MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0f335a8feef756b240a6290108c74c69be1c8caae34725c5c66ef8066276310e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 0f335a8feef756b240a6290108c74c69be1c8caae34725c5c66ef8066276310e
SHA3-384 hash: 34f844e501e8ff1d30e42d622f749c9d650c2a613112fa0518d76f667c409c6b6e608c85a367549a09197f4715cecb97
SHA1 hash: ccfc2e3bd34c092bd26da3681d5304a9e02df9bb
MD5 hash: 2d3d79cad563f00dae9330bc5425bc4b
humanhash: berlin-ceiling-saturn-louisiana
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-15 12:08:01 UTC
Last seen:2026-03-15 13:15:53 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 384:WFcuQpWx+BL0SWL0gZzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:WF8i+BL0SI06zsP4cbddr7zsP4cbddrk
TLSH T1F6925CB512896C79FBD1CE399F3C7F4CADE882C42124E3ACBA4F39215A1166DC70535A
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
2
# of downloads :
120
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=746779e4-1600-0000-c1e3-c74a940f0000 pid=3988 /usr/bin/sudo guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997 /tmp/sample.bin guuid=746779e4-1600-0000-c1e3-c74a940f0000 pid=3988->guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997 execve guuid=5a871de7-1600-0000-c1e3-c74aa00f0000 pid=4000 /usr/bin/bash guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=5a871de7-1600-0000-c1e3-c74aa00f0000 pid=4000 clone guuid=93fe2ae7-1600-0000-c1e3-c74aa10f0000 pid=4001 /usr/bin/bash guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=93fe2ae7-1600-0000-c1e3-c74aa10f0000 pid=4001 clone guuid=42a55fe7-1600-0000-c1e3-c74aa30f0000 pid=4003 /usr/bin/mkdir guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=42a55fe7-1600-0000-c1e3-c74aa30f0000 pid=4003 execve guuid=beeed9e7-1600-0000-c1e3-c74aa40f0000 pid=4004 /usr/bin/mkdir guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=beeed9e7-1600-0000-c1e3-c74aa40f0000 pid=4004 execve guuid=bce15ae8-1600-0000-c1e3-c74aa80f0000 pid=4008 /usr/bin/mkdir guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=bce15ae8-1600-0000-c1e3-c74aa80f0000 pid=4008 execve guuid=9abbbde8-1600-0000-c1e3-c74aab0f0000 pid=4011 /usr/bin/mkdir guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=9abbbde8-1600-0000-c1e3-c74aab0f0000 pid=4011 execve guuid=5ff72ce9-1600-0000-c1e3-c74aad0f0000 pid=4013 /usr/bin/mkdir guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=5ff72ce9-1600-0000-c1e3-c74aad0f0000 pid=4013 execve guuid=6239a1e9-1600-0000-c1e3-c74aae0f0000 pid=4014 /usr/bin/mkdir guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=6239a1e9-1600-0000-c1e3-c74aae0f0000 pid=4014 execve guuid=0178f8e9-1600-0000-c1e3-c74ab10f0000 pid=4017 /usr/bin/mkdir guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=0178f8e9-1600-0000-c1e3-c74ab10f0000 pid=4017 execve guuid=4a554eea-1600-0000-c1e3-c74ab30f0000 pid=4019 /usr/bin/cp guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=4a554eea-1600-0000-c1e3-c74ab30f0000 pid=4019 execve guuid=7810b3ea-1600-0000-c1e3-c74ab50f0000 pid=4021 /usr/bin/cp guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=7810b3ea-1600-0000-c1e3-c74ab50f0000 pid=4021 execve guuid=200d3beb-1600-0000-c1e3-c74ab80f0000 pid=4024 /usr/bin/cp guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=200d3beb-1600-0000-c1e3-c74ab80f0000 pid=4024 execve guuid=2403a2eb-1600-0000-c1e3-c74aba0f0000 pid=4026 /usr/bin/cp guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=2403a2eb-1600-0000-c1e3-c74aba0f0000 pid=4026 execve guuid=41d403ec-1600-0000-c1e3-c74abc0f0000 pid=4028 /usr/bin/cp guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=41d403ec-1600-0000-c1e3-c74abc0f0000 pid=4028 execve guuid=7c516dec-1600-0000-c1e3-c74ac00f0000 pid=4032 /usr/bin/cp guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=7c516dec-1600-0000-c1e3-c74ac00f0000 pid=4032 execve guuid=3f2fd1ec-1600-0000-c1e3-c74ac40f0000 pid=4036 /usr/bin/cp guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=3f2fd1ec-1600-0000-c1e3-c74ac40f0000 pid=4036 execve guuid=37ba51ed-1600-0000-c1e3-c74ac60f0000 pid=4038 /usr/bin/cp guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=37ba51ed-1600-0000-c1e3-c74ac60f0000 pid=4038 execve guuid=b6e8b5ed-1600-0000-c1e3-c74ac80f0000 pid=4040 /usr/bin/cp guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=b6e8b5ed-1600-0000-c1e3-c74ac80f0000 pid=4040 execve guuid=715c0eee-1600-0000-c1e3-c74acc0f0000 pid=4044 /usr/bin/cp guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=715c0eee-1600-0000-c1e3-c74acc0f0000 pid=4044 execve guuid=1f907aee-1600-0000-c1e3-c74acd0f0000 pid=4045 /usr/bin/cp guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=1f907aee-1600-0000-c1e3-c74acd0f0000 pid=4045 execve guuid=730a0def-1600-0000-c1e3-c74ad20f0000 pid=4050 /usr/bin/cp guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=730a0def-1600-0000-c1e3-c74ad20f0000 pid=4050 execve guuid=cf7173ef-1600-0000-c1e3-c74ad40f0000 pid=4052 /usr/bin/cp guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=cf7173ef-1600-0000-c1e3-c74ad40f0000 pid=4052 execve guuid=f47c00f0-1600-0000-c1e3-c74ad70f0000 pid=4055 /usr/bin/cp guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=f47c00f0-1600-0000-c1e3-c74ad70f0000 pid=4055 execve guuid=b13d90f0-1600-0000-c1e3-c74ada0f0000 pid=4058 /usr/bin/cp guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=b13d90f0-1600-0000-c1e3-c74ada0f0000 pid=4058 execve guuid=46edfcf0-1600-0000-c1e3-c74add0f0000 pid=4061 /usr/bin/touch guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=46edfcf0-1600-0000-c1e3-c74add0f0000 pid=4061 execve guuid=223641f1-1600-0000-c1e3-c74adf0f0000 pid=4063 /usr/bin/bash guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=223641f1-1600-0000-c1e3-c74adf0f0000 pid=4063 clone guuid=0b2b4ef1-1600-0000-c1e3-c74ae00f0000 pid=4064 /usr/bin/bash guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=0b2b4ef1-1600-0000-c1e3-c74ae00f0000 pid=4064 clone guuid=8a0677f1-1600-0000-c1e3-c74ae10f0000 pid=4065 /usr/bin/bash guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=8a0677f1-1600-0000-c1e3-c74ae10f0000 pid=4065 clone guuid=23c686f1-1600-0000-c1e3-c74ae20f0000 pid=4066 /usr/bin/base64 write-file guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=23c686f1-1600-0000-c1e3-c74ae20f0000 pid=4066 execve guuid=238f4bf2-1600-0000-c1e3-c74ae60f0000 pid=4070 /usr/bin/bash guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=238f4bf2-1600-0000-c1e3-c74ae60f0000 pid=4070 execve guuid=4b6a46f8-1600-0000-c1e3-c74a0e100000 pid=4110 /usr/bin/rm delete-file guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=4b6a46f8-1600-0000-c1e3-c74a0e100000 pid=4110 execve guuid=9664a9f8-1600-0000-c1e3-c74a10100000 pid=4112 /usr/bin/bash guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=9664a9f8-1600-0000-c1e3-c74a10100000 pid=4112 clone guuid=6a58c6f8-1600-0000-c1e3-c74a13100000 pid=4115 /usr/bin/bash guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=6a58c6f8-1600-0000-c1e3-c74a13100000 pid=4115 clone guuid=5712eef8-1600-0000-c1e3-c74a14100000 pid=4116 /usr/bin/bash guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=5712eef8-1600-0000-c1e3-c74a14100000 pid=4116 execve guuid=b3944af9-1600-0000-c1e3-c74a16100000 pid=4118 /usr/bin/rm guuid=e27046e6-1600-0000-c1e3-c74a9d0f0000 pid=3997->guuid=b3944af9-1600-0000-c1e3-c74a16100000 pid=4118 execve guuid=dbec12f3-1600-0000-c1e3-c74aea0f0000 pid=4074 /usr/bin/bash guuid=238f4bf2-1600-0000-c1e3-c74ae60f0000 pid=4070->guuid=dbec12f3-1600-0000-c1e3-c74aea0f0000 pid=4074 clone guuid=fe3321f3-1600-0000-c1e3-c74aeb0f0000 pid=4075 /usr/bin/bash guuid=238f4bf2-1600-0000-c1e3-c74ae60f0000 pid=4070->guuid=fe3321f3-1600-0000-c1e3-c74aeb0f0000 pid=4075 clone guuid=89de4ef3-1600-0000-c1e3-c74aed0f0000 pid=4077 /usr/bin/ls guuid=238f4bf2-1600-0000-c1e3-c74ae60f0000 pid=4070->guuid=89de4ef3-1600-0000-c1e3-c74aed0f0000 pid=4077 execve guuid=48400df4-1600-0000-c1e3-c74af00f0000 pid=4080 /usr/bin/cat guuid=238f4bf2-1600-0000-c1e3-c74ae60f0000 pid=4070->guuid=48400df4-1600-0000-c1e3-c74af00f0000 pid=4080 execve guuid=555f69f4-1600-0000-c1e3-c74af10f0000 pid=4081 /usr/bin/ls guuid=238f4bf2-1600-0000-c1e3-c74ae60f0000 pid=4070->guuid=555f69f4-1600-0000-c1e3-c74af10f0000 pid=4081 execve guuid=5228daf4-1600-0000-c1e3-c74af50f0000 pid=4085 /usr/bin/mkdir guuid=238f4bf2-1600-0000-c1e3-c74ae60f0000 pid=4070->guuid=5228daf4-1600-0000-c1e3-c74af50f0000 pid=4085 execve guuid=ef4931f5-1600-0000-c1e3-c74af90f0000 pid=4089 /usr/bin/mv guuid=238f4bf2-1600-0000-c1e3-c74ae60f0000 pid=4070->guuid=ef4931f5-1600-0000-c1e3-c74af90f0000 pid=4089 execve guuid=e0849ef5-1600-0000-c1e3-c74afa0f0000 pid=4090 /usr/bin/bash guuid=238f4bf2-1600-0000-c1e3-c74ae60f0000 pid=4070->guuid=e0849ef5-1600-0000-c1e3-c74afa0f0000 pid=4090 clone guuid=bd65a5f5-1600-0000-c1e3-c74afc0f0000 pid=4092 /usr/bin/base64 write-file guuid=238f4bf2-1600-0000-c1e3-c74ae60f0000 pid=4070->guuid=bd65a5f5-1600-0000-c1e3-c74afc0f0000 pid=4092 execve guuid=f1a804f6-1600-0000-c1e3-c74afe0f0000 pid=4094 /usr/bin/rm delete-file guuid=238f4bf2-1600-0000-c1e3-c74ae60f0000 pid=4070->guuid=f1a804f6-1600-0000-c1e3-c74afe0f0000 pid=4094 execve guuid=fe5948f6-1600-0000-c1e3-c74a00100000 pid=4096 /usr/bin/ls guuid=238f4bf2-1600-0000-c1e3-c74ae60f0000 pid=4070->guuid=fe5948f6-1600-0000-c1e3-c74a00100000 pid=4096 execve guuid=3fe6b6f6-1600-0000-c1e3-c74a03100000 pid=4099 /usr/bin/bash guuid=238f4bf2-1600-0000-c1e3-c74ae60f0000 pid=4070->guuid=3fe6b6f6-1600-0000-c1e3-c74a03100000 pid=4099 clone guuid=7eb0bcf6-1600-0000-c1e3-c74a04100000 pid=4100 /usr/bin/base64 write-file guuid=238f4bf2-1600-0000-c1e3-c74ae60f0000 pid=4070->guuid=7eb0bcf6-1600-0000-c1e3-c74a04100000 pid=4100 execve guuid=1c0807f7-1600-0000-c1e3-c74a06100000 pid=4102 /usr/bin/ls guuid=238f4bf2-1600-0000-c1e3-c74ae60f0000 pid=4070->guuid=1c0807f7-1600-0000-c1e3-c74a06100000 pid=4102 execve guuid=ca5470f7-1600-0000-c1e3-c74a09100000 pid=4105 /usr/bin/cat guuid=238f4bf2-1600-0000-c1e3-c74ae60f0000 pid=4070->guuid=ca5470f7-1600-0000-c1e3-c74a09100000 pid=4105 execve guuid=2099c0f7-1600-0000-c1e3-c74a0a100000 pid=4106 /usr/bin/ls guuid=238f4bf2-1600-0000-c1e3-c74ae60f0000 pid=4070->guuid=2099c0f7-1600-0000-c1e3-c74a0a100000 pid=4106 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-15 12:08:19 UTC
File Type:
Text (Shell)
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 0f335a8feef756b240a6290108c74c69be1c8caae34725c5c66ef8066276310e

(this sample)

  
Delivery method
Distributed via web download

Comments