MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7f3b5f8d7eb6fba8a1a9ff8c8177f20adff2dab75cca40bf38161f6afd82ef9c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 7f3b5f8d7eb6fba8a1a9ff8c8177f20adff2dab75cca40bf38161f6afd82ef9c
SHA3-384 hash: 3f024c82e8b70624ee28256e45036ce267e8df275d66ddc426f1ad2148fb5109465bc33ca29f54552324621738a76677
SHA1 hash: fb917ccf246a000a6823763a0d0e692adec87d54
MD5 hash: 2f05f4373e3da24ad387ea59a76f5706
humanhash: august-lake-cold-grey
File name:wget.sh
Download: download sample
File size:891 bytes
First seen:2025-06-21 17:29:03 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:9cs6v16csEvcsBNIv+csyWAKSqycs2QcslSJl5csvqAcsmZ/x+FcsOc8csmApcsx:9d6v16dEvd2+dyWAxqyd2QdlSX5dvqAg
TLSH T1371148990490660D4929CF0CB0AE4B106F46C6A5B1BABF9C6D6988239C9B530706CF0F
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.149.252.178/main.armn/an/an/a
http://103.149.252.178/main.arm5n/an/an/a
http://103.149.252.178/main.arm6n/an/an/a
http://103.149.252.178/main.arm7n/an/an/a
http://103.149.252.178/main.m68kn/an/an/a
http://103.149.252.178/main.mipsn/an/an/a
http://103.149.252.178/main.mpsln/an/an/a
http://103.149.252.178/main.powerpcn/an/an/a
http://103.149.252.178/main.sh4n/an/an/a
http://103.149.252.178/main.x86n/an/an/a
http://103.149.252.178/main.x86_64n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
97.4%
Tags:
downloader mirai agent virus
Status:
terminated
Behavior Graph:
%3 guuid=581039d9-1800-0000-1cb9-53d478100000 pid=4216 /usr/bin/sudo guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225 /tmp/sample.bin guuid=581039d9-1800-0000-1cb9-53d478100000 pid=4216->guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225 execve guuid=51f36cdb-1800-0000-1cb9-53d485100000 pid=4229 /usr/bin/wget net send-data write-file guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=51f36cdb-1800-0000-1cb9-53d485100000 pid=4229 execve guuid=bfb61723-1900-0000-1cb9-53d47b110000 pid=4475 /usr/bin/chmod guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=bfb61723-1900-0000-1cb9-53d47b110000 pid=4475 execve guuid=54e25923-1900-0000-1cb9-53d47d110000 pid=4477 /usr/bin/dash guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=54e25923-1900-0000-1cb9-53d47d110000 pid=4477 clone guuid=adc32924-1900-0000-1cb9-53d47f110000 pid=4479 /usr/bin/wget net send-data write-file guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=adc32924-1900-0000-1cb9-53d47f110000 pid=4479 execve guuid=fb0f4c6b-1900-0000-1cb9-53d433120000 pid=4659 /usr/bin/chmod guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=fb0f4c6b-1900-0000-1cb9-53d433120000 pid=4659 execve guuid=3fd3bf6b-1900-0000-1cb9-53d435120000 pid=4661 /usr/bin/dash guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=3fd3bf6b-1900-0000-1cb9-53d435120000 pid=4661 clone guuid=1e1fe06d-1900-0000-1cb9-53d442120000 pid=4674 /usr/bin/wget net send-data write-file guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=1e1fe06d-1900-0000-1cb9-53d442120000 pid=4674 execve guuid=25a4ffb3-1900-0000-1cb9-53d412130000 pid=4882 /usr/bin/chmod guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=25a4ffb3-1900-0000-1cb9-53d412130000 pid=4882 execve guuid=fba694b4-1900-0000-1cb9-53d414130000 pid=4884 /usr/bin/dash guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=fba694b4-1900-0000-1cb9-53d414130000 pid=4884 clone guuid=a9850cb6-1900-0000-1cb9-53d418130000 pid=4888 /usr/bin/wget net send-data write-file guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=a9850cb6-1900-0000-1cb9-53d418130000 pid=4888 execve guuid=5abafbfc-1900-0000-1cb9-53d475130000 pid=4981 /usr/bin/chmod guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=5abafbfc-1900-0000-1cb9-53d475130000 pid=4981 execve guuid=a0126cfd-1900-0000-1cb9-53d478130000 pid=4984 /usr/bin/dash guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=a0126cfd-1900-0000-1cb9-53d478130000 pid=4984 clone guuid=42c6e1ff-1900-0000-1cb9-53d483130000 pid=4995 /usr/bin/wget net send-data write-file guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=42c6e1ff-1900-0000-1cb9-53d483130000 pid=4995 execve guuid=6d08b847-1a00-0000-1cb9-53d43b140000 pid=5179 /usr/bin/chmod guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=6d08b847-1a00-0000-1cb9-53d43b140000 pid=5179 execve guuid=31ad1348-1a00-0000-1cb9-53d43d140000 pid=5181 /usr/bin/dash guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=31ad1348-1a00-0000-1cb9-53d43d140000 pid=5181 clone guuid=5bf0a248-1a00-0000-1cb9-53d443140000 pid=5187 /usr/bin/wget net send-data write-file guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=5bf0a248-1a00-0000-1cb9-53d443140000 pid=5187 execve guuid=2d5d4d8f-1a00-0000-1cb9-53d469140000 pid=5225 /usr/bin/chmod guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=2d5d4d8f-1a00-0000-1cb9-53d469140000 pid=5225 execve guuid=d779968f-1a00-0000-1cb9-53d46a140000 pid=5226 /usr/bin/dash guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=d779968f-1a00-0000-1cb9-53d46a140000 pid=5226 clone guuid=afc12990-1a00-0000-1cb9-53d46e140000 pid=5230 /usr/bin/wget net send-data write-file guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=afc12990-1a00-0000-1cb9-53d46e140000 pid=5230 execve guuid=63d6a0d6-1a00-0000-1cb9-53d475140000 pid=5237 /usr/bin/chmod guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=63d6a0d6-1a00-0000-1cb9-53d475140000 pid=5237 execve guuid=f52414d7-1a00-0000-1cb9-53d476140000 pid=5238 /usr/bin/dash guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=f52414d7-1a00-0000-1cb9-53d476140000 pid=5238 clone guuid=68c37ed8-1a00-0000-1cb9-53d478140000 pid=5240 /usr/bin/wget net send-data guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=68c37ed8-1a00-0000-1cb9-53d478140000 pid=5240 execve guuid=5265acf5-1a00-0000-1cb9-53d479140000 pid=5241 /usr/bin/chmod guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=5265acf5-1a00-0000-1cb9-53d479140000 pid=5241 execve guuid=d003f8f5-1a00-0000-1cb9-53d47a140000 pid=5242 /usr/bin/dash guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=d003f8f5-1a00-0000-1cb9-53d47a140000 pid=5242 clone guuid=cfab06f6-1a00-0000-1cb9-53d47b140000 pid=5243 /usr/bin/wget net send-data write-file guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=cfab06f6-1a00-0000-1cb9-53d47b140000 pid=5243 execve guuid=3b5f383f-1b00-0000-1cb9-53d47c140000 pid=5244 /usr/bin/chmod guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=3b5f383f-1b00-0000-1cb9-53d47c140000 pid=5244 execve guuid=e5968c3f-1b00-0000-1cb9-53d47d140000 pid=5245 /usr/bin/dash guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=e5968c3f-1b00-0000-1cb9-53d47d140000 pid=5245 clone guuid=e55fc640-1b00-0000-1cb9-53d47f140000 pid=5247 /usr/bin/wget net send-data write-file guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=e55fc640-1b00-0000-1cb9-53d47f140000 pid=5247 execve guuid=d189597a-1b00-0000-1cb9-53d487140000 pid=5255 /usr/bin/chmod guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=d189597a-1b00-0000-1cb9-53d487140000 pid=5255 execve guuid=9593c77a-1b00-0000-1cb9-53d488140000 pid=5256 /home/sandbox/main.x86 delete-file net guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=9593c77a-1b00-0000-1cb9-53d488140000 pid=5256 execve guuid=4a8efb7a-1b00-0000-1cb9-53d48a140000 pid=5258 /usr/bin/wget net send-data write-file guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=4a8efb7a-1b00-0000-1cb9-53d48a140000 pid=5258 execve guuid=de4326c4-1b00-0000-1cb9-53d48c140000 pid=5260 /usr/bin/chmod guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=de4326c4-1b00-0000-1cb9-53d48c140000 pid=5260 execve guuid=32982fc5-1b00-0000-1cb9-53d48d140000 pid=5261 /home/sandbox/main.x86_64 delete-file net guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=32982fc5-1b00-0000-1cb9-53d48d140000 pid=5261 execve guuid=c84d85c6-1b00-0000-1cb9-53d48f140000 pid=5263 /usr/bin/rm delete-file guuid=5cac18db-1800-0000-1cb9-53d481100000 pid=4225->guuid=c84d85c6-1b00-0000-1cb9-53d48f140000 pid=5263 execve b95ce511-3591-5114-995b-9ce77bb440cb 103.149.252.178:80 guuid=51f36cdb-1800-0000-1cb9-53d485100000 pid=4229->b95ce511-3591-5114-995b-9ce77bb440cb send: 138B guuid=adc32924-1900-0000-1cb9-53d47f110000 pid=4479->b95ce511-3591-5114-995b-9ce77bb440cb send: 139B guuid=1e1fe06d-1900-0000-1cb9-53d442120000 pid=4674->b95ce511-3591-5114-995b-9ce77bb440cb send: 139B guuid=a9850cb6-1900-0000-1cb9-53d418130000 pid=4888->b95ce511-3591-5114-995b-9ce77bb440cb send: 139B guuid=42c6e1ff-1900-0000-1cb9-53d483130000 pid=4995->b95ce511-3591-5114-995b-9ce77bb440cb send: 139B guuid=5bf0a248-1a00-0000-1cb9-53d443140000 pid=5187->b95ce511-3591-5114-995b-9ce77bb440cb send: 139B guuid=afc12990-1a00-0000-1cb9-53d46e140000 pid=5230->b95ce511-3591-5114-995b-9ce77bb440cb send: 139B guuid=68c37ed8-1a00-0000-1cb9-53d478140000 pid=5240->b95ce511-3591-5114-995b-9ce77bb440cb send: 142B guuid=cfab06f6-1a00-0000-1cb9-53d47b140000 pid=5243->b95ce511-3591-5114-995b-9ce77bb440cb send: 138B guuid=e55fc640-1b00-0000-1cb9-53d47f140000 pid=5247->b95ce511-3591-5114-995b-9ce77bb440cb send: 138B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=9593c77a-1b00-0000-1cb9-53d488140000 pid=5256->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=31b3f37a-1b00-0000-1cb9-53d489140000 pid=5257 /home/sandbox/main.x86 dns net send-data zombie guuid=9593c77a-1b00-0000-1cb9-53d488140000 pid=5256->guuid=31b3f37a-1b00-0000-1cb9-53d489140000 pid=5257 clone guuid=31b3f37a-1b00-0000-1cb9-53d489140000 pid=5257->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 31B 4f7cf0da-6077-50c4-b1a9-9d96a771ca82 voucher.io.vn:1995 guuid=31b3f37a-1b00-0000-1cb9-53d489140000 pid=5257->4f7cf0da-6077-50c4-b1a9-9d96a771ca82 send: 14B guuid=5400167b-1b00-0000-1cb9-53d48b140000 pid=5259 /home/sandbox/main.x86 guuid=31b3f37a-1b00-0000-1cb9-53d489140000 pid=5257->guuid=5400167b-1b00-0000-1cb9-53d48b140000 pid=5259 clone guuid=4fcffb95-2500-0000-1cb9-53d4b3140000 pid=5299 /home/sandbox/main.x86 net guuid=31b3f37a-1b00-0000-1cb9-53d489140000 pid=5257->guuid=4fcffb95-2500-0000-1cb9-53d4b3140000 pid=5299 clone b9a7a8d8-6d90-5690-84ac-a4b8984305ee voucher.io.vn:80 guuid=4a8efb7a-1b00-0000-1cb9-53d48a140000 pid=5258->b9a7a8d8-6d90-5690-84ac-a4b8984305ee send: 141B guuid=32982fc5-1b00-0000-1cb9-53d48d140000 pid=5261->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=59cf7bc6-1b00-0000-1cb9-53d48e140000 pid=5262 /home/sandbox/main.x86_64 dns net send-data zombie guuid=32982fc5-1b00-0000-1cb9-53d48d140000 pid=5261->guuid=59cf7bc6-1b00-0000-1cb9-53d48e140000 pid=5262 clone guuid=59cf7bc6-1b00-0000-1cb9-53d48e140000 pid=5262->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 31B guuid=59cf7bc6-1b00-0000-1cb9-53d48e140000 pid=5262->4f7cf0da-6077-50c4-b1a9-9d96a771ca82 send: 14B guuid=30eba9c6-1b00-0000-1cb9-53d490140000 pid=5264 /home/sandbox/main.x86_64 guuid=59cf7bc6-1b00-0000-1cb9-53d48e140000 pid=5262->guuid=30eba9c6-1b00-0000-1cb9-53d490140000 pid=5264 clone guuid=59d7e795-2500-0000-1cb9-53d4b1140000 pid=5297 /home/sandbox/main.x86_64 net guuid=59cf7bc6-1b00-0000-1cb9-53d48e140000 pid=5262->guuid=59d7e795-2500-0000-1cb9-53d4b1140000 pid=5297 clone 9da64a1c-892f-5d45-a651-d50bf8f52b11 94.156.33.106:10 guuid=59d7e795-2500-0000-1cb9-53d4b1140000 pid=5297->9da64a1c-892f-5d45-a651-d50bf8f52b11 con guuid=a8edf195-2500-0000-1cb9-53d4b2140000 pid=5298 /home/sandbox/main.x86_64 guuid=59d7e795-2500-0000-1cb9-53d4b1140000 pid=5297->guuid=a8edf195-2500-0000-1cb9-53d4b2140000 pid=5298 clone guuid=f7910196-2500-0000-1cb9-53d4b4140000 pid=5300 /home/sandbox/main.x86_64 guuid=59d7e795-2500-0000-1cb9-53d4b1140000 pid=5297->guuid=f7910196-2500-0000-1cb9-53d4b4140000 pid=5300 clone guuid=4fcffb95-2500-0000-1cb9-53d4b3140000 pid=5299->9da64a1c-892f-5d45-a651-d50bf8f52b11 con guuid=24b60996-2500-0000-1cb9-53d4b6140000 pid=5302 /home/sandbox/main.x86 guuid=4fcffb95-2500-0000-1cb9-53d4b3140000 pid=5299->guuid=24b60996-2500-0000-1cb9-53d4b6140000 pid=5302 clone guuid=b3da2196-2500-0000-1cb9-53d4b7140000 pid=5303 /home/sandbox/main.x86 guuid=4fcffb95-2500-0000-1cb9-53d4b3140000 pid=5299->guuid=b3da2196-2500-0000-1cb9-53d4b7140000 pid=5303 clone guuid=3ed40896-2500-0000-1cb9-53d4b5140000 pid=5301 /home/sandbox/main.x86_64 send-data guuid=f7910196-2500-0000-1cb9-53d4b4140000 pid=5300->guuid=3ed40896-2500-0000-1cb9-53d4b5140000 pid=5301 clone guuid=ba463196-2500-0000-1cb9-53d4b8140000 pid=5304 /home/sandbox/main.x86_64 send-data guuid=f7910196-2500-0000-1cb9-53d4b4140000 pid=5300->guuid=ba463196-2500-0000-1cb9-53d4b8140000 pid=5304 clone guuid=3ed40896-2500-0000-1cb9-53d4b5140000 pid=5301->9da64a1c-892f-5d45-a651-d50bf8f52b11 send: 40970B guuid=6fa93a96-2500-0000-1cb9-53d4b9140000 pid=5305 /home/sandbox/main.x86 send-data guuid=b3da2196-2500-0000-1cb9-53d4b7140000 pid=5303->guuid=6fa93a96-2500-0000-1cb9-53d4b9140000 pid=5305 clone guuid=7c036596-2500-0000-1cb9-53d4ba140000 pid=5306 /home/sandbox/main.x86 send-data guuid=b3da2196-2500-0000-1cb9-53d4b7140000 pid=5303->guuid=7c036596-2500-0000-1cb9-53d4ba140000 pid=5306 clone guuid=ba463196-2500-0000-1cb9-53d4b8140000 pid=5304->9da64a1c-892f-5d45-a651-d50bf8f52b11 send: 40970B guuid=6fa93a96-2500-0000-1cb9-53d4b9140000 pid=5305->9da64a1c-892f-5d45-a651-d50bf8f52b11 send: 40970B guuid=7c036596-2500-0000-1cb9-53d4ba140000 pid=5306->9da64a1c-892f-5d45-a651-d50bf8f52b11 send: 40970B
Threat name:
Document-HTML.Downloader.Heuristic
Status:
Malicious
First seen:
2025-06-21 17:37:06 UTC
File Type:
Text (Shell)
AV detection:
14 of 24 (58.33%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 7f3b5f8d7eb6fba8a1a9ff8c8177f20adff2dab75cca40bf38161f6afd82ef9c

(this sample)

  
Delivery method
Distributed via web download

Comments