MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 20967c25fb7c96f231f2a0fbd578a0d7f85fa17583e1d667e28e40354e65b7f4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 20967c25fb7c96f231f2a0fbd578a0d7f85fa17583e1d667e28e40354e65b7f4
SHA3-384 hash: c59d15ce4c0156f349a1ac38d74cbd0f154f0d7ada31f33a91cc88a8ce713c0a7973a8ebc36540753a4aba6239a891c3
SHA1 hash: c2b1f39fedc4a4b9b2171f6785df2394a5ddd26c
MD5 hash: 44e2ccef749ae6f7c9943e20253b1157
humanhash: aspen-fanta-nuts-kilo
File name:dnf_8.sh
Download: download sample
File size:5'334 bytes
First seen:2025-09-03 05:06:58 UTC
Last seen:2025-09-03 18:25:25 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 96:LfsdV7K8m8XQb8ztEeb4dbdd/6tZpwWzYn42j5Ye/ACgmR:Yd5zWbdd/kLwYYn42j5lL
TLSH T1B3B1D5A1AF60ECBD1B819DA0EB5562D4F420A2C30E1F790434CEE09E1F214F1327EA1A
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://115.28.186.246:81/packages/packages/uuid-ossp.sqln/an/an/a
http://mirrors.aliyun.com/repo/Centos-8.repon/an/an/a

Intelligence


File Origin
# of uploads :
3
# of downloads :
35
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
bash lolbin threat
Verdict:
Unknown
File Type:
unix shell
First seen:
2025-09-03T02:27:00Z UTC
Last seen:
2025-09-03T02:27:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=7f860ffe-1900-0000-09d6-552d02090000 pid=2306 /usr/bin/sudo guuid=b7a2c200-1a00-0000-09d6-552d0b090000 pid=2315 /tmp/sample.bin guuid=7f860ffe-1900-0000-09d6-552d02090000 pid=2306->guuid=b7a2c200-1a00-0000-09d6-552d0b090000 pid=2315 execve guuid=c3cb5501-1a00-0000-09d6-552d0e090000 pid=2318 /usr/bin/bash guuid=b7a2c200-1a00-0000-09d6-552d0b090000 pid=2315->guuid=c3cb5501-1a00-0000-09d6-552d0e090000 pid=2318 clone guuid=fbc6de01-1a00-0000-09d6-552d10090000 pid=2320 /usr/bin/date guuid=b7a2c200-1a00-0000-09d6-552d0b090000 pid=2315->guuid=fbc6de01-1a00-0000-09d6-552d10090000 pid=2320 execve guuid=92753f02-1a00-0000-09d6-552d11090000 pid=2321 /usr/bin/id guuid=b7a2c200-1a00-0000-09d6-552d0b090000 pid=2315->guuid=92753f02-1a00-0000-09d6-552d11090000 pid=2321 execve guuid=f2c78305-1a00-0000-09d6-552d12090000 pid=2322 /usr/bin/bash guuid=b7a2c200-1a00-0000-09d6-552d0b090000 pid=2315->guuid=f2c78305-1a00-0000-09d6-552d12090000 pid=2322 clone guuid=f339a405-1a00-0000-09d6-552d13090000 pid=2323 /usr/bin/bash guuid=b7a2c200-1a00-0000-09d6-552d0b090000 pid=2315->guuid=f339a405-1a00-0000-09d6-552d13090000 pid=2323 clone guuid=7aa46501-1a00-0000-09d6-552d0f090000 pid=2319 /usr/bin/dirname guuid=c3cb5501-1a00-0000-09d6-552d0e090000 pid=2318->guuid=7aa46501-1a00-0000-09d6-552d0f090000 pid=2319 execve guuid=eceaba05-1a00-0000-09d6-552d14090000 pid=2324 /usr/bin/cat guuid=f339a405-1a00-0000-09d6-552d13090000 pid=2323->guuid=eceaba05-1a00-0000-09d6-552d14090000 pid=2324 execve guuid=f18bc505-1a00-0000-09d6-552d16090000 pid=2326 /usr/bin/cut guuid=f339a405-1a00-0000-09d6-552d13090000 pid=2323->guuid=f18bc505-1a00-0000-09d6-552d16090000 pid=2326 execve guuid=82dace05-1a00-0000-09d6-552d17090000 pid=2327 /usr/bin/cut guuid=f339a405-1a00-0000-09d6-552d13090000 pid=2323->guuid=82dace05-1a00-0000-09d6-552d17090000 pid=2327 execve
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2025-09-03 05:07:32 UTC
File Type:
Text (Shell)
AV detection:
5 of 24 (20.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 20967c25fb7c96f231f2a0fbd578a0d7f85fa17583e1d667e28e40354e65b7f4

(this sample)

  
Delivery method
Distributed via web download

Comments