MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 78d890fe84aa329b7622f06e998f107cc8bf7d4dba42473faa1a2a07b6abfd61. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 78d890fe84aa329b7622f06e998f107cc8bf7d4dba42473faa1a2a07b6abfd61
SHA3-384 hash: 106c5eb7c8f4f246ddc926f57e35bf4ca482e6a0e42feee43b0984c79de7da294aa4675eccb85788879358de07f90446
SHA1 hash: 48f517b9325537e1b5214ab4d4ed4d272c6dd722
MD5 hash: 0b4707b63d24de9e142a135dbc54b136
humanhash: floor-pizza-sink-burger
File name:download-55_new.sh
Download: download sample
File size:2'991 bytes
First seen:2025-09-03 05:06:59 UTC
Last seen:2025-09-03 13:26:21 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:S/0LFARLRgZWpVUHUM9npUG8gaIjIko0CWpuwKj7QjE5pTEEXMzU8yJLxLevI+bj:SMxCL+7B9npfv/oHMfI13gSo
TLSH T12E51984E916137D24F30AF9C727A4C44801C96543CEF2D89FB6D9AEF1A1298770A7D0B
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://ttfcrm.top:81/packages/packages/erlang-17.5-Centos7.x_Linux-x86_64.tar.gzn/an/an/a
http://ttfcrm.top:81/packages/packages/erlang-22.tar.gzn/an/an/a
http://ttfcrm.top:81/packages/packages/rabbitmq-server-3.6.1-1.noarch.rpmn/an/an/a
http://ttfcrm.top:81/packages/packages/rabbitmq-server-3.8.5-1.el7.noarch.rpmn/an/an/a
http://ttfcrm.top:81/packages/packages/test.keystoren/an/an/a
http://ttfcrm.top:81/packages/packages/apache-tomcat-8.5.53.tar.gzn/an/an/a
http://ttfcrm.top:81/packages/packages/freeswitch.servicen/an/an/a
http://ttfcrm.top:81/packages/packages/mysql-connector-java-8.0.18.jarn/an/an/a
http://ttfcrm.top:81/packages/ippbx_new/ocean.sqln/an/an/a
http://ttfcrm.top:81/packages/ippbx_new/ocean.tar.gzn/an/an/a
http://ttfcrm.top:81/packages/ippbx_new/freeswitch_8.tar.gzn/an/an/a
http://ttfcrm.top:81/packages/ippbx_new/freeswitch_7.tar.gzn/an/an/a
http://ttfcrm.top:81/packages/ippbx_new/ippbx.tar.gzn/an/an/a
http://ttfcrm.top:81/packages/ippbx_new/callcenter.sqln/an/an/a
http://ttfcrm.top:81/packages/ippbx_new/ROOT.tar.gzn/an/an/a
http://ttfcrm.top:81/packages/ippbx_new/springboot-quartz.tar.gzn/an/an/a
http://ttfcrm.top:81/packages/ippbx/nginx.tar.gzn/an/an/a
http://ttfcrm.top:81/packages/ippbx/run/ChkGatewayLimit.shn/an/an/a
http://ttfcrm.top:81/packages/ippbx/run/updateGateWayLimit.shn/an/an/a
http://ttfcrm.top:81/packages/ippbx_new/run/chkpbx1.shn/an/an/a
http://ttfcrm.top:81/packages/ippbx/run/PBX1.shn/an/an/a
http://ttfcrm.top:81/packages/ippbx_new/run/chkpbx.shn/an/an/a
http://ttfcrm.top:81/packages/ippbx/run/PBX.shn/an/an/a
http://ttfcrm.top:81/packages/ippbx_new/run/DataSourceBak.shn/an/an/a
http://ttfcrm.top:81/packages/ippbx/run/usernum.shn/an/an/a
http://ttfcrm.top:81/packages/ippbx_new/run/chspring.shn/an/an/a
http://ttfcrm.top:81/packages/ippbx/run/chkcrm.shn/an/an/a
http://ttfcrm.top:81/packages/ippbx/run/CRM.shn/an/an/a
http://ttfcrm.top:81/packages/ippbx_new/run/update_oceanurl.shn/an/an/a
http://ttfcrm.top:81/packages/packages/kaer.zipn/an/an/a
http://ttfcrm.top:81/packages/ippbx_new/update_ippbx.txtn/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
37
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Unknown
File Type:
unix shell
First seen:
2025-09-03T02:27:00Z UTC
Last seen:
2025-09-03T02:27:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=4880765a-1a00-0000-06af-13e24c090000 pid=2380 /usr/bin/sudo guuid=774f555d-1a00-0000-06af-13e254090000 pid=2388 /tmp/sample.bin guuid=4880765a-1a00-0000-06af-13e24c090000 pid=2380->guuid=774f555d-1a00-0000-06af-13e254090000 pid=2388 execve guuid=89e2d05d-1a00-0000-06af-13e255090000 pid=2389 /usr/bin/bash guuid=774f555d-1a00-0000-06af-13e254090000 pid=2388->guuid=89e2d05d-1a00-0000-06af-13e255090000 pid=2389 clone guuid=6e24195e-1a00-0000-06af-13e256090000 pid=2390 /usr/bin/cat guuid=89e2d05d-1a00-0000-06af-13e255090000 pid=2389->guuid=6e24195e-1a00-0000-06af-13e256090000 pid=2390 execve guuid=6ef83b5e-1a00-0000-06af-13e257090000 pid=2391 /usr/bin/cut guuid=89e2d05d-1a00-0000-06af-13e255090000 pid=2389->guuid=6ef83b5e-1a00-0000-06af-13e257090000 pid=2391 execve guuid=fd2a7e5e-1a00-0000-06af-13e258090000 pid=2392 /usr/bin/cut guuid=89e2d05d-1a00-0000-06af-13e255090000 pid=2389->guuid=fd2a7e5e-1a00-0000-06af-13e258090000 pid=2392 execve
Threat name:
Script.Trojan.Multiverze
Status:
Malicious
First seen:
2025-09-03 05:08:25 UTC
File Type:
Text (Shell)
AV detection:
5 of 24 (20.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 78d890fe84aa329b7622f06e998f107cc8bf7d4dba42473faa1a2a07b6abfd61

(this sample)

  
Delivery method
Distributed via web download

Comments