MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0b4c4039cc81d5f78fa7265720c4e6ae370303fb9f5d0cda97c74953576f458d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 0b4c4039cc81d5f78fa7265720c4e6ae370303fb9f5d0cda97c74953576f458d
SHA3-384 hash: 0d34588004ea2f775fe7d4f9b74dc457359aef5752449508f8c73ed0381892ac2b4c39c20c64216084c1601445969f06
SHA1 hash: c9a9d35566f34e2e31f44cb376e035ee85fb57a1
MD5 hash: b09246e2200b94cb3dd82d86389fc4a6
humanhash: fruit-william-table-robert
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-27 03:31:44 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:xn0M3vgRjGlsaq7qzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:xDmjfezsP4cbddr7zsP4cbddrk
TLSH T166925BB916096C79BBC0DE7D8F3C7F0CADE481C02119A3ACBA4F39714A2069DDA0535D
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
57
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-03-27T00:39:00Z UTC
Last seen:
2026-03-27T00:54:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=3ab9f6ab-1600-0000-c8cf-bf86460e0000 pid=3654 /usr/bin/sudo guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656 /tmp/sample.bin guuid=3ab9f6ab-1600-0000-c8cf-bf86460e0000 pid=3654->guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656 execve guuid=1c04a5ae-1600-0000-c8cf-bf86490e0000 pid=3657 /usr/bin/bash guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=1c04a5ae-1600-0000-c8cf-bf86490e0000 pid=3657 clone guuid=6c0dbeae-1600-0000-c8cf-bf864a0e0000 pid=3658 /usr/bin/bash guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=6c0dbeae-1600-0000-c8cf-bf864a0e0000 pid=3658 clone guuid=dc19f3ae-1600-0000-c8cf-bf864b0e0000 pid=3659 /usr/bin/mkdir guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=dc19f3ae-1600-0000-c8cf-bf864b0e0000 pid=3659 execve guuid=8271a7af-1600-0000-c8cf-bf864c0e0000 pid=3660 /usr/bin/mkdir guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=8271a7af-1600-0000-c8cf-bf864c0e0000 pid=3660 execve guuid=859e24b0-1600-0000-c8cf-bf864d0e0000 pid=3661 /usr/bin/mkdir guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=859e24b0-1600-0000-c8cf-bf864d0e0000 pid=3661 execve guuid=d3b2a3b0-1600-0000-c8cf-bf864e0e0000 pid=3662 /usr/bin/mkdir guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=d3b2a3b0-1600-0000-c8cf-bf864e0e0000 pid=3662 execve guuid=4bcb1fb1-1600-0000-c8cf-bf864f0e0000 pid=3663 /usr/bin/mkdir guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=4bcb1fb1-1600-0000-c8cf-bf864f0e0000 pid=3663 execve guuid=58b99bb1-1600-0000-c8cf-bf86500e0000 pid=3664 /usr/bin/mkdir guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=58b99bb1-1600-0000-c8cf-bf86500e0000 pid=3664 execve guuid=bbd511b2-1600-0000-c8cf-bf86510e0000 pid=3665 /usr/bin/mkdir guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=bbd511b2-1600-0000-c8cf-bf86510e0000 pid=3665 execve guuid=436188b2-1600-0000-c8cf-bf86520e0000 pid=3666 /usr/bin/cp guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=436188b2-1600-0000-c8cf-bf86520e0000 pid=3666 execve guuid=4aa814b3-1600-0000-c8cf-bf86530e0000 pid=3667 /usr/bin/cp guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=4aa814b3-1600-0000-c8cf-bf86530e0000 pid=3667 execve guuid=19dc9eb3-1600-0000-c8cf-bf86540e0000 pid=3668 /usr/bin/cp guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=19dc9eb3-1600-0000-c8cf-bf86540e0000 pid=3668 execve guuid=0d972ab4-1600-0000-c8cf-bf86550e0000 pid=3669 /usr/bin/cp guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=0d972ab4-1600-0000-c8cf-bf86550e0000 pid=3669 execve guuid=5defb5b4-1600-0000-c8cf-bf86560e0000 pid=3670 /usr/bin/cp guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=5defb5b4-1600-0000-c8cf-bf86560e0000 pid=3670 execve guuid=fe1f3db5-1600-0000-c8cf-bf86570e0000 pid=3671 /usr/bin/cp guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=fe1f3db5-1600-0000-c8cf-bf86570e0000 pid=3671 execve guuid=1081c2b5-1600-0000-c8cf-bf86580e0000 pid=3672 /usr/bin/cp guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=1081c2b5-1600-0000-c8cf-bf86580e0000 pid=3672 execve guuid=86f049b6-1600-0000-c8cf-bf86590e0000 pid=3673 /usr/bin/cp guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=86f049b6-1600-0000-c8cf-bf86590e0000 pid=3673 execve guuid=da15c8b6-1600-0000-c8cf-bf865a0e0000 pid=3674 /usr/bin/cp guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=da15c8b6-1600-0000-c8cf-bf865a0e0000 pid=3674 execve guuid=4b7a49b7-1600-0000-c8cf-bf865b0e0000 pid=3675 /usr/bin/cp guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=4b7a49b7-1600-0000-c8cf-bf865b0e0000 pid=3675 execve guuid=d6c4e7b7-1600-0000-c8cf-bf865f0e0000 pid=3679 /usr/bin/cp guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=d6c4e7b7-1600-0000-c8cf-bf865f0e0000 pid=3679 execve guuid=2b646fb8-1600-0000-c8cf-bf86630e0000 pid=3683 /usr/bin/cp guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=2b646fb8-1600-0000-c8cf-bf86630e0000 pid=3683 execve guuid=84693fb9-1600-0000-c8cf-bf86650e0000 pid=3685 /usr/bin/cp guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=84693fb9-1600-0000-c8cf-bf86650e0000 pid=3685 execve guuid=1b12b2b9-1600-0000-c8cf-bf86670e0000 pid=3687 /usr/bin/cp guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=1b12b2b9-1600-0000-c8cf-bf86670e0000 pid=3687 execve guuid=05972bba-1600-0000-c8cf-bf866a0e0000 pid=3690 /usr/bin/cp guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=05972bba-1600-0000-c8cf-bf866a0e0000 pid=3690 execve guuid=36578bba-1600-0000-c8cf-bf866c0e0000 pid=3692 /usr/bin/touch guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=36578bba-1600-0000-c8cf-bf866c0e0000 pid=3692 execve guuid=6301e2ba-1600-0000-c8cf-bf866e0e0000 pid=3694 /usr/bin/bash guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=6301e2ba-1600-0000-c8cf-bf866e0e0000 pid=3694 clone guuid=cedbeaba-1600-0000-c8cf-bf866f0e0000 pid=3695 /usr/bin/bash guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=cedbeaba-1600-0000-c8cf-bf866f0e0000 pid=3695 clone guuid=e0251abb-1600-0000-c8cf-bf86700e0000 pid=3696 /usr/bin/bash guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=e0251abb-1600-0000-c8cf-bf86700e0000 pid=3696 clone guuid=015f2cbb-1600-0000-c8cf-bf86710e0000 pid=3697 /usr/bin/base64 write-file guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=015f2cbb-1600-0000-c8cf-bf86710e0000 pid=3697 execve guuid=6d58debb-1600-0000-c8cf-bf86720e0000 pid=3698 /usr/bin/bash guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=6d58debb-1600-0000-c8cf-bf86720e0000 pid=3698 execve guuid=f36659c2-1600-0000-c8cf-bf868e0e0000 pid=3726 /usr/bin/rm delete-file guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=f36659c2-1600-0000-c8cf-bf868e0e0000 pid=3726 execve guuid=4170a1c2-1600-0000-c8cf-bf86910e0000 pid=3729 /usr/bin/bash guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=4170a1c2-1600-0000-c8cf-bf86910e0000 pid=3729 clone guuid=2cc8a8c2-1600-0000-c8cf-bf86920e0000 pid=3730 /usr/bin/bash guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=2cc8a8c2-1600-0000-c8cf-bf86920e0000 pid=3730 clone guuid=e634c9c2-1600-0000-c8cf-bf86930e0000 pid=3731 /usr/bin/bash guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=e634c9c2-1600-0000-c8cf-bf86930e0000 pid=3731 execve guuid=d22d1cc3-1600-0000-c8cf-bf86950e0000 pid=3733 /usr/bin/rm guuid=f73c27ae-1600-0000-c8cf-bf86480e0000 pid=3656->guuid=d22d1cc3-1600-0000-c8cf-bf86950e0000 pid=3733 execve guuid=886e5fbc-1600-0000-c8cf-bf86730e0000 pid=3699 /usr/bin/bash guuid=6d58debb-1600-0000-c8cf-bf86720e0000 pid=3698->guuid=886e5fbc-1600-0000-c8cf-bf86730e0000 pid=3699 clone guuid=0da16fbc-1600-0000-c8cf-bf86740e0000 pid=3700 /usr/bin/bash guuid=6d58debb-1600-0000-c8cf-bf86720e0000 pid=3698->guuid=0da16fbc-1600-0000-c8cf-bf86740e0000 pid=3700 clone guuid=33e4acbc-1600-0000-c8cf-bf86750e0000 pid=3701 /usr/bin/ls guuid=6d58debb-1600-0000-c8cf-bf86720e0000 pid=3698->guuid=33e4acbc-1600-0000-c8cf-bf86750e0000 pid=3701 execve guuid=1330a4bd-1600-0000-c8cf-bf86760e0000 pid=3702 /usr/bin/cat guuid=6d58debb-1600-0000-c8cf-bf86720e0000 pid=3698->guuid=1330a4bd-1600-0000-c8cf-bf86760e0000 pid=3702 execve guuid=92d708be-1600-0000-c8cf-bf86770e0000 pid=3703 /usr/bin/ls guuid=6d58debb-1600-0000-c8cf-bf86720e0000 pid=3698->guuid=92d708be-1600-0000-c8cf-bf86770e0000 pid=3703 execve guuid=5e4703bf-1600-0000-c8cf-bf86780e0000 pid=3704 /usr/bin/mkdir guuid=6d58debb-1600-0000-c8cf-bf86720e0000 pid=3698->guuid=5e4703bf-1600-0000-c8cf-bf86780e0000 pid=3704 execve guuid=d99c79bf-1600-0000-c8cf-bf86790e0000 pid=3705 /usr/bin/mv guuid=6d58debb-1600-0000-c8cf-bf86720e0000 pid=3698->guuid=d99c79bf-1600-0000-c8cf-bf86790e0000 pid=3705 execve guuid=2574e0bf-1600-0000-c8cf-bf867c0e0000 pid=3708 /usr/bin/bash guuid=6d58debb-1600-0000-c8cf-bf86720e0000 pid=3698->guuid=2574e0bf-1600-0000-c8cf-bf867c0e0000 pid=3708 clone guuid=13d3e7bf-1600-0000-c8cf-bf867d0e0000 pid=3709 /usr/bin/base64 write-file guuid=6d58debb-1600-0000-c8cf-bf86720e0000 pid=3698->guuid=13d3e7bf-1600-0000-c8cf-bf867d0e0000 pid=3709 execve guuid=962137c0-1600-0000-c8cf-bf867f0e0000 pid=3711 /usr/bin/rm delete-file guuid=6d58debb-1600-0000-c8cf-bf86720e0000 pid=3698->guuid=962137c0-1600-0000-c8cf-bf867f0e0000 pid=3711 execve guuid=50d185c0-1600-0000-c8cf-bf86800e0000 pid=3712 /usr/bin/ls guuid=6d58debb-1600-0000-c8cf-bf86720e0000 pid=3698->guuid=50d185c0-1600-0000-c8cf-bf86800e0000 pid=3712 execve guuid=8825edc0-1600-0000-c8cf-bf86840e0000 pid=3716 /usr/bin/bash guuid=6d58debb-1600-0000-c8cf-bf86720e0000 pid=3698->guuid=8825edc0-1600-0000-c8cf-bf86840e0000 pid=3716 clone guuid=6afdf2c0-1600-0000-c8cf-bf86850e0000 pid=3717 /usr/bin/base64 write-file guuid=6d58debb-1600-0000-c8cf-bf86720e0000 pid=3698->guuid=6afdf2c0-1600-0000-c8cf-bf86850e0000 pid=3717 execve guuid=4a583ec1-1600-0000-c8cf-bf86870e0000 pid=3719 /usr/bin/ls guuid=6d58debb-1600-0000-c8cf-bf86720e0000 pid=3698->guuid=4a583ec1-1600-0000-c8cf-bf86870e0000 pid=3719 execve guuid=8251a2c1-1600-0000-c8cf-bf868a0e0000 pid=3722 /usr/bin/cat guuid=6d58debb-1600-0000-c8cf-bf86720e0000 pid=3698->guuid=8251a2c1-1600-0000-c8cf-bf868a0e0000 pid=3722 execve guuid=3be9e1c1-1600-0000-c8cf-bf868c0e0000 pid=3724 /usr/bin/ls guuid=6d58debb-1600-0000-c8cf-bf86720e0000 pid=3698->guuid=3be9e1c1-1600-0000-c8cf-bf868c0e0000 pid=3724 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-03-27 03:32:35 UTC
File Type:
Text (Shell)
AV detection:
14 of 36 (38.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 0b4c4039cc81d5f78fa7265720c4e6ae370303fb9f5d0cda97c74953576f458d

(this sample)

  
Delivery method
Distributed via web download

Comments