MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 df2ef99ef65b2b741311c2c50b3c74bfe1093c732b26dbec4ca1e4fd6341c1ff. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 3
| SHA256 hash: | df2ef99ef65b2b741311c2c50b3c74bfe1093c732b26dbec4ca1e4fd6341c1ff |
|---|---|
| SHA3-384 hash: | b99f75fe2be2fde2ae83ea2f312e403d023dfc632dbbe1c24c9b72e76f68a6685c93ab6ad4487d4b8d42502ea8ffb069 |
| SHA1 hash: | b271699f36eba4f7271b372be182ae03d29e0388 |
| MD5 hash: | 80af7f268846e5620c85453fc535fb3b |
| humanhash: | indigo-wolfram-nitrogen-uranus |
| File name: | installcallcenter_centos7_4.2_http.sh |
| Download: | download sample |
| File size: | 20'230 bytes |
| First seen: | 2025-09-03 05:07:02 UTC |
| Last seen: | Never |
| File type: | sh |
| MIME type: | text/x-shellscript |
| ssdeep | 384:KDPZK/j6Mgm33XXxxuu5v5Db9R5qDR0/bjrZJxiBw51yP6SBwUby8GQx8b:ePZGj6MP3hNv539R5eR0/frZJxgw5GNM |
| TLSH | T1B792E8993A7A99B66F45A9B0D36D0055306870873F07AC08F9CF847E6F164AC3BBC45B |
| Magika | shell |
| Reporter | |
| Tags: | sh |
Shell script dropper
This file seems to be a shell script dropper, using wget, ftpget and/or curl. More information about the corresponding payload URLs are shown below.
| URL | Malware sample (SHA256 hash) | Signature | Tags |
|---|---|---|---|
| http://115.28.186.246:81/packages/callcenter.sql | n/a | n/a | n/a |
| http://115.28.186.246:81/packages/packages/erlang-17.5-Centos7.x_Linux-x86_64.tar.gz | n/a | n/a | n/a |
| http://115.28.186.246:81/packages/data.tar.gz | n/a | n/a | n/a |
| http://115.28.186.246:81/packages/packages/rabbitmq-server-3.6.1-1.noarch.rpm | n/a | n/a | n/a |
| http://115.28.186.246:81/packages/ocean.tar.gz | n/a | n/a | n/a |
| http://115.28.186.246:81/packages/configs/freeswitch.service | n/a | n/a | n/a |
| http://115.28.186.246:81/packages/freeswitch.tar.gz | n/a | n/a | n/a |
| http://115.28.186.246:81/packages/bea.tar.gz | n/a | n/a | n/a |
| http://115.28.186.246:81/packages/crontab.bak | n/a | n/a | n/a |
| http://115.28.186.246:81/packages/update.txt | n/a | n/a | n/a |
| http://115.28.186.246:81/packages/trcli.tar.gz | n/a | n/a | n/a |
| http://115.28.186.246:81/packages/nginx.tar.gz | n/a | n/a | n/a |
| https://mirrors.aliyun.com/repo/Centos-7.repo | n/a | n/a | n/a |
| http://mirrors.aliyun.com/repo/epel-7.repo | n/a | n/a | n/a |
| http://ttfcrm.top:54354/iptables/newfound.txt | n/a | n/a | n/a |
| http://ttfcrm.top:54354/iptables/banthis.txt | n/a | n/a | n/a |
Intelligence
File Origin
# of uploads :
1
# of downloads :
37
Origin country :
DEVendor Threat Intelligence
Verdict:
Unknown
File Type:
unix shell
First seen:
2025-09-03T02:37:00Z UTC
Last seen:
2025-09-03T02:37:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
Score:
1%
Verdict:
Benign
File Type:
SCRIPT
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2025-09-03 05:10:19 UTC
File Type:
Text (Shell)
AV detection:
4 of 24 (16.67%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
sh df2ef99ef65b2b741311c2c50b3c74bfe1093c732b26dbec4ca1e4fd6341c1ff
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.