MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 df2ef99ef65b2b741311c2c50b3c74bfe1093c732b26dbec4ca1e4fd6341c1ff. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: df2ef99ef65b2b741311c2c50b3c74bfe1093c732b26dbec4ca1e4fd6341c1ff
SHA3-384 hash: b99f75fe2be2fde2ae83ea2f312e403d023dfc632dbbe1c24c9b72e76f68a6685c93ab6ad4487d4b8d42502ea8ffb069
SHA1 hash: b271699f36eba4f7271b372be182ae03d29e0388
MD5 hash: 80af7f268846e5620c85453fc535fb3b
humanhash: indigo-wolfram-nitrogen-uranus
File name:installcallcenter_centos7_4.2_http.sh
Download: download sample
File size:20'230 bytes
First seen:2025-09-03 05:07:02 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:KDPZK/j6Mgm33XXxxuu5v5Db9R5qDR0/bjrZJxiBw51yP6SBwUby8GQx8b:ePZGj6MP3hNv539R5eR0/frZJxgw5GNM
TLSH T1B792E8993A7A99B66F45A9B0D36D0055306870873F07AC08F9CF847E6F164AC3BBC45B
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://115.28.186.246:81/packages/callcenter.sqln/an/an/a
http://115.28.186.246:81/packages/packages/erlang-17.5-Centos7.x_Linux-x86_64.tar.gzn/an/an/a
http://115.28.186.246:81/packages/data.tar.gzn/an/an/a
http://115.28.186.246:81/packages/packages/rabbitmq-server-3.6.1-1.noarch.rpmn/an/an/a
http://115.28.186.246:81/packages/ocean.tar.gzn/an/an/a
http://115.28.186.246:81/packages/configs/freeswitch.servicen/an/an/a
http://115.28.186.246:81/packages/freeswitch.tar.gzn/an/an/a
http://115.28.186.246:81/packages/bea.tar.gzn/an/an/a
http://115.28.186.246:81/packages/crontab.bakn/an/an/a
http://115.28.186.246:81/packages/update.txtn/an/an/a
http://115.28.186.246:81/packages/trcli.tar.gzn/an/an/a
http://115.28.186.246:81/packages/nginx.tar.gzn/an/an/a
https://mirrors.aliyun.com/repo/Centos-7.repon/an/an/a
http://mirrors.aliyun.com/repo/epel-7.repon/an/an/a
http://ttfcrm.top:54354/iptables/newfound.txtn/an/an/a
http://ttfcrm.top:54354/iptables/banthis.txtn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
37
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Unknown
File Type:
unix shell
First seen:
2025-09-03T02:37:00Z UTC
Last seen:
2025-09-03T02:37:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=d9dd3a02-1800-0000-94d0-a860f30b0000 pid=3059 /usr/bin/sudo guuid=80ce0804-1800-0000-94d0-a860f70b0000 pid=3063 /tmp/sample.bin guuid=d9dd3a02-1800-0000-94d0-a860f30b0000 pid=3059->guuid=80ce0804-1800-0000-94d0-a860f70b0000 pid=3063 execve
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2025-09-03 05:10:19 UTC
File Type:
Text (Shell)
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh df2ef99ef65b2b741311c2c50b3c74bfe1093c732b26dbec4ca1e4fd6341c1ff

(this sample)

  
Delivery method
Distributed via web download

Comments