MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5fb7ef38e1397c6bd636bd31de186865e91d7cca9e20701dd1a594468f424c90. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 5fb7ef38e1397c6bd636bd31de186865e91d7cca9e20701dd1a594468f424c90
SHA3-384 hash: d03b1f6a8ee798abd72005036161cdfa86787ff845e301b3c126339a11241c463899b026fb67af0e4febfcaac2853f5b
SHA1 hash: e49b30ca528c504dd1e2c0b618e5829ef0959bce
MD5 hash: 34146748430de6f3de86aedda1b2a380
humanhash: virginia-oregon-monkey-quiet
File name:wget.sh
Download: download sample
File size:957 bytes
First seen:2025-06-22 11:48:34 UTC
Last seen:2025-06-22 19:26:44 UTC
File type: sh
MIME type:text/plain
ssdeep 24:o6I76IC6IRGNINX6InKP6I96Ig6IGM6I3V6IaR6If6I6f:op7pCpXpn4p9pgpGMp3VpaRpfp6f
TLSH T18311BCEA4019740644259C30703D2E41E68BC7E076A8DB45F4CAD4F7D5A9A3A63B9F4F
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://api.trumdvfb.com/skibidi/cutearmn/an/an/a
http://api.trumdvfb.com/skibidi/cutearm5n/an/an/a
http://api.trumdvfb.com/skibidi/cutearm6n/an/an/a
http://api.trumdvfb.com/skibidi/cutearm7n/an/an/a
http://api.trumdvfb.com/skibidi/cutem68kn/an/an/a
http://api.trumdvfb.com/skibidi/cutemipsn/an/an/a
http://api.trumdvfb.com/skibidi/cutempsln/an/an/a
http://api.trumdvfb.com/skibidi/cutepowerpcn/an/abotnetdomain elf ua-wget
http://api.trumdvfb.com/skibidi/cutesh4n/an/an/a
http://api.trumdvfb.com/skibidi/cutex86n/an/an/a
http://api.trumdvfb.com/skibidi/cutex86_64n/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
57
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
lolbin mirai remote
Status:
terminated
Behavior Graph:
%3 guuid=c087b1b5-1800-0000-94a1-25f5610b0000 pid=2913 /usr/bin/sudo guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916 /tmp/sample.bin guuid=c087b1b5-1800-0000-94a1-25f5610b0000 pid=2913->guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916 execve guuid=bb2f27b8-1800-0000-94a1-25f5650b0000 pid=2917 /usr/bin/wget dns net send-data write-file guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=bb2f27b8-1800-0000-94a1-25f5650b0000 pid=2917 execve guuid=7d3cd007-1900-0000-94a1-25f5200c0000 pid=3104 /usr/bin/chmod guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=7d3cd007-1900-0000-94a1-25f5200c0000 pid=3104 execve guuid=0e9a0808-1900-0000-94a1-25f5210c0000 pid=3105 /usr/bin/dash guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=0e9a0808-1900-0000-94a1-25f5210c0000 pid=3105 clone guuid=b26c8408-1900-0000-94a1-25f5240c0000 pid=3108 /usr/bin/wget dns net send-data write-file guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=b26c8408-1900-0000-94a1-25f5240c0000 pid=3108 execve guuid=57179252-1900-0000-94a1-25f58f0c0000 pid=3215 /usr/bin/chmod guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=57179252-1900-0000-94a1-25f58f0c0000 pid=3215 execve guuid=ffb5e452-1900-0000-94a1-25f5900c0000 pid=3216 /usr/bin/dash guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=ffb5e452-1900-0000-94a1-25f5900c0000 pid=3216 clone guuid=d7b8ce53-1900-0000-94a1-25f5920c0000 pid=3218 /usr/bin/wget dns net send-data write-file guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=d7b8ce53-1900-0000-94a1-25f5920c0000 pid=3218 execve guuid=5aa91c9c-1900-0000-94a1-25f5140d0000 pid=3348 /usr/bin/chmod guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=5aa91c9c-1900-0000-94a1-25f5140d0000 pid=3348 execve guuid=d0e0729c-1900-0000-94a1-25f5160d0000 pid=3350 /usr/bin/dash guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=d0e0729c-1900-0000-94a1-25f5160d0000 pid=3350 clone guuid=09b6769d-1900-0000-94a1-25f51a0d0000 pid=3354 /usr/bin/wget dns net send-data write-file guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=09b6769d-1900-0000-94a1-25f51a0d0000 pid=3354 execve guuid=f838a5e8-1900-0000-94a1-25f5a40d0000 pid=3492 /usr/bin/chmod guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=f838a5e8-1900-0000-94a1-25f5a40d0000 pid=3492 execve guuid=b90d46e9-1900-0000-94a1-25f5a60d0000 pid=3494 /usr/bin/dash guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=b90d46e9-1900-0000-94a1-25f5a60d0000 pid=3494 clone guuid=fef644ea-1900-0000-94a1-25f5aa0d0000 pid=3498 /usr/bin/wget dns net send-data write-file guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=fef644ea-1900-0000-94a1-25f5aa0d0000 pid=3498 execve guuid=10b91832-1a00-0000-94a1-25f51e0e0000 pid=3614 /usr/bin/chmod guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=10b91832-1a00-0000-94a1-25f51e0e0000 pid=3614 execve guuid=f55c8a32-1a00-0000-94a1-25f5200e0000 pid=3616 /usr/bin/dash guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=f55c8a32-1a00-0000-94a1-25f5200e0000 pid=3616 clone guuid=ac12ef33-1a00-0000-94a1-25f5240e0000 pid=3620 /usr/bin/wget dns net send-data write-file guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=ac12ef33-1a00-0000-94a1-25f5240e0000 pid=3620 execve guuid=84ba2b7f-1a00-0000-94a1-25f5a70e0000 pid=3751 /usr/bin/chmod guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=84ba2b7f-1a00-0000-94a1-25f5a70e0000 pid=3751 execve guuid=c036ad7f-1a00-0000-94a1-25f5a90e0000 pid=3753 /usr/bin/dash guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=c036ad7f-1a00-0000-94a1-25f5a90e0000 pid=3753 clone guuid=668f2181-1a00-0000-94a1-25f5b00e0000 pid=3760 /usr/bin/wget dns net send-data write-file guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=668f2181-1a00-0000-94a1-25f5b00e0000 pid=3760 execve guuid=b1d8a7c8-1a00-0000-94a1-25f57b0f0000 pid=3963 /usr/bin/chmod guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=b1d8a7c8-1a00-0000-94a1-25f57b0f0000 pid=3963 execve guuid=b3b30ac9-1a00-0000-94a1-25f57d0f0000 pid=3965 /usr/bin/dash guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=b3b30ac9-1a00-0000-94a1-25f57d0f0000 pid=3965 clone guuid=c30ed4c9-1a00-0000-94a1-25f5810f0000 pid=3969 /usr/bin/wget dns net send-data guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=c30ed4c9-1a00-0000-94a1-25f5810f0000 pid=3969 execve guuid=90eb28ea-1a00-0000-94a1-25f5e60f0000 pid=4070 /usr/bin/chmod guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=90eb28ea-1a00-0000-94a1-25f5e60f0000 pid=4070 execve guuid=60bc52eb-1a00-0000-94a1-25f5e90f0000 pid=4073 /usr/bin/dash guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=60bc52eb-1a00-0000-94a1-25f5e90f0000 pid=4073 clone guuid=5cb362eb-1a00-0000-94a1-25f5ea0f0000 pid=4074 /usr/bin/wget dns net send-data write-file guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=5cb362eb-1a00-0000-94a1-25f5ea0f0000 pid=4074 execve guuid=ab0bfe33-1b00-0000-94a1-25f5a1100000 pid=4257 /usr/bin/chmod guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=ab0bfe33-1b00-0000-94a1-25f5a1100000 pid=4257 execve guuid=cd336b34-1b00-0000-94a1-25f5a3100000 pid=4259 /usr/bin/dash guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=cd336b34-1b00-0000-94a1-25f5a3100000 pid=4259 clone guuid=96803c35-1b00-0000-94a1-25f5a8100000 pid=4264 /usr/bin/wget dns net send-data write-file guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=96803c35-1b00-0000-94a1-25f5a8100000 pid=4264 execve guuid=bf0ed472-1b00-0000-94a1-25f544110000 pid=4420 /usr/bin/chmod guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=bf0ed472-1b00-0000-94a1-25f544110000 pid=4420 execve guuid=18c62d73-1b00-0000-94a1-25f547110000 pid=4423 /home/sandbox/cutex86 delete-file net guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=18c62d73-1b00-0000-94a1-25f547110000 pid=4423 execve guuid=77cc6e73-1b00-0000-94a1-25f549110000 pid=4425 /usr/bin/wget dns net send-data write-file guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=77cc6e73-1b00-0000-94a1-25f549110000 pid=4425 execve guuid=83c0e3bb-1b00-0000-94a1-25f510120000 pid=4624 /usr/bin/chmod guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=83c0e3bb-1b00-0000-94a1-25f510120000 pid=4624 execve guuid=c4273ebc-1b00-0000-94a1-25f514120000 pid=4628 /home/sandbox/cutex86_64 delete-file net guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=c4273ebc-1b00-0000-94a1-25f514120000 pid=4628 execve guuid=396c6dbc-1b00-0000-94a1-25f516120000 pid=4630 /usr/bin/rm delete-file guuid=703fddb7-1800-0000-94a1-25f5640b0000 pid=2916->guuid=396c6dbc-1b00-0000-94a1-25f516120000 pid=4630 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=bb2f27b8-1800-0000-94a1-25f5650b0000 pid=2917->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B e86f753b-e3e0-5b83-89b3-1a4358cc8e45 api.trumdvfb.com:80 guuid=bb2f27b8-1800-0000-94a1-25f5650b0000 pid=2917->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 146B guuid=b26c8408-1900-0000-94a1-25f5240c0000 pid=3108->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=b26c8408-1900-0000-94a1-25f5240c0000 pid=3108->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 147B guuid=d7b8ce53-1900-0000-94a1-25f5920c0000 pid=3218->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=d7b8ce53-1900-0000-94a1-25f5920c0000 pid=3218->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 147B guuid=09b6769d-1900-0000-94a1-25f51a0d0000 pid=3354->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=09b6769d-1900-0000-94a1-25f51a0d0000 pid=3354->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 147B guuid=fef644ea-1900-0000-94a1-25f5aa0d0000 pid=3498->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=fef644ea-1900-0000-94a1-25f5aa0d0000 pid=3498->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 147B guuid=ac12ef33-1a00-0000-94a1-25f5240e0000 pid=3620->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=ac12ef33-1a00-0000-94a1-25f5240e0000 pid=3620->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 147B guuid=668f2181-1a00-0000-94a1-25f5b00e0000 pid=3760->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=668f2181-1a00-0000-94a1-25f5b00e0000 pid=3760->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 147B guuid=c30ed4c9-1a00-0000-94a1-25f5810f0000 pid=3969->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=c30ed4c9-1a00-0000-94a1-25f5810f0000 pid=3969->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 150B guuid=5cb362eb-1a00-0000-94a1-25f5ea0f0000 pid=4074->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=5cb362eb-1a00-0000-94a1-25f5ea0f0000 pid=4074->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 146B guuid=96803c35-1b00-0000-94a1-25f5a8100000 pid=4264->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=96803c35-1b00-0000-94a1-25f5a8100000 pid=4264->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 146B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=18c62d73-1b00-0000-94a1-25f547110000 pid=4423->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=aed75d73-1b00-0000-94a1-25f548110000 pid=4424 /home/sandbox/cutex86 dns net send-data zombie guuid=18c62d73-1b00-0000-94a1-25f547110000 pid=4423->guuid=aed75d73-1b00-0000-94a1-25f548110000 pid=4424 clone guuid=aed75d73-1b00-0000-94a1-25f548110000 pid=4424->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 34B 22e444ea-a1a0-531c-ad62-dd3765f3048a api.trumdvfb.com:1995 guuid=aed75d73-1b00-0000-94a1-25f548110000 pid=4424->22e444ea-a1a0-531c-ad62-dd3765f3048a send: 14B guuid=2cc48173-1b00-0000-94a1-25f54a110000 pid=4426 /home/sandbox/cutex86 guuid=aed75d73-1b00-0000-94a1-25f548110000 pid=4424->guuid=2cc48173-1b00-0000-94a1-25f54a110000 pid=4426 clone guuid=77cc6e73-1b00-0000-94a1-25f549110000 pid=4425->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=77cc6e73-1b00-0000-94a1-25f549110000 pid=4425->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 149B guuid=c4273ebc-1b00-0000-94a1-25f514120000 pid=4628->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c3a461bc-1b00-0000-94a1-25f515120000 pid=4629 /home/sandbox/cutex86_64 dns net send-data zombie guuid=c4273ebc-1b00-0000-94a1-25f514120000 pid=4628->guuid=c3a461bc-1b00-0000-94a1-25f515120000 pid=4629 clone guuid=c3a461bc-1b00-0000-94a1-25f515120000 pid=4629->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 34B guuid=c3a461bc-1b00-0000-94a1-25f515120000 pid=4629->22e444ea-a1a0-531c-ad62-dd3765f3048a send: 14B guuid=8f1577bc-1b00-0000-94a1-25f517120000 pid=4631 /home/sandbox/cutex86_64 guuid=c3a461bc-1b00-0000-94a1-25f515120000 pid=4629->guuid=8f1577bc-1b00-0000-94a1-25f517120000 pid=4631 clone
Threat name:
Document-HTML.Downloader.Heuristic
Status:
Malicious
First seen:
2025-06-22 11:49:31 UTC
File Type:
Text (Shell)
AV detection:
9 of 38 (23.68%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 5fb7ef38e1397c6bd636bd31de186865e91d7cca9e20701dd1a594468f424c90

(this sample)

  
Delivery method
Distributed via web download

Comments