MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2670466de85480cbf02219e7ffadb5b176c6ea74ae2e2b3b95a98e4590c8a98a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 2670466de85480cbf02219e7ffadb5b176c6ea74ae2e2b3b95a98e4590c8a98a
SHA3-384 hash: f1be810534bf111b6561b51285681ac8fe2107cce2ae7c9b22e78d59b0b1cac39e9d80e7e442dd2611f1e26f8b711491
SHA1 hash: 16a6e74b2a7b811cdff3129833b9975b67cbd589
MD5 hash: 06c4a3110897a5515a8d343484f02b73
humanhash: mike-lion-sad-mirror
File name:busybox.sh
Download: download sample
File size:1'025 bytes
First seen:2025-06-24 23:00:46 UTC
Last seen:2025-06-25 12:04:52 UTC
File type: sh
MIME type:text/plain
ssdeep 24:y6IF6Itd6IRGNINd6InKk6Id6IX6IGY6I3136Iv6IN6IT:ypFpHpdpnDpdpXpGYp3ZpvpNpT
TLSH T173119AEA8459740344A19C6070796C59E01ACAE02684DBC9F4DED4F7E2A9E3E633278C
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://api.trumdvfb.com/skibidi/cutearmn/an/an/a
http://api.trumdvfb.com/skibidi/cutearm5n/an/an/a
http://api.trumdvfb.com/skibidi/cutearm6n/an/an/a
http://api.trumdvfb.com/skibidi/cutearm7n/an/an/a
http://api.trumdvfb.com/skibidi/cutem68kn/an/an/a
http://api.trumdvfb.com/skibidi/cutemipsn/an/an/a
http://api.trumdvfb.com/skibidi/cutempsln/an/an/a
http://api.trumdvfb.com/skibidi/cutepowerpcn/an/abotnetdomain elf ua-wget
http://api.trumdvfb.com/skibidi/cutesh4n/an/an/a
http://api.trumdvfb.com/skibidi/cutex86n/an/an/a
http://api.trumdvfb.com/skibidi/cutex86_64n/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
100
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=a03748f4-1800-0000-b0ab-0ed7ad120000 pid=4781 /usr/bin/sudo guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789 /tmp/sample.bin guuid=a03748f4-1800-0000-b0ab-0ed7ad120000 pid=4781->guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789 execve guuid=e1d3dff6-1800-0000-b0ab-0ed7b8120000 pid=4792 /usr/bin/busybox dns net send-data write-file guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=e1d3dff6-1800-0000-b0ab-0ed7b8120000 pid=4792 execve guuid=0d24373d-1900-0000-b0ab-0ed755130000 pid=4949 /usr/bin/chmod guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=0d24373d-1900-0000-b0ab-0ed755130000 pid=4949 execve guuid=e8b8a93d-1900-0000-b0ab-0ed757130000 pid=4951 /usr/bin/dash guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=e8b8a93d-1900-0000-b0ab-0ed757130000 pid=4951 clone guuid=6f17ba3f-1900-0000-b0ab-0ed75c130000 pid=4956 /usr/bin/busybox dns net send-data write-file guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=6f17ba3f-1900-0000-b0ab-0ed75c130000 pid=4956 execve guuid=6a2f4b86-1900-0000-b0ab-0ed7af130000 pid=5039 /usr/bin/chmod guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=6a2f4b86-1900-0000-b0ab-0ed7af130000 pid=5039 execve guuid=5f2fbb86-1900-0000-b0ab-0ed7b0130000 pid=5040 /usr/bin/dash guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=5f2fbb86-1900-0000-b0ab-0ed7b0130000 pid=5040 clone guuid=a0998f88-1900-0000-b0ab-0ed7b7130000 pid=5047 /usr/bin/busybox dns net send-data write-file guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=a0998f88-1900-0000-b0ab-0ed7b7130000 pid=5047 execve guuid=722f93d1-1900-0000-b0ab-0ed758140000 pid=5208 /usr/bin/chmod guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=722f93d1-1900-0000-b0ab-0ed758140000 pid=5208 execve guuid=b64a09d2-1900-0000-b0ab-0ed75b140000 pid=5211 /usr/bin/dash guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=b64a09d2-1900-0000-b0ab-0ed75b140000 pid=5211 clone guuid=3c8e8ed3-1900-0000-b0ab-0ed75f140000 pid=5215 /usr/bin/busybox dns net send-data write-file guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=3c8e8ed3-1900-0000-b0ab-0ed75f140000 pid=5215 execve guuid=5705411a-1a00-0000-b0ab-0ed76c140000 pid=5228 /usr/bin/chmod guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=5705411a-1a00-0000-b0ab-0ed76c140000 pid=5228 execve guuid=2b7cdf1a-1a00-0000-b0ab-0ed76d140000 pid=5229 /usr/bin/dash guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=2b7cdf1a-1a00-0000-b0ab-0ed76d140000 pid=5229 clone guuid=b47b001c-1a00-0000-b0ab-0ed76f140000 pid=5231 /usr/bin/busybox dns net send-data write-file guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=b47b001c-1a00-0000-b0ab-0ed76f140000 pid=5231 execve guuid=64692f61-1a00-0000-b0ab-0ed770140000 pid=5232 /usr/bin/chmod guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=64692f61-1a00-0000-b0ab-0ed770140000 pid=5232 execve guuid=a1907b61-1a00-0000-b0ab-0ed771140000 pid=5233 /usr/bin/dash guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=a1907b61-1a00-0000-b0ab-0ed771140000 pid=5233 clone guuid=96d46462-1a00-0000-b0ab-0ed773140000 pid=5235 /usr/bin/busybox dns net send-data write-file guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=96d46462-1a00-0000-b0ab-0ed773140000 pid=5235 execve guuid=619f0ba9-1a00-0000-b0ab-0ed774140000 pid=5236 /usr/bin/chmod guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=619f0ba9-1a00-0000-b0ab-0ed774140000 pid=5236 execve guuid=4e05b5a9-1a00-0000-b0ab-0ed775140000 pid=5237 /usr/bin/dash guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=4e05b5a9-1a00-0000-b0ab-0ed775140000 pid=5237 clone guuid=64de95aa-1a00-0000-b0ab-0ed777140000 pid=5239 /usr/bin/busybox dns net send-data write-file guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=64de95aa-1a00-0000-b0ab-0ed777140000 pid=5239 execve guuid=169fe2f1-1a00-0000-b0ab-0ed77f140000 pid=5247 /usr/bin/chmod guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=169fe2f1-1a00-0000-b0ab-0ed77f140000 pid=5247 execve guuid=3aac7ef2-1a00-0000-b0ab-0ed780140000 pid=5248 /usr/bin/dash guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=3aac7ef2-1a00-0000-b0ab-0ed780140000 pid=5248 clone guuid=4ed99af4-1a00-0000-b0ab-0ed782140000 pid=5250 /usr/bin/busybox dns net send-data guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=4ed99af4-1a00-0000-b0ab-0ed782140000 pid=5250 execve guuid=3803f313-1b00-0000-b0ab-0ed783140000 pid=5251 /usr/bin/chmod guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=3803f313-1b00-0000-b0ab-0ed783140000 pid=5251 execve guuid=b21f7414-1b00-0000-b0ab-0ed784140000 pid=5252 /usr/bin/dash guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=b21f7414-1b00-0000-b0ab-0ed784140000 pid=5252 clone guuid=720a9b14-1b00-0000-b0ab-0ed785140000 pid=5253 /usr/bin/busybox dns net send-data write-file guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=720a9b14-1b00-0000-b0ab-0ed785140000 pid=5253 execve guuid=4dc6235a-1b00-0000-b0ab-0ed786140000 pid=5254 /usr/bin/chmod guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=4dc6235a-1b00-0000-b0ab-0ed786140000 pid=5254 execve guuid=35829b5a-1b00-0000-b0ab-0ed787140000 pid=5255 /usr/bin/dash guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=35829b5a-1b00-0000-b0ab-0ed787140000 pid=5255 clone guuid=8c0ccd5b-1b00-0000-b0ab-0ed789140000 pid=5257 /usr/bin/busybox dns net send-data write-file guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=8c0ccd5b-1b00-0000-b0ab-0ed789140000 pid=5257 execve guuid=da436a98-1b00-0000-b0ab-0ed78b140000 pid=5259 /usr/bin/chmod guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=da436a98-1b00-0000-b0ab-0ed78b140000 pid=5259 execve guuid=5e13bf98-1b00-0000-b0ab-0ed78c140000 pid=5260 /home/sandbox/cutex86 delete-file net guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=5e13bf98-1b00-0000-b0ab-0ed78c140000 pid=5260 execve guuid=ba2f1899-1b00-0000-b0ab-0ed78e140000 pid=5262 /usr/bin/busybox dns net send-data guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=ba2f1899-1b00-0000-b0ab-0ed78e140000 pid=5262 execve guuid=a9522d9c-1b00-0000-b0ab-0ed790140000 pid=5264 /usr/bin/chmod guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=a9522d9c-1b00-0000-b0ab-0ed790140000 pid=5264 execve guuid=c08e649c-1b00-0000-b0ab-0ed791140000 pid=5265 /usr/bin/dash guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=c08e649c-1b00-0000-b0ab-0ed791140000 pid=5265 clone guuid=610c6c9c-1b00-0000-b0ab-0ed792140000 pid=5266 /usr/bin/rm delete-file guuid=a4e885f6-1800-0000-b0ab-0ed7b5120000 pid=4789->guuid=610c6c9c-1b00-0000-b0ab-0ed792140000 pid=5266 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=e1d3dff6-1800-0000-b0ab-0ed7b8120000 pid=4792->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B e86f753b-e3e0-5b83-89b3-1a4358cc8e45 api.trumdvfb.com:80 guuid=e1d3dff6-1800-0000-b0ab-0ed7b8120000 pid=4792->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 94B guuid=6f17ba3f-1900-0000-b0ab-0ed75c130000 pid=4956->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=6f17ba3f-1900-0000-b0ab-0ed75c130000 pid=4956->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 95B guuid=a0998f88-1900-0000-b0ab-0ed7b7130000 pid=5047->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=a0998f88-1900-0000-b0ab-0ed7b7130000 pid=5047->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 95B guuid=3c8e8ed3-1900-0000-b0ab-0ed75f140000 pid=5215->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=3c8e8ed3-1900-0000-b0ab-0ed75f140000 pid=5215->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 95B guuid=b47b001c-1a00-0000-b0ab-0ed76f140000 pid=5231->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=b47b001c-1a00-0000-b0ab-0ed76f140000 pid=5231->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 95B guuid=96d46462-1a00-0000-b0ab-0ed773140000 pid=5235->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=96d46462-1a00-0000-b0ab-0ed773140000 pid=5235->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 95B guuid=64de95aa-1a00-0000-b0ab-0ed777140000 pid=5239->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=64de95aa-1a00-0000-b0ab-0ed777140000 pid=5239->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 95B guuid=4ed99af4-1a00-0000-b0ab-0ed782140000 pid=5250->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=4ed99af4-1a00-0000-b0ab-0ed782140000 pid=5250->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 98B guuid=720a9b14-1b00-0000-b0ab-0ed785140000 pid=5253->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=720a9b14-1b00-0000-b0ab-0ed785140000 pid=5253->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 94B guuid=8c0ccd5b-1b00-0000-b0ab-0ed789140000 pid=5257->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=8c0ccd5b-1b00-0000-b0ab-0ed789140000 pid=5257->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 94B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=5e13bf98-1b00-0000-b0ab-0ed78c140000 pid=5260->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d5140899-1b00-0000-b0ab-0ed78d140000 pid=5261 /home/sandbox/cutex86 dns net send-data zombie guuid=5e13bf98-1b00-0000-b0ab-0ed78c140000 pid=5260->guuid=d5140899-1b00-0000-b0ab-0ed78d140000 pid=5261 clone guuid=d5140899-1b00-0000-b0ab-0ed78d140000 pid=5261->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 34B 00f140d0-a647-5df2-a2d9-67febf35a4e2 api.trumdvfb.com:47925 guuid=d5140899-1b00-0000-b0ab-0ed78d140000 pid=5261->00f140d0-a647-5df2-a2d9-67febf35a4e2 send: 10B guuid=8ff32199-1b00-0000-b0ab-0ed78f140000 pid=5263 /home/sandbox/cutex86 guuid=d5140899-1b00-0000-b0ab-0ed78d140000 pid=5261->guuid=8ff32199-1b00-0000-b0ab-0ed78f140000 pid=5263 clone guuid=ba2f1899-1b00-0000-b0ab-0ed78e140000 pid=5262->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=ba2f1899-1b00-0000-b0ab-0ed78e140000 pid=5262->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 con
Threat name:
Document-HTML.Trojan.Egairtigado
Status:
Malicious
First seen:
2025-06-24 23:01:30 UTC
File Type:
Text (Shell)
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 2670466de85480cbf02219e7ffadb5b176c6ea74ae2e2b3b95a98e4590c8a98a

(this sample)

  
Delivery method
Distributed via web download

Comments