MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f42c2bbf20a6ff06dab5aed49404a95ca88549304a2dc30a5d6a72f2acd4c11f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: f42c2bbf20a6ff06dab5aed49404a95ca88549304a2dc30a5d6a72f2acd4c11f
SHA3-384 hash: 1167aea26b4f28ecfc8e02d92bb1ce38fd445f0ed6677ff614be86a0b1d9ec641ded5bc03bbad319c09c5de9ac32f3cb
SHA1 hash: d5c832d0da068bdfce5a130d2e6a415993ce1515
MD5 hash: a7c1c21d572fdf2a4fc1ca9e99fd146f
humanhash: diet-kentucky-wyoming-bakerloo
File name:jew.sh
Download: download sample
File size:1'797 bytes
First seen:2026-04-07 10:33:00 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:iXR1X27X+K+AXppXgPX3/XOzXeTe+X17XIg:i3+pr0fGuK+Jj
TLSH T1103198D5118243F46DE1E91B6BB5A6087186A0956CC27FCC78D8B8B8416CFCD9F41AD3
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
40
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-04-07T07:42:00Z UTC
Last seen:
2026-04-07T12:04:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=666c06ec-1900-0000-f1b4-4f9e7e0a0000 pid=2686 /usr/bin/sudo guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698 /tmp/sample.bin guuid=666c06ec-1900-0000-f1b4-4f9e7e0a0000 pid=2686->guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698 execve guuid=52f7b3ef-1900-0000-f1b4-4f9e8b0a0000 pid=2699 /usr/bin/cp guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=52f7b3ef-1900-0000-f1b4-4f9e8b0a0000 pid=2699 execve guuid=90bf71f6-1900-0000-f1b4-4f9e9c0a0000 pid=2716 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=90bf71f6-1900-0000-f1b4-4f9e9c0a0000 pid=2716 clone guuid=8a8a87f6-1900-0000-f1b4-4f9e9d0a0000 pid=2717 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=8a8a87f6-1900-0000-f1b4-4f9e9d0a0000 pid=2717 clone guuid=dda1abf6-1900-0000-f1b4-4f9e9e0a0000 pid=2718 /usr/bin/cat guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=dda1abf6-1900-0000-f1b4-4f9e9e0a0000 pid=2718 execve guuid=a48000f7-1900-0000-f1b4-4f9ea00a0000 pid=2720 /usr/bin/chmod guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=a48000f7-1900-0000-f1b4-4f9ea00a0000 pid=2720 execve guuid=bfdc4cf7-1900-0000-f1b4-4f9ea10a0000 pid=2721 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=bfdc4cf7-1900-0000-f1b4-4f9ea10a0000 pid=2721 clone guuid=4e2a90f9-1900-0000-f1b4-4f9eaa0a0000 pid=2730 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=4e2a90f9-1900-0000-f1b4-4f9eaa0a0000 pid=2730 clone guuid=73beb5f9-1900-0000-f1b4-4f9eab0a0000 pid=2731 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=73beb5f9-1900-0000-f1b4-4f9eab0a0000 pid=2731 clone guuid=d200d2f9-1900-0000-f1b4-4f9ead0a0000 pid=2733 /usr/bin/cat guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=d200d2f9-1900-0000-f1b4-4f9ead0a0000 pid=2733 execve guuid=23e354fa-1900-0000-f1b4-4f9eaf0a0000 pid=2735 /usr/bin/chmod guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=23e354fa-1900-0000-f1b4-4f9eaf0a0000 pid=2735 execve guuid=1fb1d1fa-1900-0000-f1b4-4f9eb10a0000 pid=2737 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=1fb1d1fa-1900-0000-f1b4-4f9eb10a0000 pid=2737 clone guuid=2740d3fc-1900-0000-f1b4-4f9eb80a0000 pid=2744 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=2740d3fc-1900-0000-f1b4-4f9eb80a0000 pid=2744 clone guuid=1374eafc-1900-0000-f1b4-4f9eb90a0000 pid=2745 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=1374eafc-1900-0000-f1b4-4f9eb90a0000 pid=2745 clone guuid=d3a707fd-1900-0000-f1b4-4f9eba0a0000 pid=2746 /usr/bin/cat guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=d3a707fd-1900-0000-f1b4-4f9eba0a0000 pid=2746 execve guuid=990d72fd-1900-0000-f1b4-4f9ebc0a0000 pid=2748 /usr/bin/chmod guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=990d72fd-1900-0000-f1b4-4f9ebc0a0000 pid=2748 execve guuid=ca87c0fd-1900-0000-f1b4-4f9ebd0a0000 pid=2749 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=ca87c0fd-1900-0000-f1b4-4f9ebd0a0000 pid=2749 clone guuid=3fce7bfe-1900-0000-f1b4-4f9ec20a0000 pid=2754 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=3fce7bfe-1900-0000-f1b4-4f9ec20a0000 pid=2754 clone guuid=21079efe-1900-0000-f1b4-4f9ec30a0000 pid=2755 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=21079efe-1900-0000-f1b4-4f9ec30a0000 pid=2755 clone guuid=eaf6cafe-1900-0000-f1b4-4f9ec40a0000 pid=2756 /usr/bin/cat guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=eaf6cafe-1900-0000-f1b4-4f9ec40a0000 pid=2756 execve guuid=959333ff-1900-0000-f1b4-4f9ec50a0000 pid=2757 /usr/bin/chmod guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=959333ff-1900-0000-f1b4-4f9ec50a0000 pid=2757 execve guuid=3595a7ff-1900-0000-f1b4-4f9ec70a0000 pid=2759 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=3595a7ff-1900-0000-f1b4-4f9ec70a0000 pid=2759 clone guuid=92796001-1a00-0000-f1b4-4f9ece0a0000 pid=2766 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=92796001-1a00-0000-f1b4-4f9ece0a0000 pid=2766 clone guuid=36188001-1a00-0000-f1b4-4f9ecf0a0000 pid=2767 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=36188001-1a00-0000-f1b4-4f9ecf0a0000 pid=2767 clone guuid=46649e01-1a00-0000-f1b4-4f9ed10a0000 pid=2769 /usr/bin/cat guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=46649e01-1a00-0000-f1b4-4f9ed10a0000 pid=2769 execve guuid=fd131102-1a00-0000-f1b4-4f9ed30a0000 pid=2771 /usr/bin/chmod guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=fd131102-1a00-0000-f1b4-4f9ed30a0000 pid=2771 execve guuid=93755c02-1a00-0000-f1b4-4f9ed50a0000 pid=2773 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=93755c02-1a00-0000-f1b4-4f9ed50a0000 pid=2773 clone guuid=3beef402-1a00-0000-f1b4-4f9ed90a0000 pid=2777 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=3beef402-1a00-0000-f1b4-4f9ed90a0000 pid=2777 clone guuid=ce270803-1a00-0000-f1b4-4f9eda0a0000 pid=2778 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=ce270803-1a00-0000-f1b4-4f9eda0a0000 pid=2778 clone guuid=1c6b1e03-1a00-0000-f1b4-4f9edb0a0000 pid=2779 /usr/bin/cat guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=1c6b1e03-1a00-0000-f1b4-4f9edb0a0000 pid=2779 execve guuid=e19f6e03-1a00-0000-f1b4-4f9edc0a0000 pid=2780 /usr/bin/chmod guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=e19f6e03-1a00-0000-f1b4-4f9edc0a0000 pid=2780 execve guuid=6e96cb03-1a00-0000-f1b4-4f9edf0a0000 pid=2783 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=6e96cb03-1a00-0000-f1b4-4f9edf0a0000 pid=2783 clone guuid=b9647004-1a00-0000-f1b4-4f9ee30a0000 pid=2787 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=b9647004-1a00-0000-f1b4-4f9ee30a0000 pid=2787 clone guuid=90bd8804-1a00-0000-f1b4-4f9ee40a0000 pid=2788 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=90bd8804-1a00-0000-f1b4-4f9ee40a0000 pid=2788 clone guuid=7d529e04-1a00-0000-f1b4-4f9ee60a0000 pid=2790 /usr/bin/cat guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=7d529e04-1a00-0000-f1b4-4f9ee60a0000 pid=2790 execve guuid=87cce604-1a00-0000-f1b4-4f9ee80a0000 pid=2792 /usr/bin/chmod guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=87cce604-1a00-0000-f1b4-4f9ee80a0000 pid=2792 execve guuid=697a2605-1a00-0000-f1b4-4f9ee90a0000 pid=2793 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=697a2605-1a00-0000-f1b4-4f9ee90a0000 pid=2793 clone guuid=e5afe305-1a00-0000-f1b4-4f9eec0a0000 pid=2796 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=e5afe305-1a00-0000-f1b4-4f9eec0a0000 pid=2796 clone guuid=d3bbfe05-1a00-0000-f1b4-4f9eed0a0000 pid=2797 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=d3bbfe05-1a00-0000-f1b4-4f9eed0a0000 pid=2797 clone guuid=14d50e06-1a00-0000-f1b4-4f9eee0a0000 pid=2798 /usr/bin/cat guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=14d50e06-1a00-0000-f1b4-4f9eee0a0000 pid=2798 execve guuid=63d34f06-1a00-0000-f1b4-4f9ef00a0000 pid=2800 /usr/bin/chmod guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=63d34f06-1a00-0000-f1b4-4f9ef00a0000 pid=2800 execve guuid=75129206-1a00-0000-f1b4-4f9ef10a0000 pid=2801 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=75129206-1a00-0000-f1b4-4f9ef10a0000 pid=2801 clone guuid=a053f807-1a00-0000-f1b4-4f9ef80a0000 pid=2808 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=a053f807-1a00-0000-f1b4-4f9ef80a0000 pid=2808 clone guuid=671d1f08-1a00-0000-f1b4-4f9ef90a0000 pid=2809 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=671d1f08-1a00-0000-f1b4-4f9ef90a0000 pid=2809 clone guuid=28704008-1a00-0000-f1b4-4f9efa0a0000 pid=2810 /usr/bin/cat guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=28704008-1a00-0000-f1b4-4f9efa0a0000 pid=2810 execve guuid=5a91ae08-1a00-0000-f1b4-4f9efc0a0000 pid=2812 /usr/bin/chmod guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=5a91ae08-1a00-0000-f1b4-4f9efc0a0000 pid=2812 execve guuid=d57b3709-1a00-0000-f1b4-4f9efd0a0000 pid=2813 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=d57b3709-1a00-0000-f1b4-4f9efd0a0000 pid=2813 clone guuid=a2f3250a-1a00-0000-f1b4-4f9e000b0000 pid=2816 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=a2f3250a-1a00-0000-f1b4-4f9e000b0000 pid=2816 clone guuid=c4de4a0a-1a00-0000-f1b4-4f9e010b0000 pid=2817 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=c4de4a0a-1a00-0000-f1b4-4f9e010b0000 pid=2817 clone guuid=04b7670a-1a00-0000-f1b4-4f9e020b0000 pid=2818 /usr/bin/cat guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=04b7670a-1a00-0000-f1b4-4f9e020b0000 pid=2818 execve guuid=2b1bcc0a-1a00-0000-f1b4-4f9e050b0000 pid=2821 /usr/bin/chmod guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=2b1bcc0a-1a00-0000-f1b4-4f9e050b0000 pid=2821 execve guuid=0eb00f0b-1a00-0000-f1b4-4f9e060b0000 pid=2822 /usr/bin/bash guuid=531e5fef-1900-0000-f1b4-4f9e8a0a0000 pid=2698->guuid=0eb00f0b-1a00-0000-f1b4-4f9e060b0000 pid=2822 clone
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-04-07 10:33:33 UTC
File Type:
Text (Shell)
AV detection:
24 of 38 (63.16%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh f42c2bbf20a6ff06dab5aed49404a95ca88549304a2dc30a5d6a72f2acd4c11f

(this sample)

  
Delivery method
Distributed via web download

Comments