MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 20c5421c8b618d0f3aefbb12f67e1d024663029526e6a20c71a29abba3ca86bf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 20c5421c8b618d0f3aefbb12f67e1d024663029526e6a20c71a29abba3ca86bf
SHA3-384 hash: a01e041f887aa27940072f782b8ca73c8d178a9ad9ad876a94374c2f1226d35e3338002b480fb1ef7560188b04d4144c
SHA1 hash: a1b0ccc0adff387f3a980444c2d979096b26f358
MD5 hash: 24eab16bac00cc74d26fa084a799c043
humanhash: stairway-venus-tennis-ohio
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-08 19:07:39 UTC
Last seen:2026-03-08 20:22:34 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 384:xlFcuQpWx+BL0SWL0gpzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:bF8i+BL0SI0SzsP4cbddr7zsP4cbddrk
TLSH T192925DB512896C79FBD0CE39AF3C7F4DADE8C2C42124A3ACBA4F39215A1166DC705359
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
2
# of downloads :
55
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=15daecd4-1600-0000-6365-6c20820d0000 pid=3458 /usr/bin/sudo guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467 /tmp/sample.bin guuid=15daecd4-1600-0000-6365-6c20820d0000 pid=3458->guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467 execve guuid=b2d645d8-1600-0000-6365-6c208d0d0000 pid=3469 /usr/bin/bash guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=b2d645d8-1600-0000-6365-6c208d0d0000 pid=3469 clone guuid=4fcf4ed8-1600-0000-6365-6c208e0d0000 pid=3470 /usr/bin/bash guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=4fcf4ed8-1600-0000-6365-6c208e0d0000 pid=3470 clone guuid=1f6978d8-1600-0000-6365-6c20900d0000 pid=3472 /usr/bin/mkdir guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=1f6978d8-1600-0000-6365-6c20900d0000 pid=3472 execve guuid=c8cff0d8-1600-0000-6365-6c20920d0000 pid=3474 /usr/bin/mkdir guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=c8cff0d8-1600-0000-6365-6c20920d0000 pid=3474 execve guuid=a5bd4ad9-1600-0000-6365-6c20940d0000 pid=3476 /usr/bin/mkdir guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=a5bd4ad9-1600-0000-6365-6c20940d0000 pid=3476 execve guuid=7db1c1d9-1600-0000-6365-6c20970d0000 pid=3479 /usr/bin/mkdir guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=7db1c1d9-1600-0000-6365-6c20970d0000 pid=3479 execve guuid=757e34da-1600-0000-6365-6c20980d0000 pid=3480 /usr/bin/mkdir guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=757e34da-1600-0000-6365-6c20980d0000 pid=3480 execve guuid=b2c993da-1600-0000-6365-6c209b0d0000 pid=3483 /usr/bin/mkdir guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=b2c993da-1600-0000-6365-6c209b0d0000 pid=3483 execve guuid=9540fada-1600-0000-6365-6c209d0d0000 pid=3485 /usr/bin/mkdir guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=9540fada-1600-0000-6365-6c209d0d0000 pid=3485 execve guuid=717558db-1600-0000-6365-6c209f0d0000 pid=3487 /usr/bin/cp guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=717558db-1600-0000-6365-6c209f0d0000 pid=3487 execve guuid=8d78c5db-1600-0000-6365-6c20a20d0000 pid=3490 /usr/bin/cp guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=8d78c5db-1600-0000-6365-6c20a20d0000 pid=3490 execve guuid=55aa2edc-1600-0000-6365-6c20a40d0000 pid=3492 /usr/bin/cp guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=55aa2edc-1600-0000-6365-6c20a40d0000 pid=3492 execve guuid=8af8a8dc-1600-0000-6365-6c20a60d0000 pid=3494 /usr/bin/cp guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=8af8a8dc-1600-0000-6365-6c20a60d0000 pid=3494 execve guuid=4e1f0bdd-1600-0000-6365-6c20ab0d0000 pid=3499 /usr/bin/cp guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=4e1f0bdd-1600-0000-6365-6c20ab0d0000 pid=3499 execve guuid=f132b7dd-1600-0000-6365-6c20ac0d0000 pid=3500 /usr/bin/cp guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=f132b7dd-1600-0000-6365-6c20ac0d0000 pid=3500 execve guuid=7f1a1ede-1600-0000-6365-6c20ad0d0000 pid=3501 /usr/bin/cp guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=7f1a1ede-1600-0000-6365-6c20ad0d0000 pid=3501 execve guuid=741787de-1600-0000-6365-6c20ae0d0000 pid=3502 /usr/bin/cp guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=741787de-1600-0000-6365-6c20ae0d0000 pid=3502 execve guuid=b5a3f5de-1600-0000-6365-6c20af0d0000 pid=3503 /usr/bin/cp guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=b5a3f5de-1600-0000-6365-6c20af0d0000 pid=3503 execve guuid=977256df-1600-0000-6365-6c20b00d0000 pid=3504 /usr/bin/cp guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=977256df-1600-0000-6365-6c20b00d0000 pid=3504 execve guuid=b448c1df-1600-0000-6365-6c20b10d0000 pid=3505 /usr/bin/cp guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=b448c1df-1600-0000-6365-6c20b10d0000 pid=3505 execve guuid=8d6a24e0-1600-0000-6365-6c20b20d0000 pid=3506 /usr/bin/cp guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=8d6a24e0-1600-0000-6365-6c20b20d0000 pid=3506 execve guuid=ff0881e0-1600-0000-6365-6c20b30d0000 pid=3507 /usr/bin/cp guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=ff0881e0-1600-0000-6365-6c20b30d0000 pid=3507 execve guuid=ad32dde0-1600-0000-6365-6c20b40d0000 pid=3508 /usr/bin/cp guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=ad32dde0-1600-0000-6365-6c20b40d0000 pid=3508 execve guuid=c20a49e1-1600-0000-6365-6c20b50d0000 pid=3509 /usr/bin/cp guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=c20a49e1-1600-0000-6365-6c20b50d0000 pid=3509 execve guuid=97d19ee1-1600-0000-6365-6c20b60d0000 pid=3510 /usr/bin/touch guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=97d19ee1-1600-0000-6365-6c20b60d0000 pid=3510 execve guuid=2597e0e1-1600-0000-6365-6c20ba0d0000 pid=3514 /usr/bin/bash guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=2597e0e1-1600-0000-6365-6c20ba0d0000 pid=3514 clone guuid=d22ce8e1-1600-0000-6365-6c20bb0d0000 pid=3515 /usr/bin/bash guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=d22ce8e1-1600-0000-6365-6c20bb0d0000 pid=3515 clone guuid=788f0ce2-1600-0000-6365-6c20bc0d0000 pid=3516 /usr/bin/bash guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=788f0ce2-1600-0000-6365-6c20bc0d0000 pid=3516 clone guuid=b04e13e2-1600-0000-6365-6c20bd0d0000 pid=3517 /usr/bin/base64 write-file guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=b04e13e2-1600-0000-6365-6c20bd0d0000 pid=3517 execve guuid=23deb1e2-1600-0000-6365-6c20c00d0000 pid=3520 /usr/bin/bash guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=23deb1e2-1600-0000-6365-6c20c00d0000 pid=3520 execve guuid=1a926ae8-1600-0000-6365-6c20de0d0000 pid=3550 /usr/bin/rm delete-file guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=1a926ae8-1600-0000-6365-6c20de0d0000 pid=3550 execve guuid=0b46b9e8-1600-0000-6365-6c20e00d0000 pid=3552 /usr/bin/bash guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=0b46b9e8-1600-0000-6365-6c20e00d0000 pid=3552 clone guuid=7d12c2e8-1600-0000-6365-6c20e10d0000 pid=3553 /usr/bin/bash guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=7d12c2e8-1600-0000-6365-6c20e10d0000 pid=3553 clone guuid=8be3efe8-1600-0000-6365-6c20e30d0000 pid=3555 /usr/bin/bash guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=8be3efe8-1600-0000-6365-6c20e30d0000 pid=3555 execve guuid=64b15de9-1600-0000-6365-6c20e40d0000 pid=3556 /usr/bin/rm guuid=409fb0d7-1600-0000-6365-6c208b0d0000 pid=3467->guuid=64b15de9-1600-0000-6365-6c20e40d0000 pid=3556 execve guuid=e452fae2-1600-0000-6365-6c20c20d0000 pid=3522 /usr/bin/bash guuid=23deb1e2-1600-0000-6365-6c20c00d0000 pid=3520->guuid=e452fae2-1600-0000-6365-6c20c20d0000 pid=3522 clone guuid=8fe9ffe2-1600-0000-6365-6c20c30d0000 pid=3523 /usr/bin/bash guuid=23deb1e2-1600-0000-6365-6c20c00d0000 pid=3520->guuid=8fe9ffe2-1600-0000-6365-6c20c30d0000 pid=3523 clone guuid=006616e3-1600-0000-6365-6c20c50d0000 pid=3525 /usr/bin/ls guuid=23deb1e2-1600-0000-6365-6c20c00d0000 pid=3520->guuid=006616e3-1600-0000-6365-6c20c50d0000 pid=3525 execve guuid=93bb8de3-1600-0000-6365-6c20c80d0000 pid=3528 /usr/bin/cat guuid=23deb1e2-1600-0000-6365-6c20c00d0000 pid=3520->guuid=93bb8de3-1600-0000-6365-6c20c80d0000 pid=3528 execve guuid=a09ccbe3-1600-0000-6365-6c20ca0d0000 pid=3530 /usr/bin/ls guuid=23deb1e2-1600-0000-6365-6c20c00d0000 pid=3520->guuid=a09ccbe3-1600-0000-6365-6c20ca0d0000 pid=3530 execve guuid=c61142e4-1600-0000-6365-6c20cd0d0000 pid=3533 /usr/bin/mkdir guuid=23deb1e2-1600-0000-6365-6c20c00d0000 pid=3520->guuid=c61142e4-1600-0000-6365-6c20cd0d0000 pid=3533 execve guuid=81a595e4-1600-0000-6365-6c20cf0d0000 pid=3535 /usr/bin/mv guuid=23deb1e2-1600-0000-6365-6c20c00d0000 pid=3520->guuid=81a595e4-1600-0000-6365-6c20cf0d0000 pid=3535 execve guuid=6e8e08e5-1600-0000-6365-6c20d00d0000 pid=3536 /usr/bin/bash guuid=23deb1e2-1600-0000-6365-6c20c00d0000 pid=3520->guuid=6e8e08e5-1600-0000-6365-6c20d00d0000 pid=3536 clone guuid=6e9a1be5-1600-0000-6365-6c20d10d0000 pid=3537 /usr/bin/base64 write-file guuid=23deb1e2-1600-0000-6365-6c20c00d0000 pid=3520->guuid=6e9a1be5-1600-0000-6365-6c20d10d0000 pid=3537 execve guuid=38ef8ce5-1600-0000-6365-6c20d20d0000 pid=3538 /usr/bin/rm delete-file guuid=23deb1e2-1600-0000-6365-6c20c00d0000 pid=3520->guuid=38ef8ce5-1600-0000-6365-6c20d20d0000 pid=3538 execve guuid=cb51f8e5-1600-0000-6365-6c20d40d0000 pid=3540 /usr/bin/ls guuid=23deb1e2-1600-0000-6365-6c20c00d0000 pid=3520->guuid=cb51f8e5-1600-0000-6365-6c20d40d0000 pid=3540 execve guuid=cf85b2e6-1600-0000-6365-6c20d50d0000 pid=3541 /usr/bin/bash guuid=23deb1e2-1600-0000-6365-6c20c00d0000 pid=3520->guuid=cf85b2e6-1600-0000-6365-6c20d50d0000 pid=3541 clone guuid=70aabce6-1600-0000-6365-6c20d60d0000 pid=3542 /usr/bin/base64 write-file guuid=23deb1e2-1600-0000-6365-6c20c00d0000 pid=3520->guuid=70aabce6-1600-0000-6365-6c20d60d0000 pid=3542 execve guuid=63fd12e7-1600-0000-6365-6c20d70d0000 pid=3543 /usr/bin/ls guuid=23deb1e2-1600-0000-6365-6c20c00d0000 pid=3520->guuid=63fd12e7-1600-0000-6365-6c20d70d0000 pid=3543 execve guuid=e961a3e7-1600-0000-6365-6c20d90d0000 pid=3545 /usr/bin/cat guuid=23deb1e2-1600-0000-6365-6c20c00d0000 pid=3520->guuid=e961a3e7-1600-0000-6365-6c20d90d0000 pid=3545 execve guuid=2bccf4e7-1600-0000-6365-6c20db0d0000 pid=3547 /usr/bin/ls guuid=23deb1e2-1600-0000-6365-6c20c00d0000 pid=3520->guuid=2bccf4e7-1600-0000-6365-6c20db0d0000 pid=3547 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-08 19:08:32 UTC
File Type:
Text (Shell)
AV detection:
17 of 38 (44.74%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 20c5421c8b618d0f3aefbb12f67e1d024663029526e6a20c71a29abba3ca86bf

(this sample)

  
Delivery method
Distributed via web download

Comments