000-4f9d-59dabf0c0000 pid=3263 execve guuid=994ffc87-1800-0000-4f9d-59dac10c0000 pid=3265 /usr/bin/dash guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=994ffc87-1800-0000-4f9d-59dac10c0000 pid=3265 clone guuid=650d0888-1800-0000-4f9d-59dac20c0000 pid=3266 /usr/bin/rm guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=650d0888-1800-0000-4f9d-59dac20c0000 pid=3266 execve guuid=bf114a88-1800-0000-4f9d-59dac30c0000 pid=3267 /usr/bin/wget net send-data guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=bf114a88-1800-0000-4f9d-59dac30c0000 pid=3267 execve guuid=d9294199-1800-0000-4f9d-59daed0c0000 pid=3309 /usr/bin/chmod guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=d9294199-1800-0000-4f9d-59daed0c0000 pid=3309 execve guuid=9b90ec99-1800-0000-4f9d-59daf00c0000 pid=3312 /usr/bin/dash guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=9b90ec99-1800-0000-4f9d-59daf00c0000 pid=3312 clone guuid=89ddfc99-1800-0000-4f9d-59daf10c0000 pid=3313 /usr/bin/rm guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=89ddfc99-1800-0000-4f9d-59daf10c0000 pid=3313 execve guuid=e06da49a-1800-0000-4f9d-59daf40c0000 pid=3316 /usr/bin/wget net send-data guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=e06da49a-1800-0000-4f9d-59daf40c0000 pid=3316 execve guuid=920862ab-1800-0000-4f9d-59da090d0000 pid=3337 /usr/bin/chmod guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=920862ab-1800-0000-4f9d-59da090d0000 pid=3337 execve guuid=4d68adab-1800-0000-4f9d-59da0a0d0000 pid=3338 /usr/bin/dash guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=4d68adab-1800-0000-4f9d-59da0a0d0000 pid=3338 clone guuid=78a2c0ab-1800-0000-4f9d-59da0b0d0000 pid=3339 /usr/bin/rm guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=78a2c0ab-1800-0000-4f9d-59da0b0d0000 pid=3339 execve guuid=786f06ac-1800-0000-4f9d-59da0c0d0000 pid=3340 /usr/bin/wget net send-data guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=786f06ac-1800-0000-4f9d-59da0c0d0000 pid=3340 execve guuid=4a0b76bc-1800-0000-4f9d-59da330d0000 pid=3379 /usr/bin/chmod guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=4a0b76bc-1800-0000-4f9d-59da330d0000 pid=3379 execve guuid=5564b4bc-1800-0000-4f9d-59da350d0000 pid=3381 /usr/bin/dash guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=5564b4bc-1800-0000-4f9d-59da350d0000 pid=3381 clone guuid=4d2fbebc-1800-0000-4f9d-59da360d0000 pid=3382 /usr/bin/rm guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=4d2fbebc-1800-0000-4f9d-59da360d0000 pid=3382 execve guuid=152afabc-1800-0000-4f9d-59da380d0000 pid=3384 /usr/bin/wget net send-data guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=152afabc-1800-0000-4f9d-59da380d0000 pid=3384 execve guuid=06b0e9cd-1800-0000-4f9d-59da680d0000 pid=3432 /usr/bin/chmod guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=06b0e9cd-1800-0000-4f9d-59da680d0000 pid=3432 execve guuid=2bc35bce-1800-0000-4f9d-59da6a0d0000 pid=3434 /usr/bin/dash guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=2bc35bce-1800-0000-4f9d-59da6a0d0000 pid=3434 clone guuid=30c46ace-1800-0000-4f9d-59da6b0d0000 pid=3435 /usr/bin/rm guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=30c46ace-1800-0000-4f9d-59da6b0d0000 pid=3435 execve guuid=9032adce-1800-0000-4f9d-59da6e0d0000 pid=3438 /usr/bin/wget net send-data guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=9032adce-1800-0000-4f9d-59da6e0d0000 pid=3438 execve guuid=85ff8fde-1800-0000-4f9d-59da960d0000 pid=3478 /usr/bin/chmod guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=85ff8fde-1800-0000-4f9d-59da960d0000 pid=3478 execve guuid=c727e5de-1800-0000-4f9d-59da980d0000 pid=3480 /usr/bin/dash guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=c727e5de-1800-0000-4f9d-59da980d0000 pid=3480 clone guuid=2237f4de-1800-0000-4f9d-59da990d0000 pid=3481 /usr/bin/rm guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=2237f4de-1800-0000-4f9d-59da990d0000 pid=3481 execve guuid=9fb232df-1800-0000-4f9d-59da9b0d0000 pid=3483 /usr/bin/wget net send-data guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=9fb232df-1800-0000-4f9d-59da9b0d0000 pid=3483 execve guuid=3387e1ef-1800-0000-4f9d-59dac10d0000 pid=3521 /usr/bin/chmod guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=3387e1ef-1800-0000-4f9d-59dac10d0000 pid=3521 execve guuid=b21529f0-1800-0000-4f9d-59dac30d0000 pid=3523 /usr/bin/dash guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=b21529f0-1800-0000-4f9d-59dac30d0000 pid=3523 clone guuid=94c02ff0-1800-0000-4f9d-59dac40d0000 pid=3524 /usr/bin/rm guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=94c02ff0-1800-0000-4f9d-59dac40d0000 pid=3524 execve guuid=ca9a70f0-1800-0000-4f9d-59dac50d0000 pid=3525 /usr/bin/wget net send-data guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=ca9a70f0-1800-0000-4f9d-59dac50d0000 pid=3525 execve guuid=2e7a5000-1900-0000-4f9d-59dae40d0000 pid=3556 /usr/bin/chmod guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=2e7a5000-1900-0000-4f9d-59dae40d0000 pid=3556 execve guuid=9c32aa00-1900-0000-4f9d-59dae50d0000 pid=3557 /usr/bin/dash guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=9c32aa00-1900-0000-4f9d-59dae50d0000 pid=3557 clone guuid=00c0b800-1900-0000-4f9d-59dae60d0000 pid=3558 /usr/bin/rm guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=00c0b800-1900-0000-4f9d-59dae60d0000 pid=3558 execve guuid=9d810201-1900-0000-4f9d-59dae80d0000 pid=3560 /usr/bin/wget net send-data guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=9d810201-1900-0000-4f9d-59dae80d0000 pid=3560 execve guuid=f9314912-1900-0000-4f9d-59da1e0e0000 pid=3614 /usr/bin/chmod guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=f9314912-1900-0000-4f9d-59da1e0e0000 pid=3614 execve guuid=3b3f8412-1900-0000-4f9d-59da1f0e0000 pid=3615 /usr/bin/dash guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=3b3f8412-1900-0000-4f9d-59da1f0e0000 pid=3615 clone guuid=2d2b8c12-1900-0000-4f9d-59da200e0000 pid=3616 /usr/bin/rm guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=2d2b8c12-1900-0000-4f9d-59da200e0000 pid=3616 execve guuid=efefc612-1900-0000-4f9d-59da220e0000 pid=3618 /usr/bin/wget net send-data guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=efefc612-1900-0000-4f9d-59da220e0000 pid=3618 execve guuid=e953cb23-1900-0000-4f9d-59da540e0000 pid=3668 /usr/bin/chmod guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=e953cb23-1900-0000-4f9d-59da540e0000 pid=3668 execve guuid=08c61b24-1900-0000-4f9d-59da550e0000 pid=3669 /usr/bin/dash guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=08c61b24-1900-0000-4f9d-59da550e0000 pid=3669 clone guuid=6ed62c24-1900-0000-4f9d-59da570e0000 pid=3671 /usr/bin/rm guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=6ed62c24-1900-0000-4f9d-59da570e0000 pid=3671 execve guuid=df2fac24-1900-0000-4f9d-59da590e0000 pid=3673 /usr/bin/wget net send-data guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=df2fac24-1900-0000-4f9d-59da590e0000 pid=3673 execve guuid=dc628e34-1900-0000-4f9d-59da760e0000 pid=3702 /usr/bin/chmod guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=dc628e34-1900-0000-4f9d-59da760e0000 pid=3702 execve guuid=9c85fb34-1900-0000-4f9d-59da770e0000 pid=3703 /usr/bin/dash guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=9c85fb34-1900-0000-4f9d-59da770e0000 pid=3703 clone guuid=cdc31135-1900-0000-4f9d-59da780e0000 pid=3704 /usr/bin/rm guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=cdc31135-1900-0000-4f9d-59da780e0000 pid=3704 execve guuid=a6808235-1900-0000-4f9d-59da790e0000 pid=3705 /usr/bin/wget net send-data guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=a6808235-1900-0000-4f9d-59da790e0000 pid=3705 execve guuid=b8dcf246-1900-0000-4f9d-59da940e0000 pid=3732 /usr/bin/chmod guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=b8dcf246-1900-0000-4f9d-59da940e0000 pid=3732 execve guuid=08cd2d47-1900-0000-4f9d-59da950e0000 pid=3733 /usr/bin/dash guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=08cd2d47-1900-0000-4f9d-59da950e0000 pid=3733 clone guuid=0f943247-1900-0000-4f9d-59da970e0000 pid=3735 /usr/bin/rm guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=0f943247-1900-0000-4f9d-59da970e0000 pid=3735 execve guuid=1b058047-1900-0000-4f9d-59da980e0000 pid=3736 /usr/bin/wget net send-data guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=1b058047-1900-0000-4f9d-59da980e0000 pid=3736 execve guuid=b0b14f58-1900-0000-4f9d-59dae10e0000 pid=3809 /usr/bin/chmod guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=b0b14f58-1900-0000-4f9d-59dae10e0000 pid=3809 execve guuid=50018d58-1900-0000-4f9d-59dae30e0000 pid=3811 /usr/bin/dash guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=50018d58-1900-0000-4f9d-59dae30e0000 pid=3811 clone guuid=78129858-1900-0000-4f9d-59dae40e0000 pid=3812 /usr/bin/rm guuid=b19b6b62-1800-0000-4f9d-59da950c0000 pid=3221->guuid=78129858-1900-0000-4f9d-59dae40e0000 pid=3812 execve d36d56f8-abc3-5ed0-a599-5201d0e14e28 83.229.17.114:80 guuid=45cab462-1800-0000-4f9d-59da970c0000 pid=3223->d36d56f8-abc3-5ed0-a599-5201d0e14e28 send: 138B guuid=c003dc76-1800-0000-4f9d-59dab20c0000 pid=3250->d36d56f8-abc3-5ed0-a599-5201d0e14e28 send: 138B guuid=bf114a88-1800-0000-4f9d-59dac30c0000 pid=3267->d36d56f8-abc3-5ed0-a599-5201d0e14e28 send: 137B guuid=e06da49a-1800-0000-4f9d-59daf40c0000 pid=3316->d36d56f8-abc3-5ed0-a599-5201d0e14e28 send: 137B guuid=786f06ac-1800-0000-4f9d-59da0c0d0000 pid=3340->d36d56f8-abc3-5ed0-a599-5201d0e14e28 send: 138B guuid=152afabc-1800-0000-4f9d-59da380d0000 pid=3384->d36d56f8-abc3-5ed0-a599-5201d0e14e28 send: 138B guuid=9032adce-1800-0000-4f9d-59da6e0d0000 pid=3438->d36d56f8-abc3-5ed0-a599-5201d0e14e28 send: 137B guuid=9fb232df-1800-0000-4f9d-59da9b0d0000 pid=3483->d36d56f8-abc3-5ed0-a599-5201d0e14e28 send: 138B guuid=ca9a70f0-1800-0000-4f9d-59dac50d0000 pid=3525->d36d56f8-abc3-5ed0-a599-5201d0e14e28 send: 138B guuid=9d810201-1900-0000-4f9d-59dae80d0000 pid=3560->d36d56f8-abc3-5ed0-a599-5201d0e14e28 send: 139B guuid=efefc612-1900-0000-4f9d-59da220e0000 pid=3618->d36d56f8-abc3-5ed0-a599-5201d0e14e28 send: 138B guuid=df2fac24-1900-0000-4f9d-59da590e0000 pid=3673->d36d56f8-abc3-5ed0-a599-5201d0e14e28 send: 138B guuid=a6808235-1900-0000-4f9d-59da790e0000 pid=3705->d36d56f8-abc3-5ed0-a599-5201d0e14e28 send: 138B guuid=1b058047-1900-0000-4f9d-59da980e0000 pid=3736->d36d56f8-abc3-5ed0-a599-5201d0e14e28 send: 137B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-03-17 20:16:59 UTC
File Type:
Text (Shell)
AV detection:
17 of 24 (70.83%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh b5426740520fd58c7501b938acdb81ea0fff8ad57c6e1333bb4af34722edfa1a

(this sample)

  
Delivery method
Distributed via web download

Comments