MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 20967c25fb7c96f231f2a0fbd578a0d7f85fa17583e1d667e28e40354e65b7f4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 4
| SHA256 hash: | 20967c25fb7c96f231f2a0fbd578a0d7f85fa17583e1d667e28e40354e65b7f4 |
|---|---|
| SHA3-384 hash: | c59d15ce4c0156f349a1ac38d74cbd0f154f0d7ada31f33a91cc88a8ce713c0a7973a8ebc36540753a4aba6239a891c3 |
| SHA1 hash: | c2b1f39fedc4a4b9b2171f6785df2394a5ddd26c |
| MD5 hash: | 44e2ccef749ae6f7c9943e20253b1157 |
| humanhash: | aspen-fanta-nuts-kilo |
| File name: | dnf_8.sh |
| Download: | download sample |
| File size: | 5'334 bytes |
| First seen: | 2025-09-03 05:06:58 UTC |
| Last seen: | 2025-09-03 18:25:25 UTC |
| File type: | sh |
| MIME type: | text/x-shellscript |
| ssdeep | 96:LfsdV7K8m8XQb8ztEeb4dbdd/6tZpwWzYn42j5Ye/ACgmR:Yd5zWbdd/kLwYYn42j5lL |
| TLSH | T1B3B1D5A1AF60ECBD1B819DA0EB5562D4F420A2C30E1F790434CEE09E1F214F1327EA1A |
| Magika | shell |
| Reporter | |
| Tags: | sh |
Shell script dropper
This file seems to be a shell script dropper, using wget, ftpget and/or curl. More information about the corresponding payload URLs are shown below.
| URL | Malware sample (SHA256 hash) | Signature | Tags |
|---|---|---|---|
| http://115.28.186.246:81/packages/packages/uuid-ossp.sql | n/a | n/a | n/a |
| http://mirrors.aliyun.com/repo/Centos-8.repo | n/a | n/a | n/a |
Intelligence
File Origin
# of uploads :
3
# of downloads :
35
Origin country :
DEVendor Threat Intelligence
Verdict:
Suspicious
Threat level:
5/10
Confidence:
100%
Tags:
bash lolbin threat
Verdict:
Unknown
File Type:
unix shell
First seen:
2025-09-03T02:27:00Z UTC
Last seen:
2025-09-03T02:27:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
Score:
3%
Verdict:
Benign
File Type:
SCRIPT
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2025-09-03 05:07:32 UTC
File Type:
Text (Shell)
AV detection:
5 of 24 (20.83%)
Threat level:
5/5
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
3/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
sh 20967c25fb7c96f231f2a0fbd578a0d7f85fa17583e1d667e28e40354e65b7f4
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.