MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0b6568e67e4545d2ed31b91a09fd8768d8241321c13f9acc06f38ff1a3f91f53. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 0b6568e67e4545d2ed31b91a09fd8768d8241321c13f9acc06f38ff1a3f91f53
SHA3-384 hash: fd7fddee87770a12c265e9b5338625605dfd20ae11fecd77c248b9c30d8f2e4cb0176bc0b59a2ebaa310fbfc39775406
SHA1 hash: f7bf11df5958568d813d00ff56817672e6c190ef
MD5 hash: 057a4d214929df3aad6b5ce79f3e4cd9
humanhash: four-indigo-iowa-nitrogen
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-14 05:16:20 UTC
Last seen:2026-03-14 19:02:49 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 384:6GO0M3vgRjGlsaq73zsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:6GMmjfjzsP4cbddr7zsP4cbddrk
TLSH T1FB925CB916496C79BBC0DE7D9F3C7F0CADE481C02219A39CBA4F39714A2069DDA0635D
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
2
# of downloads :
88
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=e919e858-1600-0000-896d-dd9a5b0b0000 pid=2907 /usr/bin/sudo guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913 /tmp/sample.bin guuid=e919e858-1600-0000-896d-dd9a5b0b0000 pid=2907->guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913 execve guuid=7e6c715b-1600-0000-896d-dd9a630b0000 pid=2915 /usr/bin/bash guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=7e6c715b-1600-0000-896d-dd9a630b0000 pid=2915 clone guuid=42de995b-1600-0000-896d-dd9a640b0000 pid=2916 /usr/bin/bash guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=42de995b-1600-0000-896d-dd9a640b0000 pid=2916 clone guuid=05f8fe5b-1600-0000-896d-dd9a650b0000 pid=2917 /usr/bin/mkdir guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=05f8fe5b-1600-0000-896d-dd9a650b0000 pid=2917 execve guuid=17ad4d5c-1600-0000-896d-dd9a670b0000 pid=2919 /usr/bin/mkdir guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=17ad4d5c-1600-0000-896d-dd9a670b0000 pid=2919 execve guuid=f21aaa5c-1600-0000-896d-dd9a690b0000 pid=2921 /usr/bin/mkdir guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=f21aaa5c-1600-0000-896d-dd9a690b0000 pid=2921 execve guuid=c017005d-1600-0000-896d-dd9a6b0b0000 pid=2923 /usr/bin/mkdir guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=c017005d-1600-0000-896d-dd9a6b0b0000 pid=2923 execve guuid=b4f0535d-1600-0000-896d-dd9a6d0b0000 pid=2925 /usr/bin/mkdir guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=b4f0535d-1600-0000-896d-dd9a6d0b0000 pid=2925 execve guuid=3a86ae5d-1600-0000-896d-dd9a6f0b0000 pid=2927 /usr/bin/mkdir guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=3a86ae5d-1600-0000-896d-dd9a6f0b0000 pid=2927 execve guuid=62cb335e-1600-0000-896d-dd9a710b0000 pid=2929 /usr/bin/mkdir guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=62cb335e-1600-0000-896d-dd9a710b0000 pid=2929 execve guuid=6b798c5e-1600-0000-896d-dd9a730b0000 pid=2931 /usr/bin/cp guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=6b798c5e-1600-0000-896d-dd9a730b0000 pid=2931 execve guuid=d499e95e-1600-0000-896d-dd9a740b0000 pid=2932 /usr/bin/cp guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=d499e95e-1600-0000-896d-dd9a740b0000 pid=2932 execve guuid=bf4b715f-1600-0000-896d-dd9a780b0000 pid=2936 /usr/bin/cp guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=bf4b715f-1600-0000-896d-dd9a780b0000 pid=2936 execve guuid=0f58bf5f-1600-0000-896d-dd9a7a0b0000 pid=2938 /usr/bin/cp guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=0f58bf5f-1600-0000-896d-dd9a7a0b0000 pid=2938 execve guuid=4f5e2560-1600-0000-896d-dd9a7c0b0000 pid=2940 /usr/bin/cp guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=4f5e2560-1600-0000-896d-dd9a7c0b0000 pid=2940 execve guuid=e0c58460-1600-0000-896d-dd9a7e0b0000 pid=2942 /usr/bin/cp guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=e0c58460-1600-0000-896d-dd9a7e0b0000 pid=2942 execve guuid=3e09e660-1600-0000-896d-dd9a7f0b0000 pid=2943 /usr/bin/cp guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=3e09e660-1600-0000-896d-dd9a7f0b0000 pid=2943 execve guuid=257e3c61-1600-0000-896d-dd9a810b0000 pid=2945 /usr/bin/cp guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=257e3c61-1600-0000-896d-dd9a810b0000 pid=2945 execve guuid=b5c60562-1600-0000-896d-dd9a820b0000 pid=2946 /usr/bin/cp guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=b5c60562-1600-0000-896d-dd9a820b0000 pid=2946 execve guuid=d97f7c62-1600-0000-896d-dd9a830b0000 pid=2947 /usr/bin/cp guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=d97f7c62-1600-0000-896d-dd9a830b0000 pid=2947 execve guuid=62f8d862-1600-0000-896d-dd9a860b0000 pid=2950 /usr/bin/cp guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=62f8d862-1600-0000-896d-dd9a860b0000 pid=2950 execve guuid=8b443863-1600-0000-896d-dd9a880b0000 pid=2952 /usr/bin/cp guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=8b443863-1600-0000-896d-dd9a880b0000 pid=2952 execve guuid=7361ad63-1600-0000-896d-dd9a8a0b0000 pid=2954 /usr/bin/cp guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=7361ad63-1600-0000-896d-dd9a8a0b0000 pid=2954 execve guuid=440f1264-1600-0000-896d-dd9a8c0b0000 pid=2956 /usr/bin/cp guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=440f1264-1600-0000-896d-dd9a8c0b0000 pid=2956 execve guuid=e06c7264-1600-0000-896d-dd9a8f0b0000 pid=2959 /usr/bin/cp guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=e06c7264-1600-0000-896d-dd9a8f0b0000 pid=2959 execve guuid=65f4d264-1600-0000-896d-dd9a910b0000 pid=2961 /usr/bin/touch guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=65f4d264-1600-0000-896d-dd9a910b0000 pid=2961 execve guuid=a8562c65-1600-0000-896d-dd9a920b0000 pid=2962 /usr/bin/bash guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=a8562c65-1600-0000-896d-dd9a920b0000 pid=2962 clone guuid=02823865-1600-0000-896d-dd9a940b0000 pid=2964 /usr/bin/bash guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=02823865-1600-0000-896d-dd9a940b0000 pid=2964 clone guuid=9c3a5a65-1600-0000-896d-dd9a950b0000 pid=2965 /usr/bin/bash guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=9c3a5a65-1600-0000-896d-dd9a950b0000 pid=2965 clone guuid=91b96765-1600-0000-896d-dd9a960b0000 pid=2966 /usr/bin/base64 write-file guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=91b96765-1600-0000-896d-dd9a960b0000 pid=2966 execve guuid=dcb20166-1600-0000-896d-dd9a970b0000 pid=2967 /usr/bin/bash guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=dcb20166-1600-0000-896d-dd9a970b0000 pid=2967 execve guuid=64c8fc6a-1600-0000-896d-dd9ab30b0000 pid=2995 /usr/bin/rm delete-file guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=64c8fc6a-1600-0000-896d-dd9ab30b0000 pid=2995 execve guuid=5578476b-1600-0000-896d-dd9ab50b0000 pid=2997 /usr/bin/bash guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=5578476b-1600-0000-896d-dd9ab50b0000 pid=2997 clone guuid=73f3506b-1600-0000-896d-dd9ab60b0000 pid=2998 /usr/bin/bash guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=73f3506b-1600-0000-896d-dd9ab60b0000 pid=2998 clone guuid=9c8b816b-1600-0000-896d-dd9ab80b0000 pid=3000 /usr/bin/bash guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=9c8b816b-1600-0000-896d-dd9ab80b0000 pid=3000 execve guuid=e774f06b-1600-0000-896d-dd9abb0b0000 pid=3003 /usr/bin/rm guuid=9069915a-1600-0000-896d-dd9a610b0000 pid=2913->guuid=e774f06b-1600-0000-896d-dd9abb0b0000 pid=3003 execve guuid=05b95c66-1600-0000-896d-dd9a980b0000 pid=2968 /usr/bin/bash guuid=dcb20166-1600-0000-896d-dd9a970b0000 pid=2967->guuid=05b95c66-1600-0000-896d-dd9a980b0000 pid=2968 clone guuid=ec958066-1600-0000-896d-dd9a990b0000 pid=2969 /usr/bin/bash guuid=dcb20166-1600-0000-896d-dd9a970b0000 pid=2967->guuid=ec958066-1600-0000-896d-dd9a990b0000 pid=2969 clone guuid=e142ab66-1600-0000-896d-dd9a9a0b0000 pid=2970 /usr/bin/ls guuid=dcb20166-1600-0000-896d-dd9a970b0000 pid=2967->guuid=e142ab66-1600-0000-896d-dd9a9a0b0000 pid=2970 execve guuid=9f6c2467-1600-0000-896d-dd9a9d0b0000 pid=2973 /usr/bin/cat guuid=dcb20166-1600-0000-896d-dd9a970b0000 pid=2967->guuid=9f6c2467-1600-0000-896d-dd9a9d0b0000 pid=2973 execve guuid=448e6d67-1600-0000-896d-dd9a9f0b0000 pid=2975 /usr/bin/ls guuid=dcb20166-1600-0000-896d-dd9a970b0000 pid=2967->guuid=448e6d67-1600-0000-896d-dd9a9f0b0000 pid=2975 execve guuid=eb6dc967-1600-0000-896d-dd9aa10b0000 pid=2977 /usr/bin/mkdir guuid=dcb20166-1600-0000-896d-dd9a970b0000 pid=2967->guuid=eb6dc967-1600-0000-896d-dd9aa10b0000 pid=2977 execve guuid=eb171c68-1600-0000-896d-dd9aa30b0000 pid=2979 /usr/bin/mv guuid=dcb20166-1600-0000-896d-dd9a970b0000 pid=2967->guuid=eb171c68-1600-0000-896d-dd9aa30b0000 pid=2979 execve guuid=9ee37a68-1600-0000-896d-dd9aa60b0000 pid=2982 /usr/bin/bash guuid=dcb20166-1600-0000-896d-dd9a970b0000 pid=2967->guuid=9ee37a68-1600-0000-896d-dd9aa60b0000 pid=2982 clone guuid=31f48068-1600-0000-896d-dd9aa70b0000 pid=2983 /usr/bin/base64 write-file guuid=dcb20166-1600-0000-896d-dd9a970b0000 pid=2967->guuid=31f48068-1600-0000-896d-dd9aa70b0000 pid=2983 execve guuid=d7a9cf68-1600-0000-896d-dd9aa90b0000 pid=2985 /usr/bin/rm delete-file guuid=dcb20166-1600-0000-896d-dd9a970b0000 pid=2967->guuid=d7a9cf68-1600-0000-896d-dd9aa90b0000 pid=2985 execve guuid=ac001a69-1600-0000-896d-dd9aaa0b0000 pid=2986 /usr/bin/ls guuid=dcb20166-1600-0000-896d-dd9a970b0000 pid=2967->guuid=ac001a69-1600-0000-896d-dd9aaa0b0000 pid=2986 execve guuid=101e7e69-1600-0000-896d-dd9aac0b0000 pid=2988 /usr/bin/bash guuid=dcb20166-1600-0000-896d-dd9a970b0000 pid=2967->guuid=101e7e69-1600-0000-896d-dd9aac0b0000 pid=2988 clone guuid=4dd58669-1600-0000-896d-dd9aad0b0000 pid=2989 /usr/bin/base64 write-file guuid=dcb20166-1600-0000-896d-dd9a970b0000 pid=2967->guuid=4dd58669-1600-0000-896d-dd9aad0b0000 pid=2989 execve guuid=87b3e769-1600-0000-896d-dd9aae0b0000 pid=2990 /usr/bin/ls guuid=dcb20166-1600-0000-896d-dd9a970b0000 pid=2967->guuid=87b3e769-1600-0000-896d-dd9aae0b0000 pid=2990 execve guuid=eec4556a-1600-0000-896d-dd9ab00b0000 pid=2992 /usr/bin/cat guuid=dcb20166-1600-0000-896d-dd9a970b0000 pid=2967->guuid=eec4556a-1600-0000-896d-dd9ab00b0000 pid=2992 execve guuid=8cee986a-1600-0000-896d-dd9ab10b0000 pid=2993 /usr/bin/ls guuid=dcb20166-1600-0000-896d-dd9a970b0000 pid=2967->guuid=8cee986a-1600-0000-896d-dd9ab10b0000 pid=2993 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-14 05:17:26 UTC
File Type:
Text (Shell)
AV detection:
10 of 23 (43.48%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 0b6568e67e4545d2ed31b91a09fd8768d8241321c13f9acc06f38ff1a3f91f53

(this sample)

  
Delivery method
Distributed via web download

Comments