MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e50e554554633f74465b089271f9a818f53fcd8e66146fb8f556b34cedae7147. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: e50e554554633f74465b089271f9a818f53fcd8e66146fb8f556b34cedae7147
SHA3-384 hash: e76a62492557ee38bfe4b08f5ff12ed9a2be62fa9cdec90875610a0436673e20fe656554e5ea296ee324fb3e852a67b6
SHA1 hash: 2e24beee3c1959e3fb4851daa1cc152674313c8d
MD5 hash: 36f7dd146191c3f2f76d1a42343eeacb
humanhash: may-salami-connecticut-cold
File name:curl.sh
Download: download sample
File size:926 bytes
First seen:2025-06-24 22:28:33 UTC
Last seen:2025-06-25 11:44:39 UTC
File type: sh
MIME type:text/plain
ssdeep 24:3J3h6IEU6I36IRGNINJ6InKu6IFL6In6IGC6I31H6If6IZ6I4:Lpxp3pJpnTpFLpnpGCp31pfpZp4
TLSH T1C311E0FD8499B4036661AC30F039A849E01AC9E03694D780F0EFD8B7C1BD63A1374399
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://api.trumdvfb.com/skibidi/cutearmn/an/an/a
http://api.trumdvfb.com/skibidi/cutearm5n/an/an/a
http://api.trumdvfb.com/skibidi/cutearm6n/an/an/a
http://api.trumdvfb.com/skibidi/cutearm7n/an/an/a
http://api.trumdvfb.com/skibidi/cutem68kn/an/an/a
http://api.trumdvfb.com/skibidi/cutemipsn/an/an/a
http://api.trumdvfb.com/skibidi/cutempsln/an/an/a
http://api.trumdvfb.com/skibidi/cutepowerpcn/an/abotnetdomain elf ua-wget
http://api.trumdvfb.com/skibidi/cutesh4n/an/an/a
http://api.trumdvfb.com/skibidi/cutex86n/an/an/a
http://api.trumdvfb.com/skibidi/cutex86_64n/an/an/a

Intelligence


File Origin
# of uploads :
4
# of downloads :
99
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Status:
terminated
Behavior Graph:
%3 guuid=48ce0e2d-1900-0000-7ed5-a1d2d3070000 pid=2003 /usr/bin/sudo guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010 /tmp/sample.bin guuid=48ce0e2d-1900-0000-7ed5-a1d2d3070000 pid=2003->guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010 execve guuid=24f7cf2f-1900-0000-7ed5-a1d2db070000 pid=2011 /usr/bin/curl net send-data guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=24f7cf2f-1900-0000-7ed5-a1d2db070000 pid=2011 execve guuid=c8d7987b-1900-0000-7ed5-a1d27d080000 pid=2173 /usr/bin/chmod guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=c8d7987b-1900-0000-7ed5-a1d27d080000 pid=2173 execve guuid=bd52eb7b-1900-0000-7ed5-a1d27f080000 pid=2175 /usr/bin/dash guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=bd52eb7b-1900-0000-7ed5-a1d27f080000 pid=2175 clone guuid=cce9fe7b-1900-0000-7ed5-a1d280080000 pid=2176 /usr/bin/curl net send-data guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=cce9fe7b-1900-0000-7ed5-a1d280080000 pid=2176 execve guuid=e4af13c7-1900-0000-7ed5-a1d22e090000 pid=2350 /usr/bin/chmod guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=e4af13c7-1900-0000-7ed5-a1d22e090000 pid=2350 execve guuid=2d354fc7-1900-0000-7ed5-a1d22f090000 pid=2351 /usr/bin/dash guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=2d354fc7-1900-0000-7ed5-a1d22f090000 pid=2351 clone guuid=d56a56c7-1900-0000-7ed5-a1d230090000 pid=2352 /usr/bin/curl net send-data guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=d56a56c7-1900-0000-7ed5-a1d230090000 pid=2352 execve guuid=df64910e-1a00-0000-7ed5-a1d2b9090000 pid=2489 /usr/bin/chmod guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=df64910e-1a00-0000-7ed5-a1d2b9090000 pid=2489 execve guuid=059ffe0e-1a00-0000-7ed5-a1d2ba090000 pid=2490 /usr/bin/dash guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=059ffe0e-1a00-0000-7ed5-a1d2ba090000 pid=2490 clone guuid=61690a0f-1a00-0000-7ed5-a1d2bc090000 pid=2492 /usr/bin/curl net send-data guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=61690a0f-1a00-0000-7ed5-a1d2bc090000 pid=2492 execve guuid=6d22e055-1a00-0000-7ed5-a1d2780a0000 pid=2680 /usr/bin/chmod guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=6d22e055-1a00-0000-7ed5-a1d2780a0000 pid=2680 execve guuid=79875956-1a00-0000-7ed5-a1d27a0a0000 pid=2682 /usr/bin/dash guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=79875956-1a00-0000-7ed5-a1d27a0a0000 pid=2682 clone guuid=03f46a56-1a00-0000-7ed5-a1d27b0a0000 pid=2683 /usr/bin/curl net send-data guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=03f46a56-1a00-0000-7ed5-a1d27b0a0000 pid=2683 execve guuid=f6740c9f-1a00-0000-7ed5-a1d20b0b0000 pid=2827 /usr/bin/chmod guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=f6740c9f-1a00-0000-7ed5-a1d20b0b0000 pid=2827 execve guuid=b5275c9f-1a00-0000-7ed5-a1d20d0b0000 pid=2829 /usr/bin/dash guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=b5275c9f-1a00-0000-7ed5-a1d20d0b0000 pid=2829 clone guuid=be25639f-1a00-0000-7ed5-a1d20e0b0000 pid=2830 /usr/bin/curl net send-data guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=be25639f-1a00-0000-7ed5-a1d20e0b0000 pid=2830 execve guuid=16138fe8-1a00-0000-7ed5-a1d29d0b0000 pid=2973 /usr/bin/chmod guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=16138fe8-1a00-0000-7ed5-a1d29d0b0000 pid=2973 execve guuid=734beee8-1a00-0000-7ed5-a1d29e0b0000 pid=2974 /usr/bin/dash guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=734beee8-1a00-0000-7ed5-a1d29e0b0000 pid=2974 clone guuid=6cfcf9e8-1a00-0000-7ed5-a1d29f0b0000 pid=2975 /usr/bin/curl net send-data guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=6cfcf9e8-1a00-0000-7ed5-a1d29f0b0000 pid=2975 execve guuid=d061b537-1b00-0000-7ed5-a1d21d0c0000 pid=3101 /usr/bin/chmod guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=d061b537-1b00-0000-7ed5-a1d21d0c0000 pid=3101 execve guuid=5ac2ee37-1b00-0000-7ed5-a1d21f0c0000 pid=3103 /usr/bin/dash guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=5ac2ee37-1b00-0000-7ed5-a1d21f0c0000 pid=3103 clone guuid=1359f437-1b00-0000-7ed5-a1d2200c0000 pid=3104 /usr/bin/curl net send-data guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=1359f437-1b00-0000-7ed5-a1d2200c0000 pid=3104 execve guuid=fd28cf56-1b00-0000-7ed5-a1d2640c0000 pid=3172 /usr/bin/chmod guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=fd28cf56-1b00-0000-7ed5-a1d2640c0000 pid=3172 execve guuid=17224d57-1b00-0000-7ed5-a1d2660c0000 pid=3174 /usr/bin/dash guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=17224d57-1b00-0000-7ed5-a1d2660c0000 pid=3174 clone guuid=8b306b57-1b00-0000-7ed5-a1d2670c0000 pid=3175 /usr/bin/curl net send-data guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=8b306b57-1b00-0000-7ed5-a1d2670c0000 pid=3175 execve guuid=1d7290a6-1b00-0000-7ed5-a1d2bf0c0000 pid=3263 /usr/bin/chmod guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=1d7290a6-1b00-0000-7ed5-a1d2bf0c0000 pid=3263 execve guuid=eed30fa7-1b00-0000-7ed5-a1d2c00c0000 pid=3264 /usr/bin/dash guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=eed30fa7-1b00-0000-7ed5-a1d2c00c0000 pid=3264 clone guuid=98001ca7-1b00-0000-7ed5-a1d2c10c0000 pid=3265 /usr/bin/curl net send-data guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=98001ca7-1b00-0000-7ed5-a1d2c10c0000 pid=3265 execve guuid=4a2ff5e4-1b00-0000-7ed5-a1d2260d0000 pid=3366 /usr/bin/chmod guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=4a2ff5e4-1b00-0000-7ed5-a1d2260d0000 pid=3366 execve guuid=5fadade5-1b00-0000-7ed5-a1d2290d0000 pid=3369 /usr/bin/dash guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=5fadade5-1b00-0000-7ed5-a1d2290d0000 pid=3369 clone guuid=3de4dee5-1b00-0000-7ed5-a1d22b0d0000 pid=3371 /usr/bin/curl net send-data guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=3de4dee5-1b00-0000-7ed5-a1d22b0d0000 pid=3371 execve guuid=9a106732-1c00-0000-7ed5-a1d2cc0d0000 pid=3532 /usr/bin/chmod guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=9a106732-1c00-0000-7ed5-a1d2cc0d0000 pid=3532 execve guuid=8ecbd232-1c00-0000-7ed5-a1d2cd0d0000 pid=3533 /usr/bin/dash guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=8ecbd232-1c00-0000-7ed5-a1d2cd0d0000 pid=3533 clone guuid=c920e132-1c00-0000-7ed5-a1d2ce0d0000 pid=3534 /usr/bin/rm delete-file guuid=ea36992f-1900-0000-7ed5-a1d2da070000 pid=2010->guuid=c920e132-1c00-0000-7ed5-a1d2ce0d0000 pid=3534 execve e86f753b-e3e0-5b83-89b3-1a4358cc8e45 api.trumdvfb.com:80 guuid=24f7cf2f-1900-0000-7ed5-a1d2db070000 pid=2011->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 95B guuid=24f7cf2f-1900-0000-7ed5-a1d2db070000 pid=2018 /usr/bin/curl dns net send-data guuid=24f7cf2f-1900-0000-7ed5-a1d2db070000 pid=2011->guuid=24f7cf2f-1900-0000-7ed5-a1d2db070000 pid=2018 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=24f7cf2f-1900-0000-7ed5-a1d2db070000 pid=2018->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=cce9fe7b-1900-0000-7ed5-a1d280080000 pid=2176->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 96B guuid=cce9fe7b-1900-0000-7ed5-a1d280080000 pid=2182 /usr/bin/curl dns net send-data guuid=cce9fe7b-1900-0000-7ed5-a1d280080000 pid=2176->guuid=cce9fe7b-1900-0000-7ed5-a1d280080000 pid=2182 clone guuid=cce9fe7b-1900-0000-7ed5-a1d280080000 pid=2182->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=d56a56c7-1900-0000-7ed5-a1d230090000 pid=2352->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 96B guuid=d56a56c7-1900-0000-7ed5-a1d230090000 pid=2357 /usr/bin/curl dns net send-data guuid=d56a56c7-1900-0000-7ed5-a1d230090000 pid=2352->guuid=d56a56c7-1900-0000-7ed5-a1d230090000 pid=2357 clone guuid=d56a56c7-1900-0000-7ed5-a1d230090000 pid=2357->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=61690a0f-1a00-0000-7ed5-a1d2bc090000 pid=2492->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 96B guuid=61690a0f-1a00-0000-7ed5-a1d2bc090000 pid=2497 /usr/bin/curl dns net send-data guuid=61690a0f-1a00-0000-7ed5-a1d2bc090000 pid=2492->guuid=61690a0f-1a00-0000-7ed5-a1d2bc090000 pid=2497 clone guuid=61690a0f-1a00-0000-7ed5-a1d2bc090000 pid=2497->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=03f46a56-1a00-0000-7ed5-a1d27b0a0000 pid=2683->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 96B guuid=03f46a56-1a00-0000-7ed5-a1d27b0a0000 pid=2690 /usr/bin/curl dns net send-data guuid=03f46a56-1a00-0000-7ed5-a1d27b0a0000 pid=2683->guuid=03f46a56-1a00-0000-7ed5-a1d27b0a0000 pid=2690 clone guuid=03f46a56-1a00-0000-7ed5-a1d27b0a0000 pid=2690->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=be25639f-1a00-0000-7ed5-a1d20e0b0000 pid=2830->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 96B guuid=be25639f-1a00-0000-7ed5-a1d20e0b0000 pid=2837 /usr/bin/curl dns net send-data guuid=be25639f-1a00-0000-7ed5-a1d20e0b0000 pid=2830->guuid=be25639f-1a00-0000-7ed5-a1d20e0b0000 pid=2837 clone guuid=be25639f-1a00-0000-7ed5-a1d20e0b0000 pid=2837->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=6cfcf9e8-1a00-0000-7ed5-a1d29f0b0000 pid=2975->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 96B guuid=6cfcf9e8-1a00-0000-7ed5-a1d29f0b0000 pid=2985 /usr/bin/curl dns net send-data guuid=6cfcf9e8-1a00-0000-7ed5-a1d29f0b0000 pid=2975->guuid=6cfcf9e8-1a00-0000-7ed5-a1d29f0b0000 pid=2985 clone guuid=6cfcf9e8-1a00-0000-7ed5-a1d29f0b0000 pid=2985->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=1359f437-1b00-0000-7ed5-a1d2200c0000 pid=3104->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 99B guuid=1359f437-1b00-0000-7ed5-a1d2200c0000 pid=3109 /usr/bin/curl dns net send-data guuid=1359f437-1b00-0000-7ed5-a1d2200c0000 pid=3104->guuid=1359f437-1b00-0000-7ed5-a1d2200c0000 pid=3109 clone guuid=1359f437-1b00-0000-7ed5-a1d2200c0000 pid=3109->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=8b306b57-1b00-0000-7ed5-a1d2670c0000 pid=3175->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 95B guuid=8b306b57-1b00-0000-7ed5-a1d2670c0000 pid=3184 /usr/bin/curl dns net send-data guuid=8b306b57-1b00-0000-7ed5-a1d2670c0000 pid=3175->guuid=8b306b57-1b00-0000-7ed5-a1d2670c0000 pid=3184 clone guuid=8b306b57-1b00-0000-7ed5-a1d2670c0000 pid=3184->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=98001ca7-1b00-0000-7ed5-a1d2c10c0000 pid=3265->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 95B guuid=98001ca7-1b00-0000-7ed5-a1d2c10c0000 pid=3270 /usr/bin/curl dns net send-data guuid=98001ca7-1b00-0000-7ed5-a1d2c10c0000 pid=3265->guuid=98001ca7-1b00-0000-7ed5-a1d2c10c0000 pid=3270 clone guuid=98001ca7-1b00-0000-7ed5-a1d2c10c0000 pid=3270->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B guuid=3de4dee5-1b00-0000-7ed5-a1d22b0d0000 pid=3371->e86f753b-e3e0-5b83-89b3-1a4358cc8e45 send: 98B guuid=3de4dee5-1b00-0000-7ed5-a1d22b0d0000 pid=3381 /usr/bin/curl dns net send-data guuid=3de4dee5-1b00-0000-7ed5-a1d22b0d0000 pid=3371->guuid=3de4dee5-1b00-0000-7ed5-a1d22b0d0000 pid=3381 clone guuid=3de4dee5-1b00-0000-7ed5-a1d22b0d0000 pid=3381->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B
Threat name:
Document-HTML.Trojan.Heuristic
Status:
Malicious
First seen:
2025-06-24 22:29:45 UTC
File Type:
Text (Shell)
AV detection:
9 of 24 (37.50%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh e50e554554633f74465b089271f9a818f53fcd8e66146fb8f556b34cedae7147

(this sample)

  
Delivery method
Distributed via web download

Comments