MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 aefe19e1e266ac294e84c7d5d05358a0a316deda7c4003ff461565589bbcacbb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 6
| SHA256 hash: | aefe19e1e266ac294e84c7d5d05358a0a316deda7c4003ff461565589bbcacbb |
|---|---|
| SHA3-384 hash: | cd524dd9d2b49868188d26bfe505a196d5e4aacc6d404457b360d665daaa6b52892e37b9b6f737944dbeaa40118af9cb |
| SHA1 hash: | 62d4750f4aeb5dd4aa85e423f7b07201c8ed2253 |
| MD5 hash: | fa6a1ff28f5b02d94d9bf70847b434a5 |
| humanhash: | oven-oklahoma-kilo-hot |
| File name: | wget.sh |
| Download: | download sample |
| File size: | 926 bytes |
| First seen: | 2025-06-23 08:11:03 UTC |
| Last seen: | Never |
| File type: | sh |
| MIME type: | text/plain |
| ssdeep | 24:o6Iu6IU6IRGNINW6InKN6IFo6IE6IGl36I31k6IM6Im6I4:opupUpWpnApFopEpGl3p3CpMpmp4 |
| TLSH | T13411CEFB8419B40249619C3070792C41E05ACAE03794E784F8CFD8B7C5B9A3A2375B89 |
| Magika | shell |
| Reporter | |
| Tags: | sh |
Shell script dropper
This file seems to be a shell script dropper, using wget, ftpget and/or curl. More information about the corresponding payload URLs are shown below.
| URL | Malware sample (SHA256 hash) | Signature | Tags |
|---|---|---|---|
| http://api.trumdvfb.com/skibidi/cutearm | n/a | n/a | n/a |
| http://api.trumdvfb.com/skibidi/cutearm5 | n/a | n/a | n/a |
| http://api.trumdvfb.com/skibidi/cutearm6 | n/a | n/a | n/a |
| http://api.trumdvfb.com/skibidi/cutearm7 | n/a | n/a | n/a |
| http://api.trumdvfb.com/skibidi/cutem68k | n/a | n/a | n/a |
| http://api.trumdvfb.com/skibidi/cutemips | n/a | n/a | n/a |
| http://api.trumdvfb.com/skibidi/cutempsl | n/a | n/a | n/a |
| http://api.trumdvfb.com/skibidi/cutepowerpc | n/a | n/a | botnetdomain elf ua-wget |
| http://api.trumdvfb.com/skibidi/cutesh4 | n/a | n/a | n/a |
| http://api.trumdvfb.com/skibidi/cutex86 | n/a | n/a | n/a |
| http://api.trumdvfb.com/skibidi/cutex86_64 | n/a | n/a | n/a |
Intelligence
File Origin
# of uploads :
1
# of downloads :
81
Origin country :
DEVendor Threat Intelligence
Verdict:
Clean
Score:
99.9%
Link:
Tags:
n/a
Verdict:
Malicious
Threat level:
10/10
Confidence:
100%
Tags:
evasive
Status:
terminated
Behavior Graph:
Score:
100%
Verdict:
Malware
File Type:
SCRIPT
Threat name:
Document-HTML.Trojan.Egairtigado
Status:
Malicious
First seen:
2025-06-23 08:11:33 UTC
File Type:
Text (Shell)
AV detection:
10 of 24 (41.67%)
Threat level:
5/5
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
sh aefe19e1e266ac294e84c7d5d05358a0a316deda7c4003ff461565589bbcacbb
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.