MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 78d890fe84aa329b7622f06e998f107cc8bf7d4dba42473faa1a2a07b6abfd61. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 3
| SHA256 hash: | 78d890fe84aa329b7622f06e998f107cc8bf7d4dba42473faa1a2a07b6abfd61 |
|---|---|
| SHA3-384 hash: | 106c5eb7c8f4f246ddc926f57e35bf4ca482e6a0e42feee43b0984c79de7da294aa4675eccb85788879358de07f90446 |
| SHA1 hash: | 48f517b9325537e1b5214ab4d4ed4d272c6dd722 |
| MD5 hash: | 0b4707b63d24de9e142a135dbc54b136 |
| humanhash: | floor-pizza-sink-burger |
| File name: | download-55_new.sh |
| Download: | download sample |
| File size: | 2'991 bytes |
| First seen: | 2025-09-03 05:06:59 UTC |
| Last seen: | 2025-09-03 13:26:21 UTC |
| File type: | sh |
| MIME type: | text/x-shellscript |
| ssdeep | 24:S/0LFARLRgZWpVUHUM9npUG8gaIjIko0CWpuwKj7QjE5pTEEXMzU8yJLxLevI+bj:SMxCL+7B9npfv/oHMfI13gSo |
| TLSH | T12E51984E916137D24F30AF9C727A4C44801C96543CEF2D89FB6D9AEF1A1298770A7D0B |
| Magika | shell |
| Reporter | |
| Tags: | sh |
Shell script dropper
This file seems to be a shell script dropper, using wget, ftpget and/or curl. More information about the corresponding payload URLs are shown below.
| URL | Malware sample (SHA256 hash) | Signature | Tags |
|---|---|---|---|
| http://ttfcrm.top:81/packages/packages/erlang-17.5-Centos7.x_Linux-x86_64.tar.gz | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/packages/erlang-22.tar.gz | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/packages/rabbitmq-server-3.6.1-1.noarch.rpm | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/packages/rabbitmq-server-3.8.5-1.el7.noarch.rpm | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/packages/test.keystore | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/packages/apache-tomcat-8.5.53.tar.gz | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/packages/freeswitch.service | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/packages/mysql-connector-java-8.0.18.jar | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/ippbx_new/ocean.sql | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/ippbx_new/ocean.tar.gz | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/ippbx_new/freeswitch_8.tar.gz | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/ippbx_new/freeswitch_7.tar.gz | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/ippbx_new/ippbx.tar.gz | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/ippbx_new/callcenter.sql | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/ippbx_new/ROOT.tar.gz | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/ippbx_new/springboot-quartz.tar.gz | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/ippbx/nginx.tar.gz | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/ippbx/run/ChkGatewayLimit.sh | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/ippbx/run/updateGateWayLimit.sh | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/ippbx_new/run/chkpbx1.sh | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/ippbx/run/PBX1.sh | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/ippbx_new/run/chkpbx.sh | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/ippbx/run/PBX.sh | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/ippbx_new/run/DataSourceBak.sh | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/ippbx/run/usernum.sh | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/ippbx_new/run/chspring.sh | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/ippbx/run/chkcrm.sh | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/ippbx/run/CRM.sh | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/ippbx_new/run/update_oceanurl.sh | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/packages/kaer.zip | n/a | n/a | n/a |
| http://ttfcrm.top:81/packages/ippbx_new/update_ippbx.txt | n/a | n/a | n/a |
Intelligence
File Origin
# of uploads :
2
# of downloads :
37
Origin country :
DEVendor Threat Intelligence
Verdict:
Unknown
File Type:
unix shell
First seen:
2025-09-03T02:27:00Z UTC
Last seen:
2025-09-03T02:27:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
Score:
29%
Verdict:
Benign
File Type:
SCRIPT
Threat name:
Script.Trojan.Multiverze
Status:
Malicious
First seen:
2025-09-03 05:08:25 UTC
File Type:
Text (Shell)
AV detection:
5 of 24 (20.83%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
sh 78d890fe84aa329b7622f06e998f107cc8bf7d4dba42473faa1a2a07b6abfd61
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.