MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 411f61a18b783ea8f33da8c2c30c7ae575e6e8c157ef2c9d103096904ae22349. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 411f61a18b783ea8f33da8c2c30c7ae575e6e8c157ef2c9d103096904ae22349
SHA3-384 hash: 19fcefd7d40b85c645f1cc696d21206ca8f1b928ec212d2d8f195ac2f9cf576f603f8ffbbdb102cfa1372c0a07f36f43
SHA1 hash: 7abd94ee23e01e4e4d9c4e01952423295720adfd
MD5 hash: 91e0fbb0e571e290ce0487ea6521b154
humanhash: xray-white-princess-two
File name:curl.sh
Download: download sample
File size:957 bytes
First seen:2025-06-22 11:53:16 UTC
Last seen:2025-06-23 00:30:59 UTC
File type: sh
MIME type:text/plain
ssdeep 24:3J3h6I06I16IRGNINQ6InK46Ie6Iz6IGf6I3G6Iai6II6I6f:Lp0p1pQpnbpepzpGfp3GpaipIp6f
TLSH T19411EBED8059740767359C30B03D6A49E486C6E036A4D681F0EED4F7E1A923B43B5B9A
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://api.trumdvfb.com/skibidi/cutearmn/an/an/a
http://api.trumdvfb.com/skibidi/cutearm5n/an/an/a
http://api.trumdvfb.com/skibidi/cutearm6n/an/an/a
http://api.trumdvfb.com/skibidi/cutearm7n/an/an/a
http://api.trumdvfb.com/skibidi/cutem68kn/an/an/a
http://api.trumdvfb.com/skibidi/cutemipsn/an/an/a
http://api.trumdvfb.com/skibidi/cutempsln/an/an/a
http://api.trumdvfb.com/skibidi/cutepowerpcn/an/abotnetdomain elf ua-wget
http://api.trumdvfb.com/skibidi/cutesh4n/an/an/a
http://api.trumdvfb.com/skibidi/cutex86n/an/an/a
http://api.trumdvfb.com/skibidi/cutex86_64n/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
60
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
lolbin mirai remote
Status:
terminated
Behavior Graph:
%3 guuid=95873c80-1a00-0000-e3ac-e06b160c0000 pid=3094 /usr/bin/sudo guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101 /tmp/sample.bin guuid=95873c80-1a00-0000-e3ac-e06b160c0000 pid=3094->guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101 execve guuid=ef687882-1a00-0000-e3ac-e06b1e0c0000 pid=3102 /usr/bin/curl net send-data guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=ef687882-1a00-0000-e3ac-e06b1e0c0000 pid=3102 execve guuid=7571ebcf-1a00-0000-e3ac-e06b8e0c0000 pid=3214 /usr/bin/chmod guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=7571ebcf-1a00-0000-e3ac-e06b8e0c0000 pid=3214 execve guuid=9054bdd0-1a00-0000-e3ac-e06b8f0c0000 pid=3215 /usr/bin/dash guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=9054bdd0-1a00-0000-e3ac-e06b8f0c0000 pid=3215 clone guuid=1a0fc6d0-1a00-0000-e3ac-e06b900c0000 pid=3216 /usr/bin/curl net send-data guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=1a0fc6d0-1a00-0000-e3ac-e06b900c0000 pid=3216 execve guuid=7c32d61c-1b00-0000-e3ac-e06be80c0000 pid=3304 /usr/bin/chmod guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=7c32d61c-1b00-0000-e3ac-e06be80c0000 pid=3304 execve guuid=f061691d-1b00-0000-e3ac-e06bea0c0000 pid=3306 /usr/bin/dash guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=f061691d-1b00-0000-e3ac-e06bea0c0000 pid=3306 clone guuid=6c56791d-1b00-0000-e3ac-e06beb0c0000 pid=3307 /usr/bin/curl net send-data guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=6c56791d-1b00-0000-e3ac-e06beb0c0000 pid=3307 execve guuid=fd78a565-1b00-0000-e3ac-e06b6c0d0000 pid=3436 /usr/bin/chmod guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=fd78a565-1b00-0000-e3ac-e06b6c0d0000 pid=3436 execve guuid=cf303666-1b00-0000-e3ac-e06b6e0d0000 pid=3438 /usr/bin/dash guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=cf303666-1b00-0000-e3ac-e06b6e0d0000 pid=3438 clone guuid=48bf5266-1b00-0000-e3ac-e06b6f0d0000 pid=3439 /usr/bin/curl net send-data guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=48bf5266-1b00-0000-e3ac-e06b6f0d0000 pid=3439 execve guuid=56c9b9b0-1b00-0000-e3ac-e06b020e0000 pid=3586 /usr/bin/chmod guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=56c9b9b0-1b00-0000-e3ac-e06b020e0000 pid=3586 execve guuid=317211b1-1b00-0000-e3ac-e06b040e0000 pid=3588 /usr/bin/dash guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=317211b1-1b00-0000-e3ac-e06b040e0000 pid=3588 clone guuid=beba22b1-1b00-0000-e3ac-e06b050e0000 pid=3589 /usr/bin/curl net send-data guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=beba22b1-1b00-0000-e3ac-e06b050e0000 pid=3589 execve guuid=e1f3b3fa-1b00-0000-e3ac-e06bc60e0000 pid=3782 /usr/bin/chmod guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=e1f3b3fa-1b00-0000-e3ac-e06bc60e0000 pid=3782 execve guuid=5a9c1cfb-1b00-0000-e3ac-e06bc70e0000 pid=3783 /usr/bin/dash guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=5a9c1cfb-1b00-0000-e3ac-e06bc70e0000 pid=3783 clone guuid=86c22afb-1b00-0000-e3ac-e06bc80e0000 pid=3784 /usr/bin/curl net send-data guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=86c22afb-1b00-0000-e3ac-e06bc80e0000 pid=3784 execve guuid=59239244-1c00-0000-e3ac-e06bbb0f0000 pid=4027 /usr/bin/chmod guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=59239244-1c00-0000-e3ac-e06bbb0f0000 pid=4027 execve guuid=875cf544-1c00-0000-e3ac-e06bbc0f0000 pid=4028 /usr/bin/dash guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=875cf544-1c00-0000-e3ac-e06bbc0f0000 pid=4028 clone guuid=90be0445-1c00-0000-e3ac-e06bbe0f0000 pid=4030 /usr/bin/curl net send-data guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=90be0445-1c00-0000-e3ac-e06bbe0f0000 pid=4030 execve guuid=fe64a58f-1c00-0000-e3ac-e06b7b100000 pid=4219 /usr/bin/chmod guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=fe64a58f-1c00-0000-e3ac-e06b7b100000 pid=4219 execve guuid=6de82b90-1c00-0000-e3ac-e06b7f100000 pid=4223 /usr/bin/dash guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=6de82b90-1c00-0000-e3ac-e06b7f100000 pid=4223 clone guuid=c9234090-1c00-0000-e3ac-e06b81100000 pid=4225 /usr/bin/curl net send-data guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=c9234090-1c00-0000-e3ac-e06b81100000 pid=4225 execve guuid=233257b2-1c00-0000-e3ac-e06bda100000 pid=4314 /usr/bin/chmod guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=233257b2-1c00-0000-e3ac-e06bda100000 pid=4314 execve guuid=3b08ebb2-1c00-0000-e3ac-e06bdb100000 pid=4315 /usr/bin/dash guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=3b08ebb2-1c00-0000-e3ac-e06bdb100000 pid=4315 clone guuid=5eb5fcb2-1c00-0000-e3ac-e06bdc100000 pid=4316 /usr/bin/curl net send-data guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=5eb5fcb2-1c00-0000-e3ac-e06bdc100000 pid=4316 execve guuid=c9ecd3ff-1c00-0000-e3ac-e06bb0110000 pid=4528 /usr/bin/chmod guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=c9ecd3ff-1c00-0000-e3ac-e06bb0110000 pid=4528 execve guuid=66454900-1d00-0000-e3ac-e06bb1110000 pid=4529 /usr/bin/dash guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=66454900-1d00-0000-e3ac-e06bb1110000 pid=4529 clone guuid=1ee96300-1d00-0000-e3ac-e06bb2110000 pid=4530 /usr/bin/curl net send-data guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=1ee96300-1d00-0000-e3ac-e06bb2110000 pid=4530 execve guuid=b209b63d-1d00-0000-e3ac-e06b51120000 pid=4689 /usr/bin/chmod guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=b209b63d-1d00-0000-e3ac-e06b51120000 pid=4689 execve guuid=a5160f3e-1d00-0000-e3ac-e06b53120000 pid=4691 /usr/bin/dash guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=a5160f3e-1d00-0000-e3ac-e06b53120000 pid=4691 clone guuid=8a2d243e-1d00-0000-e3ac-e06b54120000 pid=4692 /usr/bin/curl net send-data guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=8a2d243e-1d00-0000-e3ac-e06b54120000 pid=4692 execve guuid=9604ef87-1d00-0000-e3ac-e06bea120000 pid=4842 /usr/bin/chmod guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=9604ef87-1d00-0000-e3ac-e06bea120000 pid=4842 execve guuid=58cd6888-1d00-0000-e3ac-e06bed120000 pid=4845 /usr/bin/dash guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=58cd6888-1d00-0000-e3ac-e06bed120000 pid=4845 clone guuid=b1127588-1d00-0000-e3ac-e06bee120000 pid=4846 /usr/bin/rm delete-file guuid=8c004282-1a00-0000-e3ac-e06b1d0c0000 pid=3101->guuid=b1127588-1d00-0000-e3ac-e06bee120000 pid=4846 execve e86f753b-e3e0-5b83-89b3-1a4358cc8e45 api.trumdvfb.com:80 guuid=ef687882-1a00-0000-e3ac-e06b1e0c0000 pid=3102->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 95B guuid=ef687882-1a00-0000-e3ac-e06b1e0c0000 pid=3112 /usr/bin/curl dns net send-data guuid=ef687882-1a00-0000-e3ac-e06b1e0c0000 pid=3102->guuid=ef687882-1a00-0000-e3ac-e06b1e0c0000 pid=3112 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=ef687882-1a00-0000-e3ac-e06b1e0c0000 pid=3112->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=1a0fc6d0-1a00-0000-e3ac-e06b900c0000 pid=3216->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 96B guuid=1a0fc6d0-1a00-0000-e3ac-e06b900c0000 pid=3217 /usr/bin/curl dns net send-data guuid=1a0fc6d0-1a00-0000-e3ac-e06b900c0000 pid=3216->guuid=1a0fc6d0-1a00-0000-e3ac-e06b900c0000 pid=3217 clone guuid=1a0fc6d0-1a00-0000-e3ac-e06b900c0000 pid=3217->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=6c56791d-1b00-0000-e3ac-e06beb0c0000 pid=3307->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 96B guuid=6c56791d-1b00-0000-e3ac-e06beb0c0000 pid=3310 /usr/bin/curl dns net send-data guuid=6c56791d-1b00-0000-e3ac-e06beb0c0000 pid=3307->guuid=6c56791d-1b00-0000-e3ac-e06beb0c0000 pid=3310 clone guuid=6c56791d-1b00-0000-e3ac-e06beb0c0000 pid=3310->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=48bf5266-1b00-0000-e3ac-e06b6f0d0000 pid=3439->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 96B guuid=48bf5266-1b00-0000-e3ac-e06b6f0d0000 pid=3447 /usr/bin/curl dns net send-data guuid=48bf5266-1b00-0000-e3ac-e06b6f0d0000 pid=3439->guuid=48bf5266-1b00-0000-e3ac-e06b6f0d0000 pid=3447 clone guuid=48bf5266-1b00-0000-e3ac-e06b6f0d0000 pid=3447->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=beba22b1-1b00-0000-e3ac-e06b050e0000 pid=3589->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 96B guuid=beba22b1-1b00-0000-e3ac-e06b050e0000 pid=3596 /usr/bin/curl dns net send-data guuid=beba22b1-1b00-0000-e3ac-e06b050e0000 pid=3589->guuid=beba22b1-1b00-0000-e3ac-e06b050e0000 pid=3596 clone guuid=beba22b1-1b00-0000-e3ac-e06b050e0000 pid=3596->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=86c22afb-1b00-0000-e3ac-e06bc80e0000 pid=3784->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 96B guuid=86c22afb-1b00-0000-e3ac-e06bc80e0000 pid=3796 /usr/bin/curl dns net send-data guuid=86c22afb-1b00-0000-e3ac-e06bc80e0000 pid=3784->guuid=86c22afb-1b00-0000-e3ac-e06bc80e0000 pid=3796 clone guuid=86c22afb-1b00-0000-e3ac-e06bc80e0000 pid=3796->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=90be0445-1c00-0000-e3ac-e06bbe0f0000 pid=4030->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 96B guuid=90be0445-1c00-0000-e3ac-e06bbe0f0000 pid=4036 /usr/bin/curl dns net send-data guuid=90be0445-1c00-0000-e3ac-e06bbe0f0000 pid=4030->guuid=90be0445-1c00-0000-e3ac-e06bbe0f0000 pid=4036 clone guuid=90be0445-1c00-0000-e3ac-e06bbe0f0000 pid=4036->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=c9234090-1c00-0000-e3ac-e06b81100000 pid=4225->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 99B guuid=c9234090-1c00-0000-e3ac-e06b81100000 pid=4236 /usr/bin/curl dns net send-data guuid=c9234090-1c00-0000-e3ac-e06b81100000 pid=4225->guuid=c9234090-1c00-0000-e3ac-e06b81100000 pid=4236 clone guuid=c9234090-1c00-0000-e3ac-e06b81100000 pid=4236->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=5eb5fcb2-1c00-0000-e3ac-e06bdc100000 pid=4316->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 95B guuid=5eb5fcb2-1c00-0000-e3ac-e06bdc100000 pid=4324 /usr/bin/curl dns net send-data guuid=5eb5fcb2-1c00-0000-e3ac-e06bdc100000 pid=4316->guuid=5eb5fcb2-1c00-0000-e3ac-e06bdc100000 pid=4324 clone guuid=5eb5fcb2-1c00-0000-e3ac-e06bdc100000 pid=4324->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=1ee96300-1d00-0000-e3ac-e06bb2110000 pid=4530->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 95B guuid=1ee96300-1d00-0000-e3ac-e06bb2110000 pid=4536 /usr/bin/curl dns net send-data guuid=1ee96300-1d00-0000-e3ac-e06bb2110000 pid=4530->guuid=1ee96300-1d00-0000-e3ac-e06bb2110000 pid=4536 clone guuid=1ee96300-1d00-0000-e3ac-e06bb2110000 pid=4536->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=8a2d243e-1d00-0000-e3ac-e06b54120000 pid=4692->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 98B guuid=8a2d243e-1d00-0000-e3ac-e06b54120000 pid=4697 /usr/bin/curl dns net send-data guuid=8a2d243e-1d00-0000-e3ac-e06b54120000 pid=4692->guuid=8a2d243e-1d00-0000-e3ac-e06b54120000 pid=4697 clone guuid=8a2d243e-1d00-0000-e3ac-e06b54120000 pid=4697->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B
Threat name:
Document-HTML.Downloader.Heuristic
Status:
Malicious
First seen:
2025-06-22 11:54:23 UTC
File Type:
Text (Shell)
AV detection:
9 of 38 (23.68%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 411f61a18b783ea8f33da8c2c30c7ae575e6e8c157ef2c9d103096904ae22349

(this sample)

  
Delivery method
Distributed via web download

Comments