🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bd9edfdc9eacc0592a78b59f811fe29cb875aa834f31ccb1909b7a4d37f79726. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: bd9edfdc9eacc0592a78b59f811fe29cb875aa834f31ccb1909b7a4d37f79726
SHA3-384 hash: b215a2aef6c02dea816e8e52b347d2c43665ef63427458b9534cb91a8018204abc1f32822ad097d2da9a24cb2af767c5
SHA1 hash: b51711daf1ed6e35fcb9e67f09efa15cf2da5d36
MD5 hash: 073e184e5bff6b59a329ad32246434a5
humanhash: minnesota-neptune-uniform-fourteen
File name:t.sh
Download: download sample
File size:1'386 bytes
First seen:2026-08-28 19:08:51 UTC
Last seen:2026-08-29 02:53:26 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:3pfc4pt/pqO0p+O+NI7JpgeKZpJa4p8mupYOYs5p65lFpjUHjQt6p7D7NFpF60pE:3pfc4pt/pqO0pPHJpgeipJa4p8bpYOYL
TLSH T1772135CF5090B55385AEEE14B277D9889012E1D321CA2E1FDECC2875C8DC954F36AF54
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter BlinkzSec
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139.226/arc9b1f88a9438254cf36932cf0ab696411ac2891c698f9d98da65569178702a0dd Mirai176-65-139-226 elf mirai ua-wget
http://176.65.139.226/arm51e8bd8f4e5b43fa500919cbfd3336d76ad99f84867112a6ecb8adcda0adba41 Mirai176-65-139-226 elf mirai ua-wget
http://176.65.139.226/arm5276b9063aa94145ff3ffc85d0774827b281c0e2171c9897b841a1aa4aa13e95b Mirai176-65-139-226 elf mirai ua-wget
http://176.65.139.226/arm63eddc12d4ba25b88cb0959661c4e90ffe89179c9f5cac591bdd00505536d378f Mirai176-65-139-226 elf mirai ua-wget
http://176.65.139.226/arm7167eb5695a7e3ea5edc97ff1cc50f1992955e083994df2074b2811fd0487afe8 Mirai176-65-139-226 elf mirai ua-wget
http://176.65.139.226/m68kd7f5cd3b5df8d19f8f1b89ce9e1562b535c1c07706dfdf6780ffd277b38c3ee6 Mirai176-65-139-226 elf mirai ua-wget
http://176.65.139.226/mips94e2c0f81f4831a6a1eeb60b2174bec1d51039debc8e0e440cff8853551a399e Mirai176-65-139-226 elf mirai ua-wget
http://176.65.139.226/mpsl39939eac4508c4a5bb29de62795fe61d409f9d2e6dd8c4552b4c2159fe7b0432 Mirai176-65-139-226 elf mirai ua-wget
http://176.65.139.226/ppc00660f4fff4ca116abf4c18312685c38d50f11bc5410a77c87e90ce1ef4cd1cd Mirai176-65-139-226 elf mirai ua-wget
http://176.65.139.226/sh4fd4f7fa0e014ef1a139c4074bc2d11a58955f219e0debd3ab60d2d18b910e6a3 Mirai176-65-139-226 elf mirai ua-wget
http://176.65.139.226/spc590719983a25e257f9cff35a338db7ad6f09953f3f3730ebc7b3065fb3a4ade3 Mirai176-65-139-226 elf mirai ua-wget
http://176.65.139.226/x862d906364a04607ff90a84bbda506f0bbb9c657d3b91a749e31b3b8cd7d8a5470 Mirai176-65-139-226 elf mirai ua-wget
http://176.65.139.226/x86_6485101584bc0d4334ba8f970cae4ef1d2d4fddd324b2e99a32dc5714f1cd73b69 Mirai176-65-139-226 elf mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
53
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-08-28T17:15:00Z UTC
Last seen:
2026-08-29T20:13:00Z UTC
Hits:
~10
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-08-28 19:08:37 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh bd9edfdc9eacc0592a78b59f811fe29cb875aa834f31ccb1909b7a4d37f79726

(this sample)

  
Delivery method
Distributed via web download

Comments