MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2578216acbad758fde4efd8d8d04d3fef0bf41845532851cc9cec37a48421d55. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 2578216acbad758fde4efd8d8d04d3fef0bf41845532851cc9cec37a48421d55
SHA3-384 hash: 8f1b145998181706f6cd945ffd70f596e8d1616074d384ea0c1538799c5bc5bc234a1bd0c8c50f17c29a6cdb27d1eb67
SHA1 hash: d9425581f52f1b9d8897d0d5ac46120ebbd0a2cb
MD5 hash: 3e8bfe0907913abff693b7c81bd380f8
humanhash: mike-fillet-lactose-yankee
File name:busybox.sh
Download: download sample
File size:1'055 bytes
First seen:2025-06-27 17:16:45 UTC
Last seen:2025-06-28 14:47:53 UTC
File type: sh
MIME type:text/plain
ssdeep 24:BD0+hD0VhD0UGNIN/hD0gKnhD0ShD0zhD0RQhD0fhD0ZlhD0ehD0v1U:BLhKhXhvshphsh+Qh2hilhvhy1U
TLSH T1BA1136FB00A9B4511928CC70B0295C0DA1878FF03161D785F4CEE8BAE2A9F395375F48
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://mafia.trumdvfb.com/skibdi/cutearmn/an/an/a
http://mafia.trumdvfb.com/skibdi/cutearm5n/an/an/a
http://mafia.trumdvfb.com/skibdi/cutearm6n/an/an/a
http://mafia.trumdvfb.com/skibdi/cutearm7n/an/an/a
http://mafia.trumdvfb.com/skibdi/cutem68kn/an/an/a
http://mafia.trumdvfb.com/skibdi/cutemipsn/an/an/a
http://mafia.trumdvfb.com/skibdi/cutempsln/an/an/a
http://mafia.trumdvfb.com/skibdi/cuteppcn/an/an/a
http://mafia.trumdvfb.com/skibdi/cutesh4n/an/an/a
http://mafia.trumdvfb.com/skibdi/cutex86n/an/an/a
http://mafia.trumdvfb.com/skibdi/cutex86_64n/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
120
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=31a89ccc-1a00-0000-a4f2-c6bd1b0a0000 pid=2587 /usr/bin/sudo guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594 /tmp/sample.bin guuid=31a89ccc-1a00-0000-a4f2-c6bd1b0a0000 pid=2587->guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594 execve guuid=082bddcf-1a00-0000-a4f2-c6bd240a0000 pid=2596 /usr/bin/busybox dns net send-data guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=082bddcf-1a00-0000-a4f2-c6bd240a0000 pid=2596 execve guuid=f4a361ee-1a00-0000-a4f2-c6bd7e0a0000 pid=2686 /usr/bin/chmod guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=f4a361ee-1a00-0000-a4f2-c6bd7e0a0000 pid=2686 execve guuid=cb742cef-1a00-0000-a4f2-c6bd810a0000 pid=2689 /usr/bin/dash guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=cb742cef-1a00-0000-a4f2-c6bd810a0000 pid=2689 clone guuid=789e39ef-1a00-0000-a4f2-c6bd830a0000 pid=2691 /usr/bin/busybox dns net send-data guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=789e39ef-1a00-0000-a4f2-c6bd830a0000 pid=2691 execve guuid=b4dc520e-1b00-0000-a4f2-c6bdc80a0000 pid=2760 /usr/bin/chmod guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=b4dc520e-1b00-0000-a4f2-c6bdc80a0000 pid=2760 execve guuid=8649b40e-1b00-0000-a4f2-c6bdca0a0000 pid=2762 /usr/bin/dash guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=8649b40e-1b00-0000-a4f2-c6bdca0a0000 pid=2762 clone guuid=8d21c40e-1b00-0000-a4f2-c6bdcb0a0000 pid=2763 /usr/bin/busybox dns net send-data guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=8d21c40e-1b00-0000-a4f2-c6bdcb0a0000 pid=2763 execve guuid=538ce92c-1b00-0000-a4f2-c6bd030b0000 pid=2819 /usr/bin/chmod guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=538ce92c-1b00-0000-a4f2-c6bd030b0000 pid=2819 execve guuid=7b5e752d-1b00-0000-a4f2-c6bd040b0000 pid=2820 /usr/bin/dash guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=7b5e752d-1b00-0000-a4f2-c6bd040b0000 pid=2820 clone guuid=f75d942d-1b00-0000-a4f2-c6bd050b0000 pid=2821 /usr/bin/busybox dns net send-data guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=f75d942d-1b00-0000-a4f2-c6bd050b0000 pid=2821 execve guuid=86c21f4c-1b00-0000-a4f2-c6bd540b0000 pid=2900 /usr/bin/chmod guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=86c21f4c-1b00-0000-a4f2-c6bd540b0000 pid=2900 execve guuid=4feb684c-1b00-0000-a4f2-c6bd550b0000 pid=2901 /usr/bin/dash guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=4feb684c-1b00-0000-a4f2-c6bd550b0000 pid=2901 clone guuid=0d84764c-1b00-0000-a4f2-c6bd560b0000 pid=2902 /usr/bin/busybox dns net send-data guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=0d84764c-1b00-0000-a4f2-c6bd560b0000 pid=2902 execve guuid=5c384d6f-1b00-0000-a4f2-c6bd800b0000 pid=2944 /usr/bin/chmod guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=5c384d6f-1b00-0000-a4f2-c6bd800b0000 pid=2944 execve guuid=4845dd6f-1b00-0000-a4f2-c6bd810b0000 pid=2945 /usr/bin/dash guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=4845dd6f-1b00-0000-a4f2-c6bd810b0000 pid=2945 clone guuid=981efc6f-1b00-0000-a4f2-c6bd820b0000 pid=2946 /usr/bin/busybox dns net send-data guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=981efc6f-1b00-0000-a4f2-c6bd820b0000 pid=2946 execve guuid=7d578b8d-1b00-0000-a4f2-c6bd8a0b0000 pid=2954 /usr/bin/chmod guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=7d578b8d-1b00-0000-a4f2-c6bd8a0b0000 pid=2954 execve guuid=a2a7158e-1b00-0000-a4f2-c6bd8b0b0000 pid=2955 /usr/bin/dash guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=a2a7158e-1b00-0000-a4f2-c6bd8b0b0000 pid=2955 clone guuid=dbe4328e-1b00-0000-a4f2-c6bd8c0b0000 pid=2956 /usr/bin/busybox dns net send-data guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=dbe4328e-1b00-0000-a4f2-c6bd8c0b0000 pid=2956 execve guuid=27cc35ad-1b00-0000-a4f2-c6bdb00b0000 pid=2992 /usr/bin/chmod guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=27cc35ad-1b00-0000-a4f2-c6bdb00b0000 pid=2992 execve guuid=a82f8fad-1b00-0000-a4f2-c6bdb10b0000 pid=2993 /usr/bin/dash guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=a82f8fad-1b00-0000-a4f2-c6bdb10b0000 pid=2993 clone guuid=68539cad-1b00-0000-a4f2-c6bdb20b0000 pid=2994 /usr/bin/busybox dns net send-data guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=68539cad-1b00-0000-a4f2-c6bdb20b0000 pid=2994 execve guuid=2909a6ca-1b00-0000-a4f2-c6bdf50b0000 pid=3061 /usr/bin/chmod guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=2909a6ca-1b00-0000-a4f2-c6bdf50b0000 pid=3061 execve guuid=a1d215cb-1b00-0000-a4f2-c6bdf60b0000 pid=3062 /usr/bin/dash guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=a1d215cb-1b00-0000-a4f2-c6bdf60b0000 pid=3062 clone guuid=0db535cb-1b00-0000-a4f2-c6bdf70b0000 pid=3063 /usr/bin/busybox dns net send-data guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=0db535cb-1b00-0000-a4f2-c6bdf70b0000 pid=3063 execve guuid=62045ce9-1b00-0000-a4f2-c6bd380c0000 pid=3128 /usr/bin/chmod guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=62045ce9-1b00-0000-a4f2-c6bd380c0000 pid=3128 execve guuid=e865aee9-1b00-0000-a4f2-c6bd390c0000 pid=3129 /usr/bin/dash guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=e865aee9-1b00-0000-a4f2-c6bd390c0000 pid=3129 clone guuid=1c24c0e9-1b00-0000-a4f2-c6bd3a0c0000 pid=3130 /usr/bin/busybox dns net send-data guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=1c24c0e9-1b00-0000-a4f2-c6bd3a0c0000 pid=3130 execve guuid=d013ae07-1c00-0000-a4f2-c6bd700c0000 pid=3184 /usr/bin/chmod guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=d013ae07-1c00-0000-a4f2-c6bd700c0000 pid=3184 execve guuid=13244508-1c00-0000-a4f2-c6bd720c0000 pid=3186 /usr/bin/dash guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=13244508-1c00-0000-a4f2-c6bd720c0000 pid=3186 clone guuid=c2025e08-1c00-0000-a4f2-c6bd730c0000 pid=3187 /usr/bin/busybox dns net send-data guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=c2025e08-1c00-0000-a4f2-c6bd730c0000 pid=3187 execve guuid=d1605726-1c00-0000-a4f2-c6bda60c0000 pid=3238 /usr/bin/chmod guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=d1605726-1c00-0000-a4f2-c6bda60c0000 pid=3238 execve guuid=56cb9f26-1c00-0000-a4f2-c6bda80c0000 pid=3240 /usr/bin/dash guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=56cb9f26-1c00-0000-a4f2-c6bda80c0000 pid=3240 clone guuid=51feb226-1c00-0000-a4f2-c6bda90c0000 pid=3241 /usr/bin/rm delete-file guuid=3f9b81cf-1a00-0000-a4f2-c6bd220a0000 pid=2594->guuid=51feb226-1c00-0000-a4f2-c6bda90c0000 pid=3241 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=082bddcf-1a00-0000-a4f2-c6bd240a0000 pid=2596->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B ae352235-8098-59df-9f11-a305b88fdf27 mafia.trumdvfb.com:80 guuid=082bddcf-1a00-0000-a4f2-c6bd240a0000 pid=2596->ae352235-8098-59df-9f11-a305b88fdf27 send: 95B guuid=789e39ef-1a00-0000-a4f2-c6bd830a0000 pid=2691->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=789e39ef-1a00-0000-a4f2-c6bd830a0000 pid=2691->ae352235-8098-59df-9f11-a305b88fdf27 send: 96B guuid=8d21c40e-1b00-0000-a4f2-c6bdcb0a0000 pid=2763->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=8d21c40e-1b00-0000-a4f2-c6bdcb0a0000 pid=2763->ae352235-8098-59df-9f11-a305b88fdf27 send: 96B guuid=f75d942d-1b00-0000-a4f2-c6bd050b0000 pid=2821->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=f75d942d-1b00-0000-a4f2-c6bd050b0000 pid=2821->ae352235-8098-59df-9f11-a305b88fdf27 send: 96B guuid=0d84764c-1b00-0000-a4f2-c6bd560b0000 pid=2902->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=0d84764c-1b00-0000-a4f2-c6bd560b0000 pid=2902->ae352235-8098-59df-9f11-a305b88fdf27 send: 96B guuid=981efc6f-1b00-0000-a4f2-c6bd820b0000 pid=2946->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=981efc6f-1b00-0000-a4f2-c6bd820b0000 pid=2946->ae352235-8098-59df-9f11-a305b88fdf27 send: 96B guuid=dbe4328e-1b00-0000-a4f2-c6bd8c0b0000 pid=2956->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=dbe4328e-1b00-0000-a4f2-c6bd8c0b0000 pid=2956->ae352235-8098-59df-9f11-a305b88fdf27 send: 96B guuid=68539cad-1b00-0000-a4f2-c6bdb20b0000 pid=2994->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=68539cad-1b00-0000-a4f2-c6bdb20b0000 pid=2994->ae352235-8098-59df-9f11-a305b88fdf27 send: 95B guuid=0db535cb-1b00-0000-a4f2-c6bdf70b0000 pid=3063->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=0db535cb-1b00-0000-a4f2-c6bdf70b0000 pid=3063->ae352235-8098-59df-9f11-a305b88fdf27 send: 95B guuid=1c24c0e9-1b00-0000-a4f2-c6bd3a0c0000 pid=3130->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=1c24c0e9-1b00-0000-a4f2-c6bd3a0c0000 pid=3130->ae352235-8098-59df-9f11-a305b88fdf27 send: 95B guuid=c2025e08-1c00-0000-a4f2-c6bd730c0000 pid=3187->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=c2025e08-1c00-0000-a4f2-c6bd730c0000 pid=3187->ae352235-8098-59df-9f11-a305b88fdf27 send: 98B
Threat name:
Document-HTML.Downloader.Heuristic
Status:
Malicious
First seen:
2025-06-27 17:17:28 UTC
File Type:
Text (Shell)
AV detection:
10 of 38 (26.32%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 2578216acbad758fde4efd8d8d04d3fef0bf41845532851cc9cec37a48421d55

(this sample)

  
Delivery method
Distributed via web download

Comments