MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 03f1b29c04b19364018ea2490a1ed052d13593b65dfa69b559f93116860d811c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 03f1b29c04b19364018ea2490a1ed052d13593b65dfa69b559f93116860d811c
SHA3-384 hash: 06cc7b572627a526f015744b3b57551f6477b7b93f781aadde17212d00c7eb1bb51f3d5f8bc015444ac8705c594788ca
SHA1 hash: aa0c9a47adb8dbc33c0b3ca3ebb1e18e8b7f013a
MD5 hash: 9664e16bd53d0da9f055f53bdab4e635
humanhash: north-west-robert-monkey
File name:wget.sh
Download: download sample
File size:967 bytes
First seen:2025-06-27 16:16:50 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:fD0ID0lD0UGNINnD0gK/D0kD0jD0RyD0HD0ZVD0oD0v1U:fLsPvmhm+yQiV3y1U
TLSH T1261166FB00A9B4411B28DC30B0291C09B1878BF031B1D785F4CEE87BE1A9B362275F49
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://mafia.trumdvfb.com/skibdi/cutearmn/an/an/a
http://mafia.trumdvfb.com/skibdi/cutearm5n/an/an/a
http://mafia.trumdvfb.com/skibdi/cutearm6n/an/an/a
http://mafia.trumdvfb.com/skibdi/cutearm7n/an/an/a
http://mafia.trumdvfb.com/skibdi/cutem68kn/an/an/a
http://mafia.trumdvfb.com/skibdi/cutemipsn/an/an/a
http://mafia.trumdvfb.com/skibdi/cutempsln/an/an/a
http://mafia.trumdvfb.com/skibdi/cuteppcn/an/an/a
http://mafia.trumdvfb.com/skibdi/cutesh4n/an/an/a
http://mafia.trumdvfb.com/skibdi/cutex86n/an/an/a
http://mafia.trumdvfb.com/skibdi/cutex86_64n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
102
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=3de9d462-1800-0000-0bc5-97a8cb0b0000 pid=3019 /usr/bin/sudo guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029 /tmp/sample.bin guuid=3de9d462-1800-0000-0bc5-97a8cb0b0000 pid=3019->guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029 execve guuid=0d16aa65-1800-0000-0bc5-97a8d70b0000 pid=3031 /usr/bin/wget dns net send-data guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=0d16aa65-1800-0000-0bc5-97a8d70b0000 pid=3031 execve guuid=9f093887-1800-0000-0bc5-97a8300c0000 pid=3120 /usr/bin/chmod guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=9f093887-1800-0000-0bc5-97a8300c0000 pid=3120 execve guuid=3b199587-1800-0000-0bc5-97a8320c0000 pid=3122 /usr/bin/dash guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=3b199587-1800-0000-0bc5-97a8320c0000 pid=3122 clone guuid=f41fa087-1800-0000-0bc5-97a8330c0000 pid=3123 /usr/bin/wget dns net send-data guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=f41fa087-1800-0000-0bc5-97a8330c0000 pid=3123 execve guuid=50f03ea6-1800-0000-0bc5-97a86c0c0000 pid=3180 /usr/bin/chmod guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=50f03ea6-1800-0000-0bc5-97a86c0c0000 pid=3180 execve guuid=bc99afa6-1800-0000-0bc5-97a86d0c0000 pid=3181 /usr/bin/dash guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=bc99afa6-1800-0000-0bc5-97a86d0c0000 pid=3181 clone guuid=5932bda6-1800-0000-0bc5-97a86e0c0000 pid=3182 /usr/bin/wget dns net send-data guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=5932bda6-1800-0000-0bc5-97a86e0c0000 pid=3182 execve guuid=5038d8c5-1800-0000-0bc5-97a8890c0000 pid=3209 /usr/bin/chmod guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=5038d8c5-1800-0000-0bc5-97a8890c0000 pid=3209 execve guuid=d49349c6-1800-0000-0bc5-97a88b0c0000 pid=3211 /usr/bin/dash guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=d49349c6-1800-0000-0bc5-97a88b0c0000 pid=3211 clone guuid=45d354c6-1800-0000-0bc5-97a88c0c0000 pid=3212 /usr/bin/wget dns net send-data guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=45d354c6-1800-0000-0bc5-97a88c0c0000 pid=3212 execve guuid=9ba28de4-1800-0000-0bc5-97a8ab0c0000 pid=3243 /usr/bin/chmod guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=9ba28de4-1800-0000-0bc5-97a8ab0c0000 pid=3243 execve guuid=037cebe4-1800-0000-0bc5-97a8ac0c0000 pid=3244 /usr/bin/dash guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=037cebe4-1800-0000-0bc5-97a8ac0c0000 pid=3244 clone guuid=c96a06e5-1800-0000-0bc5-97a8ad0c0000 pid=3245 /usr/bin/wget dns net send-data guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=c96a06e5-1800-0000-0bc5-97a8ad0c0000 pid=3245 execve guuid=29321403-1900-0000-0bc5-97a8cf0c0000 pid=3279 /usr/bin/chmod guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=29321403-1900-0000-0bc5-97a8cf0c0000 pid=3279 execve guuid=e3ebb803-1900-0000-0bc5-97a8d00c0000 pid=3280 /usr/bin/dash guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=e3ebb803-1900-0000-0bc5-97a8d00c0000 pid=3280 clone guuid=3a9bcf03-1900-0000-0bc5-97a8d10c0000 pid=3281 /usr/bin/wget dns net send-data guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=3a9bcf03-1900-0000-0bc5-97a8d10c0000 pid=3281 execve guuid=1370bd23-1900-0000-0bc5-97a8050d0000 pid=3333 /usr/bin/chmod guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=1370bd23-1900-0000-0bc5-97a8050d0000 pid=3333 execve guuid=d1de2f24-1900-0000-0bc5-97a8070d0000 pid=3335 /usr/bin/dash guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=d1de2f24-1900-0000-0bc5-97a8070d0000 pid=3335 clone guuid=d1173924-1900-0000-0bc5-97a8080d0000 pid=3336 /usr/bin/wget dns net send-data guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=d1173924-1900-0000-0bc5-97a8080d0000 pid=3336 execve guuid=f8e0ad49-1900-0000-0bc5-97a8330d0000 pid=3379 /usr/bin/chmod guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=f8e0ad49-1900-0000-0bc5-97a8330d0000 pid=3379 execve guuid=01b72f4a-1900-0000-0bc5-97a8350d0000 pid=3381 /usr/bin/dash guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=01b72f4a-1900-0000-0bc5-97a8350d0000 pid=3381 clone guuid=a48d444a-1900-0000-0bc5-97a8360d0000 pid=3382 /usr/bin/wget dns net send-data guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=a48d444a-1900-0000-0bc5-97a8360d0000 pid=3382 execve guuid=1dd81a69-1900-0000-0bc5-97a8660d0000 pid=3430 /usr/bin/chmod guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=1dd81a69-1900-0000-0bc5-97a8660d0000 pid=3430 execve guuid=93518269-1900-0000-0bc5-97a8680d0000 pid=3432 /usr/bin/dash guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=93518269-1900-0000-0bc5-97a8680d0000 pid=3432 clone guuid=33169869-1900-0000-0bc5-97a8690d0000 pid=3433 /usr/bin/wget dns net send-data guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=33169869-1900-0000-0bc5-97a8690d0000 pid=3433 execve guuid=ab46c488-1900-0000-0bc5-97a8a50d0000 pid=3493 /usr/bin/chmod guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=ab46c488-1900-0000-0bc5-97a8a50d0000 pid=3493 execve guuid=f1543889-1900-0000-0bc5-97a8a80d0000 pid=3496 /usr/bin/dash guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=f1543889-1900-0000-0bc5-97a8a80d0000 pid=3496 clone guuid=69f44589-1900-0000-0bc5-97a8a90d0000 pid=3497 /usr/bin/wget dns net send-data guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=69f44589-1900-0000-0bc5-97a8a90d0000 pid=3497 execve guuid=49c338af-1900-0000-0bc5-97a8e20d0000 pid=3554 /usr/bin/chmod guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=49c338af-1900-0000-0bc5-97a8e20d0000 pid=3554 execve guuid=7d317baf-1900-0000-0bc5-97a8e30d0000 pid=3555 /usr/bin/dash guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=7d317baf-1900-0000-0bc5-97a8e30d0000 pid=3555 clone guuid=0dc48baf-1900-0000-0bc5-97a8e40d0000 pid=3556 /usr/bin/wget dns net send-data guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=0dc48baf-1900-0000-0bc5-97a8e40d0000 pid=3556 execve guuid=54e5edcf-1900-0000-0bc5-97a82e0e0000 pid=3630 /usr/bin/chmod guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=54e5edcf-1900-0000-0bc5-97a82e0e0000 pid=3630 execve guuid=96a25fd0-1900-0000-0bc5-97a82f0e0000 pid=3631 /usr/bin/dash guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=96a25fd0-1900-0000-0bc5-97a82f0e0000 pid=3631 clone guuid=317775d0-1900-0000-0bc5-97a8300e0000 pid=3632 /usr/bin/rm delete-file guuid=23135965-1800-0000-0bc5-97a8d50b0000 pid=3029->guuid=317775d0-1900-0000-0bc5-97a8300e0000 pid=3632 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=0d16aa65-1800-0000-0bc5-97a8d70b0000 pid=3031->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B ae352235-8098-59df-9f11-a305b88fdf27 mafia.trumdvfb.com:80 guuid=0d16aa65-1800-0000-0bc5-97a8d70b0000 pid=3031->ae352235-8098-59df-9f11-a305b88fdf27 send: 147B guuid=f41fa087-1800-0000-0bc5-97a8330c0000 pid=3123->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=f41fa087-1800-0000-0bc5-97a8330c0000 pid=3123->ae352235-8098-59df-9f11-a305b88fdf27 send: 148B guuid=5932bda6-1800-0000-0bc5-97a86e0c0000 pid=3182->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=5932bda6-1800-0000-0bc5-97a86e0c0000 pid=3182->ae352235-8098-59df-9f11-a305b88fdf27 send: 148B guuid=45d354c6-1800-0000-0bc5-97a88c0c0000 pid=3212->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=45d354c6-1800-0000-0bc5-97a88c0c0000 pid=3212->ae352235-8098-59df-9f11-a305b88fdf27 send: 148B guuid=c96a06e5-1800-0000-0bc5-97a8ad0c0000 pid=3245->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=c96a06e5-1800-0000-0bc5-97a8ad0c0000 pid=3245->ae352235-8098-59df-9f11-a305b88fdf27 send: 148B guuid=3a9bcf03-1900-0000-0bc5-97a8d10c0000 pid=3281->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=3a9bcf03-1900-0000-0bc5-97a8d10c0000 pid=3281->ae352235-8098-59df-9f11-a305b88fdf27 send: 148B guuid=d1173924-1900-0000-0bc5-97a8080d0000 pid=3336->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=d1173924-1900-0000-0bc5-97a8080d0000 pid=3336->ae352235-8098-59df-9f11-a305b88fdf27 send: 148B guuid=a48d444a-1900-0000-0bc5-97a8360d0000 pid=3382->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=a48d444a-1900-0000-0bc5-97a8360d0000 pid=3382->ae352235-8098-59df-9f11-a305b88fdf27 send: 147B guuid=33169869-1900-0000-0bc5-97a8690d0000 pid=3433->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=33169869-1900-0000-0bc5-97a8690d0000 pid=3433->ae352235-8098-59df-9f11-a305b88fdf27 send: 147B guuid=69f44589-1900-0000-0bc5-97a8a90d0000 pid=3497->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=69f44589-1900-0000-0bc5-97a8a90d0000 pid=3497->ae352235-8098-59df-9f11-a305b88fdf27 send: 147B guuid=0dc48baf-1900-0000-0bc5-97a8e40d0000 pid=3556->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=0dc48baf-1900-0000-0bc5-97a8e40d0000 pid=3556->ae352235-8098-59df-9f11-a305b88fdf27 send: 150B
Threat name:
Document-HTML.Downloader.Heuristic
Status:
Malicious
First seen:
2025-06-27 16:17:30 UTC
File Type:
Text (Shell)
AV detection:
8 of 38 (21.05%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 03f1b29c04b19364018ea2490a1ed052d13593b65dfa69b559f93116860d811c

(this sample)

  
Delivery method
Distributed via web download

Comments