MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aefe19e1e266ac294e84c7d5d05358a0a316deda7c4003ff461565589bbcacbb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: aefe19e1e266ac294e84c7d5d05358a0a316deda7c4003ff461565589bbcacbb
SHA3-384 hash: cd524dd9d2b49868188d26bfe505a196d5e4aacc6d404457b360d665daaa6b52892e37b9b6f737944dbeaa40118af9cb
SHA1 hash: 62d4750f4aeb5dd4aa85e423f7b07201c8ed2253
MD5 hash: fa6a1ff28f5b02d94d9bf70847b434a5
humanhash: oven-oklahoma-kilo-hot
File name:wget.sh
Download: download sample
File size:926 bytes
First seen:2025-06-23 08:11:03 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:o6Iu6IU6IRGNINW6InKN6IFo6IE6IGl36I31k6IM6Im6I4:opupUpWpnApFopEpGl3p3CpMpmp4
TLSH T13411CEFB8419B40249619C3070792C41E05ACAE03794E784F8CFD8B7C5B9A3A2375B89
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://api.trumdvfb.com/skibidi/cutearmn/an/an/a
http://api.trumdvfb.com/skibidi/cutearm5n/an/an/a
http://api.trumdvfb.com/skibidi/cutearm6n/an/an/a
http://api.trumdvfb.com/skibidi/cutearm7n/an/an/a
http://api.trumdvfb.com/skibidi/cutem68kn/an/an/a
http://api.trumdvfb.com/skibidi/cutemipsn/an/an/a
http://api.trumdvfb.com/skibidi/cutempsln/an/an/a
http://api.trumdvfb.com/skibidi/cutepowerpcn/an/abotnetdomain elf ua-wget
http://api.trumdvfb.com/skibidi/cutesh4n/an/an/a
http://api.trumdvfb.com/skibidi/cutex86n/an/an/a
http://api.trumdvfb.com/skibidi/cutex86_64n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Status:
terminated
Behavior Graph:
%3 guuid=799af001-1900-0000-2723-1ee58d130000 pid=5005 /usr/bin/sudo guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014 /tmp/sample.bin guuid=799af001-1900-0000-2723-1ee58d130000 pid=5005->guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014 execve guuid=bb94e503-1900-0000-2723-1ee598130000 pid=5016 /usr/bin/wget dns net send-data write-file guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=bb94e503-1900-0000-2723-1ee598130000 pid=5016 execve guuid=e0ba3140-1900-0000-2723-1ee52b140000 pid=5163 /usr/bin/chmod guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=e0ba3140-1900-0000-2723-1ee52b140000 pid=5163 execve guuid=15209340-1900-0000-2723-1ee52e140000 pid=5166 /usr/bin/dash guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=15209340-1900-0000-2723-1ee52e140000 pid=5166 clone guuid=51634741-1900-0000-2723-1ee532140000 pid=5170 /usr/bin/wget dns net send-data write-file guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=51634741-1900-0000-2723-1ee532140000 pid=5170 execve guuid=9fdff47c-1900-0000-2723-1ee55b140000 pid=5211 /usr/bin/chmod guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=9fdff47c-1900-0000-2723-1ee55b140000 pid=5211 execve guuid=924e747d-1900-0000-2723-1ee55c140000 pid=5212 /usr/bin/dash guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=924e747d-1900-0000-2723-1ee55c140000 pid=5212 clone guuid=77248e7e-1900-0000-2723-1ee55e140000 pid=5214 /usr/bin/wget dns net send-data guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=77248e7e-1900-0000-2723-1ee55e140000 pid=5214 execve guuid=f6df8a9e-1900-0000-2723-1ee567140000 pid=5223 /usr/bin/chmod guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=f6df8a9e-1900-0000-2723-1ee567140000 pid=5223 execve guuid=cc2f329f-1900-0000-2723-1ee568140000 pid=5224 /usr/bin/dash guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=cc2f329f-1900-0000-2723-1ee568140000 pid=5224 clone guuid=cdc0509f-1900-0000-2723-1ee569140000 pid=5225 /usr/bin/wget dns net send-data write-file guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=cdc0509f-1900-0000-2723-1ee569140000 pid=5225 execve guuid=318974da-1900-0000-2723-1ee56a140000 pid=5226 /usr/bin/chmod guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=318974da-1900-0000-2723-1ee56a140000 pid=5226 execve guuid=dfa615db-1900-0000-2723-1ee56b140000 pid=5227 /usr/bin/dash guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=dfa615db-1900-0000-2723-1ee56b140000 pid=5227 clone guuid=67f17cdc-1900-0000-2723-1ee56d140000 pid=5229 /usr/bin/wget dns net send-data write-file guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=67f17cdc-1900-0000-2723-1ee56d140000 pid=5229 execve guuid=30ae541b-1a00-0000-2723-1ee56e140000 pid=5230 /usr/bin/chmod guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=30ae541b-1a00-0000-2723-1ee56e140000 pid=5230 execve guuid=f843ff1b-1a00-0000-2723-1ee56f140000 pid=5231 /usr/bin/dash guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=f843ff1b-1a00-0000-2723-1ee56f140000 pid=5231 clone guuid=9783601d-1a00-0000-2723-1ee571140000 pid=5233 /usr/bin/wget dns net send-data write-file guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=9783601d-1a00-0000-2723-1ee571140000 pid=5233 execve guuid=7cedbf57-1a00-0000-2723-1ee579140000 pid=5241 /usr/bin/chmod guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=7cedbf57-1a00-0000-2723-1ee579140000 pid=5241 execve guuid=5a182058-1a00-0000-2723-1ee57a140000 pid=5242 /usr/bin/dash guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=5a182058-1a00-0000-2723-1ee57a140000 pid=5242 clone guuid=2fe91c5c-1a00-0000-2723-1ee57c140000 pid=5244 /usr/bin/wget dns net send-data write-file guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=2fe91c5c-1a00-0000-2723-1ee57c140000 pid=5244 execve guuid=a39a49a2-1a00-0000-2723-1ee57d140000 pid=5245 /usr/bin/chmod guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=a39a49a2-1a00-0000-2723-1ee57d140000 pid=5245 execve guuid=fa55f2a2-1a00-0000-2723-1ee57e140000 pid=5246 /usr/bin/dash guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=fa55f2a2-1a00-0000-2723-1ee57e140000 pid=5246 clone guuid=602a60a5-1a00-0000-2723-1ee580140000 pid=5248 /usr/bin/wget dns net send-data write-file guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=602a60a5-1a00-0000-2723-1ee580140000 pid=5248 execve guuid=4d9a81d3-1a00-0000-2723-1ee581140000 pid=5249 /usr/bin/chmod guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=4d9a81d3-1a00-0000-2723-1ee581140000 pid=5249 execve guuid=f9db60d4-1a00-0000-2723-1ee582140000 pid=5250 /usr/bin/dash guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=f9db60d4-1a00-0000-2723-1ee582140000 pid=5250 clone guuid=11e33cd6-1a00-0000-2723-1ee584140000 pid=5252 /usr/bin/wget dns net send-data write-file guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=11e33cd6-1a00-0000-2723-1ee584140000 pid=5252 execve guuid=5fce9702-1b00-0000-2723-1ee585140000 pid=5253 /usr/bin/chmod guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=5fce9702-1b00-0000-2723-1ee585140000 pid=5253 execve guuid=8115d102-1b00-0000-2723-1ee586140000 pid=5254 /usr/bin/dash guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=8115d102-1b00-0000-2723-1ee586140000 pid=5254 clone guuid=5b1c5a03-1b00-0000-2723-1ee588140000 pid=5256 /usr/bin/wget dns net send-data write-file guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=5b1c5a03-1b00-0000-2723-1ee588140000 pid=5256 execve guuid=6ece8b2f-1b00-0000-2723-1ee58a140000 pid=5258 /usr/bin/chmod guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=6ece8b2f-1b00-0000-2723-1ee58a140000 pid=5258 execve guuid=f2960130-1b00-0000-2723-1ee58b140000 pid=5259 /home/sandbox/cutex86 net guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=f2960130-1b00-0000-2723-1ee58b140000 pid=5259 execve guuid=3ec83e30-1b00-0000-2723-1ee58e140000 pid=5262 /usr/bin/wget dns net send-data write-file guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=3ec83e30-1b00-0000-2723-1ee58e140000 pid=5262 execve guuid=c084665f-1b00-0000-2723-1ee59b140000 pid=5275 /usr/bin/chmod guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=c084665f-1b00-0000-2723-1ee59b140000 pid=5275 execve guuid=e5d9f15f-1b00-0000-2723-1ee59d140000 pid=5277 /home/sandbox/cutex86_64 net guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=e5d9f15f-1b00-0000-2723-1ee59d140000 pid=5277 execve guuid=74642860-1b00-0000-2723-1ee5a0140000 pid=5280 /usr/bin/rm delete-file guuid=f3d1a503-1900-0000-2723-1ee596130000 pid=5014->guuid=74642860-1b00-0000-2723-1ee5a0140000 pid=5280 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=bb94e503-1900-0000-2723-1ee598130000 pid=5016->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B e86f753b-e3e0-5b83-89b3-1a4358cc8e45 api.trumdvfb.com:80 guuid=bb94e503-1900-0000-2723-1ee598130000 pid=5016->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 146B guuid=51634741-1900-0000-2723-1ee532140000 pid=5170->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=51634741-1900-0000-2723-1ee532140000 pid=5170->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 147B guuid=77248e7e-1900-0000-2723-1ee55e140000 pid=5214->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=77248e7e-1900-0000-2723-1ee55e140000 pid=5214->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 147B guuid=cdc0509f-1900-0000-2723-1ee569140000 pid=5225->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=cdc0509f-1900-0000-2723-1ee569140000 pid=5225->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 147B guuid=67f17cdc-1900-0000-2723-1ee56d140000 pid=5229->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=67f17cdc-1900-0000-2723-1ee56d140000 pid=5229->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 147B guuid=9783601d-1a00-0000-2723-1ee571140000 pid=5233->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=9783601d-1a00-0000-2723-1ee571140000 pid=5233->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 147B guuid=2fe91c5c-1a00-0000-2723-1ee57c140000 pid=5244->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=2fe91c5c-1a00-0000-2723-1ee57c140000 pid=5244->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 147B guuid=602a60a5-1a00-0000-2723-1ee580140000 pid=5248->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=602a60a5-1a00-0000-2723-1ee580140000 pid=5248->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 150B guuid=11e33cd6-1a00-0000-2723-1ee584140000 pid=5252->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=11e33cd6-1a00-0000-2723-1ee584140000 pid=5252->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 146B guuid=5b1c5a03-1b00-0000-2723-1ee588140000 pid=5256->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=5b1c5a03-1b00-0000-2723-1ee588140000 pid=5256->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 146B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=f2960130-1b00-0000-2723-1ee58b140000 pid=5259->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3e443230-1b00-0000-2723-1ee58c140000 pid=5260 /home/sandbox/cutex86 guuid=f2960130-1b00-0000-2723-1ee58b140000 pid=5259->guuid=3e443230-1b00-0000-2723-1ee58c140000 pid=5260 clone guuid=aa0f3f30-1b00-0000-2723-1ee58d140000 pid=5261 /home/sandbox/cutex86 net zombie guuid=3e443230-1b00-0000-2723-1ee58c140000 pid=5260->guuid=aa0f3f30-1b00-0000-2723-1ee58d140000 pid=5261 clone guuid=3ec83e30-1b00-0000-2723-1ee58e140000 pid=5262->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=3ec83e30-1b00-0000-2723-1ee58e140000 pid=5262->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 149B 81d3693e-3a89-533c-9814-2f320e0c5d5b api.trumdvfb.com:5683 guuid=aa0f3f30-1b00-0000-2723-1ee58d140000 pid=5261->81d3693e-3a89-533c-9814-2f320e0c5d5b con guuid=e5d9f15f-1b00-0000-2723-1ee59d140000 pid=5277->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=50021060-1b00-0000-2723-1ee59e140000 pid=5278 /home/sandbox/cutex86_64 zombie guuid=e5d9f15f-1b00-0000-2723-1ee59d140000 pid=5277->guuid=50021060-1b00-0000-2723-1ee59e140000 pid=5278 clone guuid=6d761e60-1b00-0000-2723-1ee59f140000 pid=5279 /home/sandbox/cutex86_64 net zombie guuid=50021060-1b00-0000-2723-1ee59e140000 pid=5278->guuid=6d761e60-1b00-0000-2723-1ee59f140000 pid=5279 clone guuid=6d761e60-1b00-0000-2723-1ee59f140000 pid=5279->81d3693e-3a89-533c-9814-2f320e0c5d5b con
Threat name:
Document-HTML.Trojan.Egairtigado
Status:
Malicious
First seen:
2025-06-23 08:11:33 UTC
File Type:
Text (Shell)
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh aefe19e1e266ac294e84c7d5d05358a0a316deda7c4003ff461565589bbcacbb

(this sample)

  
Delivery method
Distributed via web download

Comments