MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7a0b3da343e9ce3e38bf933fe21b31bea9d0b2c28c381baf59c655d17c2d33fb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 7a0b3da343e9ce3e38bf933fe21b31bea9d0b2c28c381baf59c655d17c2d33fb
SHA3-384 hash: fd52eebffe57305b9012844027d1c340159c0a0aa5b3354e9d72831349090f6bc40fc4deafaf784b6682897217b82dc9
SHA1 hash: 9a84f0448551cd0294337b2657b175a688fee3f2
MD5 hash: 468d118d95afd541158485f3c5dfa448
humanhash: quebec-high-arkansas-mango
File name:curl.sh
Download: download sample
File size:967 bytes
First seen:2025-06-27 16:56:43 UTC
Last seen:2025-06-28 22:39:06 UTC
File type: sh
MIME type:text/plain
ssdeep 24:3J3mD0bD0GD0UGNINID0gKQD0XD00D0RND0oD0Z2D07D0v1U:wMvgvBiB+NTi2Yy1U
TLSH T1671166FB00EDB4822B28CC34F0295C0DB1838AF071B1D781F08EE879E1A97361275769
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://mafia.trumdvfb.com/skibdi/cutearmn/an/an/a
http://mafia.trumdvfb.com/skibdi/cutearm5n/an/an/a
http://mafia.trumdvfb.com/skibdi/cutearm6n/an/an/a
http://mafia.trumdvfb.com/skibdi/cutearm7n/an/an/a
http://mafia.trumdvfb.com/skibdi/cutem68kn/an/an/a
http://mafia.trumdvfb.com/skibdi/cutemipsn/an/an/a
http://mafia.trumdvfb.com/skibdi/cutempsln/an/an/a
http://mafia.trumdvfb.com/skibdi/cuteppcn/an/an/a
http://mafia.trumdvfb.com/skibdi/cutesh4n/an/an/a
http://mafia.trumdvfb.com/skibdi/cutex86n/an/an/a
http://mafia.trumdvfb.com/skibdi/cutex86_64n/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
119
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=743c6445-1900-0000-816b-9fb7900b0000 pid=2960 /usr/bin/sudo guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963 /tmp/sample.bin guuid=743c6445-1900-0000-816b-9fb7900b0000 pid=2960->guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963 execve guuid=d1a74947-1900-0000-816b-9fb7940b0000 pid=2964 /usr/bin/curl net send-data guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=d1a74947-1900-0000-816b-9fb7940b0000 pid=2964 execve guuid=645de76a-1900-0000-816b-9fb7e80b0000 pid=3048 /usr/bin/chmod guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=645de76a-1900-0000-816b-9fb7e80b0000 pid=3048 execve guuid=257b1f6b-1900-0000-816b-9fb7ea0b0000 pid=3050 /usr/bin/dash guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=257b1f6b-1900-0000-816b-9fb7ea0b0000 pid=3050 clone guuid=3205256b-1900-0000-816b-9fb7eb0b0000 pid=3051 /usr/bin/curl net send-data guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=3205256b-1900-0000-816b-9fb7eb0b0000 pid=3051 execve guuid=6649228b-1900-0000-816b-9fb7260c0000 pid=3110 /usr/bin/chmod guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=6649228b-1900-0000-816b-9fb7260c0000 pid=3110 execve guuid=a9b2c68b-1900-0000-816b-9fb7290c0000 pid=3113 /usr/bin/dash guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=a9b2c68b-1900-0000-816b-9fb7290c0000 pid=3113 clone guuid=e79adc8b-1900-0000-816b-9fb72a0c0000 pid=3114 /usr/bin/curl net send-data guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=e79adc8b-1900-0000-816b-9fb72a0c0000 pid=3114 execve guuid=c5cd52ab-1900-0000-816b-9fb7610c0000 pid=3169 /usr/bin/chmod guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=c5cd52ab-1900-0000-816b-9fb7610c0000 pid=3169 execve guuid=67eedcab-1900-0000-816b-9fb7620c0000 pid=3170 /usr/bin/dash guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=67eedcab-1900-0000-816b-9fb7620c0000 pid=3170 clone guuid=35b0f5ab-1900-0000-816b-9fb7630c0000 pid=3171 /usr/bin/curl net send-data guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=35b0f5ab-1900-0000-816b-9fb7630c0000 pid=3171 execve guuid=aef9dbcd-1900-0000-816b-9fb78a0c0000 pid=3210 /usr/bin/chmod guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=aef9dbcd-1900-0000-816b-9fb78a0c0000 pid=3210 execve guuid=f26266ce-1900-0000-816b-9fb78d0c0000 pid=3213 /usr/bin/dash guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=f26266ce-1900-0000-816b-9fb78d0c0000 pid=3213 clone guuid=5dab74ce-1900-0000-816b-9fb78e0c0000 pid=3214 /usr/bin/curl net send-data guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=5dab74ce-1900-0000-816b-9fb78e0c0000 pid=3214 execve guuid=95f10eed-1900-0000-816b-9fb7ae0c0000 pid=3246 /usr/bin/chmod guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=95f10eed-1900-0000-816b-9fb7ae0c0000 pid=3246 execve guuid=972692ed-1900-0000-816b-9fb7b00c0000 pid=3248 /usr/bin/dash guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=972692ed-1900-0000-816b-9fb7b00c0000 pid=3248 clone guuid=d1b7aaed-1900-0000-816b-9fb7b10c0000 pid=3249 /usr/bin/curl net send-data guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=d1b7aaed-1900-0000-816b-9fb7b10c0000 pid=3249 execve guuid=87fe810e-1a00-0000-816b-9fb7ce0c0000 pid=3278 /usr/bin/chmod guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=87fe810e-1a00-0000-816b-9fb7ce0c0000 pid=3278 execve guuid=f11f0e0f-1a00-0000-816b-9fb7d00c0000 pid=3280 /usr/bin/dash guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=f11f0e0f-1a00-0000-816b-9fb7d00c0000 pid=3280 clone guuid=267d1d0f-1a00-0000-816b-9fb7d10c0000 pid=3281 /usr/bin/curl net send-data guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=267d1d0f-1a00-0000-816b-9fb7d10c0000 pid=3281 execve guuid=7f686b32-1a00-0000-816b-9fb70a0d0000 pid=3338 /usr/bin/chmod guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=7f686b32-1a00-0000-816b-9fb70a0d0000 pid=3338 execve guuid=b91ced32-1a00-0000-816b-9fb70c0d0000 pid=3340 /usr/bin/dash guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=b91ced32-1a00-0000-816b-9fb70c0d0000 pid=3340 clone guuid=93310c33-1a00-0000-816b-9fb70e0d0000 pid=3342 /usr/bin/curl net send-data guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=93310c33-1a00-0000-816b-9fb70e0d0000 pid=3342 execve guuid=574b9a54-1a00-0000-816b-9fb7430d0000 pid=3395 /usr/bin/chmod guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=574b9a54-1a00-0000-816b-9fb7430d0000 pid=3395 execve guuid=80230555-1a00-0000-816b-9fb7440d0000 pid=3396 /usr/bin/dash guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=80230555-1a00-0000-816b-9fb7440d0000 pid=3396 clone guuid=14a72255-1a00-0000-816b-9fb7460d0000 pid=3398 /usr/bin/curl net send-data guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=14a72255-1a00-0000-816b-9fb7460d0000 pid=3398 execve guuid=d0da1876-1a00-0000-816b-9fb7820d0000 pid=3458 /usr/bin/chmod guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=d0da1876-1a00-0000-816b-9fb7820d0000 pid=3458 execve guuid=eece8a76-1a00-0000-816b-9fb7830d0000 pid=3459 /usr/bin/dash guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=eece8a76-1a00-0000-816b-9fb7830d0000 pid=3459 clone guuid=a4259b76-1a00-0000-816b-9fb7840d0000 pid=3460 /usr/bin/curl net send-data guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=a4259b76-1a00-0000-816b-9fb7840d0000 pid=3460 execve guuid=2fc1cc96-1a00-0000-816b-9fb7d00d0000 pid=3536 /usr/bin/chmod guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=2fc1cc96-1a00-0000-816b-9fb7d00d0000 pid=3536 execve guuid=bbe72397-1a00-0000-816b-9fb7d10d0000 pid=3537 /usr/bin/dash guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=bbe72397-1a00-0000-816b-9fb7d10d0000 pid=3537 clone guuid=cfed3197-1a00-0000-816b-9fb7d20d0000 pid=3538 /usr/bin/curl net send-data guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=cfed3197-1a00-0000-816b-9fb7d20d0000 pid=3538 execve guuid=cab01fbd-1a00-0000-816b-9fb71a0e0000 pid=3610 /usr/bin/chmod guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=cab01fbd-1a00-0000-816b-9fb71a0e0000 pid=3610 execve guuid=7620d6bd-1a00-0000-816b-9fb71b0e0000 pid=3611 /usr/bin/dash guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=7620d6bd-1a00-0000-816b-9fb71b0e0000 pid=3611 clone guuid=a4b2edbd-1a00-0000-816b-9fb71c0e0000 pid=3612 /usr/bin/rm delete-file guuid=67b30b47-1900-0000-816b-9fb7930b0000 pid=2963->guuid=a4b2edbd-1a00-0000-816b-9fb71c0e0000 pid=3612 execve ae352235-8098-59df-9f11-a305b88fdf27 mafia.trumdvfb.com:80 guuid=d1a74947-1900-0000-816b-9fb7940b0000 pid=2964->ae352235-8098-59df-9f11-a305b88fdf27 send: 96B guuid=d1a74947-1900-0000-816b-9fb7940b0000 pid=2976 /usr/bin/curl dns net send-data guuid=d1a74947-1900-0000-816b-9fb7940b0000 pid=2964->guuid=d1a74947-1900-0000-816b-9fb7940b0000 pid=2976 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=d1a74947-1900-0000-816b-9fb7940b0000 pid=2976->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=3205256b-1900-0000-816b-9fb7eb0b0000 pid=3051->ae352235-8098-59df-9f11-a305b88fdf27 send: 97B guuid=3205256b-1900-0000-816b-9fb7eb0b0000 pid=3057 /usr/bin/curl dns net send-data guuid=3205256b-1900-0000-816b-9fb7eb0b0000 pid=3051->guuid=3205256b-1900-0000-816b-9fb7eb0b0000 pid=3057 clone guuid=3205256b-1900-0000-816b-9fb7eb0b0000 pid=3057->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=e79adc8b-1900-0000-816b-9fb72a0c0000 pid=3114->ae352235-8098-59df-9f11-a305b88fdf27 send: 97B guuid=e79adc8b-1900-0000-816b-9fb72a0c0000 pid=3120 /usr/bin/curl dns net send-data guuid=e79adc8b-1900-0000-816b-9fb72a0c0000 pid=3114->guuid=e79adc8b-1900-0000-816b-9fb72a0c0000 pid=3120 clone guuid=e79adc8b-1900-0000-816b-9fb72a0c0000 pid=3120->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=35b0f5ab-1900-0000-816b-9fb7630c0000 pid=3171->ae352235-8098-59df-9f11-a305b88fdf27 send: 97B guuid=35b0f5ab-1900-0000-816b-9fb7630c0000 pid=3179 /usr/bin/curl dns net send-data guuid=35b0f5ab-1900-0000-816b-9fb7630c0000 pid=3171->guuid=35b0f5ab-1900-0000-816b-9fb7630c0000 pid=3179 clone guuid=35b0f5ab-1900-0000-816b-9fb7630c0000 pid=3179->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=5dab74ce-1900-0000-816b-9fb78e0c0000 pid=3214->ae352235-8098-59df-9f11-a305b88fdf27 send: 97B guuid=5dab74ce-1900-0000-816b-9fb78e0c0000 pid=3216 /usr/bin/curl dns net send-data guuid=5dab74ce-1900-0000-816b-9fb78e0c0000 pid=3214->guuid=5dab74ce-1900-0000-816b-9fb78e0c0000 pid=3216 clone guuid=5dab74ce-1900-0000-816b-9fb78e0c0000 pid=3216->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=d1b7aaed-1900-0000-816b-9fb7b10c0000 pid=3249->ae352235-8098-59df-9f11-a305b88fdf27 send: 97B guuid=d1b7aaed-1900-0000-816b-9fb7b10c0000 pid=3251 /usr/bin/curl dns net send-data guuid=d1b7aaed-1900-0000-816b-9fb7b10c0000 pid=3249->guuid=d1b7aaed-1900-0000-816b-9fb7b10c0000 pid=3251 clone guuid=d1b7aaed-1900-0000-816b-9fb7b10c0000 pid=3251->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=267d1d0f-1a00-0000-816b-9fb7d10c0000 pid=3281->ae352235-8098-59df-9f11-a305b88fdf27 send: 97B guuid=267d1d0f-1a00-0000-816b-9fb7d10c0000 pid=3290 /usr/bin/curl dns net send-data guuid=267d1d0f-1a00-0000-816b-9fb7d10c0000 pid=3281->guuid=267d1d0f-1a00-0000-816b-9fb7d10c0000 pid=3290 clone guuid=267d1d0f-1a00-0000-816b-9fb7d10c0000 pid=3290->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=93310c33-1a00-0000-816b-9fb70e0d0000 pid=3342->ae352235-8098-59df-9f11-a305b88fdf27 send: 96B guuid=93310c33-1a00-0000-816b-9fb70e0d0000 pid=3351 /usr/bin/curl dns net send-data guuid=93310c33-1a00-0000-816b-9fb70e0d0000 pid=3342->guuid=93310c33-1a00-0000-816b-9fb70e0d0000 pid=3351 clone guuid=93310c33-1a00-0000-816b-9fb70e0d0000 pid=3351->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=14a72255-1a00-0000-816b-9fb7460d0000 pid=3398->ae352235-8098-59df-9f11-a305b88fdf27 send: 96B guuid=14a72255-1a00-0000-816b-9fb7460d0000 pid=3401 /usr/bin/curl dns net send-data guuid=14a72255-1a00-0000-816b-9fb7460d0000 pid=3398->guuid=14a72255-1a00-0000-816b-9fb7460d0000 pid=3401 clone guuid=14a72255-1a00-0000-816b-9fb7460d0000 pid=3401->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=a4259b76-1a00-0000-816b-9fb7840d0000 pid=3460->ae352235-8098-59df-9f11-a305b88fdf27 send: 96B guuid=a4259b76-1a00-0000-816b-9fb7840d0000 pid=3468 /usr/bin/curl dns net send-data guuid=a4259b76-1a00-0000-816b-9fb7840d0000 pid=3460->guuid=a4259b76-1a00-0000-816b-9fb7840d0000 pid=3468 clone guuid=a4259b76-1a00-0000-816b-9fb7840d0000 pid=3468->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B guuid=cfed3197-1a00-0000-816b-9fb7d20d0000 pid=3538->ae352235-8098-59df-9f11-a305b88fdf27 send: 99B guuid=cfed3197-1a00-0000-816b-9fb7d20d0000 pid=3544 /usr/bin/curl dns net send-data guuid=cfed3197-1a00-0000-816b-9fb7d20d0000 pid=3538->guuid=cfed3197-1a00-0000-816b-9fb7d20d0000 pid=3544 clone guuid=cfed3197-1a00-0000-816b-9fb7d20d0000 pid=3544->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B
Threat name:
Document-HTML.Downloader.Heuristic
Status:
Malicious
First seen:
2025-06-27 16:57:24 UTC
File Type:
Text (Shell)
AV detection:
8 of 38 (21.05%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 7a0b3da343e9ce3e38bf933fe21b31bea9d0b2c28c381baf59c655d17c2d33fb

(this sample)

  
Delivery method
Distributed via web download

Comments