MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 21475c8a690e49e9a7ac6dd4b96621d9c0536a75403d1187cdbd4af1e7c681c2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 21475c8a690e49e9a7ac6dd4b96621d9c0536a75403d1187cdbd4af1e7c681c2
SHA3-384 hash: 2c188e690de06d2e291a6e51a22f74699c85a3c79dd2900ef6a04c42d37091a466e86e68b8202c52e5ae253b7da2dcf4
SHA1 hash: ee389eb3c77f260a4d111f9e1d1a0be842fa7be6
MD5 hash: 983af7cffddb7b15d1db00124828b9e5
humanhash: lemon-muppet-island-oven
File name:k.php
Download: download sample
File size:19'491 bytes
First seen:2026-03-17 15:28:58 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:4OncuxOLnVYMSezsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:4tuQL+ezsP4cbddr7zsP4cbddrk
TLSH T173924CB506496C79BBC0CE799F3C7F0CAEE582C42128E39DBA1F39705A2166DC609359
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=8d505119-1700-0000-957a-5f0e3d0d0000 pid=3389 /usr/bin/sudo guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397 /tmp/sample.bin guuid=8d505119-1700-0000-957a-5f0e3d0d0000 pid=3389->guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397 execve guuid=97e0b31b-1700-0000-957a-5f0e480d0000 pid=3400 /usr/bin/bash guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=97e0b31b-1700-0000-957a-5f0e480d0000 pid=3400 clone guuid=77a7ba1b-1700-0000-957a-5f0e490d0000 pid=3401 /usr/bin/bash guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=77a7ba1b-1700-0000-957a-5f0e490d0000 pid=3401 clone guuid=ef34d21b-1700-0000-957a-5f0e4a0d0000 pid=3402 /usr/bin/mkdir guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=ef34d21b-1700-0000-957a-5f0e4a0d0000 pid=3402 execve guuid=1516191c-1700-0000-957a-5f0e4d0d0000 pid=3405 /usr/bin/mkdir guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=1516191c-1700-0000-957a-5f0e4d0d0000 pid=3405 execve guuid=c864601c-1700-0000-957a-5f0e4f0d0000 pid=3407 /usr/bin/mkdir guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=c864601c-1700-0000-957a-5f0e4f0d0000 pid=3407 execve guuid=bdffad1c-1700-0000-957a-5f0e510d0000 pid=3409 /usr/bin/mkdir guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=bdffad1c-1700-0000-957a-5f0e510d0000 pid=3409 execve guuid=6a3ffa1c-1700-0000-957a-5f0e530d0000 pid=3411 /usr/bin/mkdir guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=6a3ffa1c-1700-0000-957a-5f0e530d0000 pid=3411 execve guuid=5bce471d-1700-0000-957a-5f0e550d0000 pid=3413 /usr/bin/mkdir guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=5bce471d-1700-0000-957a-5f0e550d0000 pid=3413 execve guuid=c7e3921d-1700-0000-957a-5f0e570d0000 pid=3415 /usr/bin/mkdir guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=c7e3921d-1700-0000-957a-5f0e570d0000 pid=3415 execve guuid=ba6fe21d-1700-0000-957a-5f0e5a0d0000 pid=3418 /usr/bin/cp guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=ba6fe21d-1700-0000-957a-5f0e5a0d0000 pid=3418 execve guuid=bcf23e1e-1700-0000-957a-5f0e5c0d0000 pid=3420 /usr/bin/cp guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=bcf23e1e-1700-0000-957a-5f0e5c0d0000 pid=3420 execve guuid=253e961e-1700-0000-957a-5f0e5e0d0000 pid=3422 /usr/bin/cp guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=253e961e-1700-0000-957a-5f0e5e0d0000 pid=3422 execve guuid=7cdeec1e-1700-0000-957a-5f0e610d0000 pid=3425 /usr/bin/cp guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=7cdeec1e-1700-0000-957a-5f0e610d0000 pid=3425 execve guuid=5049451f-1700-0000-957a-5f0e630d0000 pid=3427 /usr/bin/cp guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=5049451f-1700-0000-957a-5f0e630d0000 pid=3427 execve guuid=4dbe9c1f-1700-0000-957a-5f0e660d0000 pid=3430 /usr/bin/cp guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=4dbe9c1f-1700-0000-957a-5f0e660d0000 pid=3430 execve guuid=11b6f61f-1700-0000-957a-5f0e680d0000 pid=3432 /usr/bin/cp guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=11b6f61f-1700-0000-957a-5f0e680d0000 pid=3432 execve guuid=f9535320-1700-0000-957a-5f0e6a0d0000 pid=3434 /usr/bin/cp guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=f9535320-1700-0000-957a-5f0e6a0d0000 pid=3434 execve guuid=3fabb520-1700-0000-957a-5f0e6d0d0000 pid=3437 /usr/bin/cp guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=3fabb520-1700-0000-957a-5f0e6d0d0000 pid=3437 execve guuid=81561021-1700-0000-957a-5f0e6f0d0000 pid=3439 /usr/bin/cp guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=81561021-1700-0000-957a-5f0e6f0d0000 pid=3439 execve guuid=f9066821-1700-0000-957a-5f0e720d0000 pid=3442 /usr/bin/cp guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=f9066821-1700-0000-957a-5f0e720d0000 pid=3442 execve guuid=d431c621-1700-0000-957a-5f0e740d0000 pid=3444 /usr/bin/cp guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=d431c621-1700-0000-957a-5f0e740d0000 pid=3444 execve guuid=f1b12222-1700-0000-957a-5f0e770d0000 pid=3447 /usr/bin/cp guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=f1b12222-1700-0000-957a-5f0e770d0000 pid=3447 execve guuid=ef4a7522-1700-0000-957a-5f0e790d0000 pid=3449 /usr/bin/cp guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=ef4a7522-1700-0000-957a-5f0e790d0000 pid=3449 execve guuid=eeafc222-1700-0000-957a-5f0e7b0d0000 pid=3451 /usr/bin/cp guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=eeafc222-1700-0000-957a-5f0e7b0d0000 pid=3451 execve guuid=798e1e23-1700-0000-957a-5f0e7e0d0000 pid=3454 /usr/bin/touch guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=798e1e23-1700-0000-957a-5f0e7e0d0000 pid=3454 execve guuid=5b5a5a23-1700-0000-957a-5f0e800d0000 pid=3456 /usr/bin/bash guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=5b5a5a23-1700-0000-957a-5f0e800d0000 pid=3456 clone guuid=6a505f23-1700-0000-957a-5f0e810d0000 pid=3457 /usr/bin/bash guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=6a505f23-1700-0000-957a-5f0e810d0000 pid=3457 clone guuid=de537523-1700-0000-957a-5f0e820d0000 pid=3458 /usr/bin/bash guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=de537523-1700-0000-957a-5f0e820d0000 pid=3458 clone guuid=84817b23-1700-0000-957a-5f0e830d0000 pid=3459 /usr/bin/base64 write-file guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=84817b23-1700-0000-957a-5f0e830d0000 pid=3459 execve guuid=833eeb23-1700-0000-957a-5f0e860d0000 pid=3462 /usr/bin/bash guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=833eeb23-1700-0000-957a-5f0e860d0000 pid=3462 execve guuid=e7bc2a28-1700-0000-957a-5f0ea90d0000 pid=3497 /usr/bin/rm delete-file guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=e7bc2a28-1700-0000-957a-5f0ea90d0000 pid=3497 execve guuid=7d097028-1700-0000-957a-5f0eab0d0000 pid=3499 /usr/bin/bash guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=7d097028-1700-0000-957a-5f0eab0d0000 pid=3499 clone guuid=499b7628-1700-0000-957a-5f0eac0d0000 pid=3500 /usr/bin/bash guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=499b7628-1700-0000-957a-5f0eac0d0000 pid=3500 clone guuid=eef99a28-1700-0000-957a-5f0eae0d0000 pid=3502 /usr/bin/bash guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=eef99a28-1700-0000-957a-5f0eae0d0000 pid=3502 execve guuid=0647eb28-1700-0000-957a-5f0eb00d0000 pid=3504 /usr/bin/rm guuid=fb0d611b-1700-0000-957a-5f0e450d0000 pid=3397->guuid=0647eb28-1700-0000-957a-5f0eb00d0000 pid=3504 execve guuid=06d03324-1700-0000-957a-5f0e880d0000 pid=3464 /usr/bin/bash guuid=833eeb23-1700-0000-957a-5f0e860d0000 pid=3462->guuid=06d03324-1700-0000-957a-5f0e880d0000 pid=3464 clone guuid=b3183924-1700-0000-957a-5f0e8a0d0000 pid=3466 /usr/bin/bash guuid=833eeb23-1700-0000-957a-5f0e860d0000 pid=3462->guuid=b3183924-1700-0000-957a-5f0e8a0d0000 pid=3466 clone guuid=29a95324-1700-0000-957a-5f0e8b0d0000 pid=3467 /usr/bin/ls guuid=833eeb23-1700-0000-957a-5f0e860d0000 pid=3462->guuid=29a95324-1700-0000-957a-5f0e8b0d0000 pid=3467 execve guuid=4fa6b124-1700-0000-957a-5f0e8e0d0000 pid=3470 /usr/bin/cat guuid=833eeb23-1700-0000-957a-5f0e860d0000 pid=3462->guuid=4fa6b124-1700-0000-957a-5f0e8e0d0000 pid=3470 execve guuid=c304ec24-1700-0000-957a-5f0e900d0000 pid=3472 /usr/bin/ls guuid=833eeb23-1700-0000-957a-5f0e860d0000 pid=3462->guuid=c304ec24-1700-0000-957a-5f0e900d0000 pid=3472 execve guuid=58b34b25-1700-0000-957a-5f0e920d0000 pid=3474 /usr/bin/mkdir guuid=833eeb23-1700-0000-957a-5f0e860d0000 pid=3462->guuid=58b34b25-1700-0000-957a-5f0e920d0000 pid=3474 execve guuid=912c9125-1700-0000-957a-5f0e950d0000 pid=3477 /usr/bin/mv guuid=833eeb23-1700-0000-957a-5f0e860d0000 pid=3462->guuid=912c9125-1700-0000-957a-5f0e950d0000 pid=3477 execve guuid=4d18e325-1700-0000-957a-5f0e970d0000 pid=3479 /usr/bin/bash guuid=833eeb23-1700-0000-957a-5f0e860d0000 pid=3462->guuid=4d18e325-1700-0000-957a-5f0e970d0000 pid=3479 clone guuid=7f5bec25-1700-0000-957a-5f0e980d0000 pid=3480 /usr/bin/base64 write-file guuid=833eeb23-1700-0000-957a-5f0e860d0000 pid=3462->guuid=7f5bec25-1700-0000-957a-5f0e980d0000 pid=3480 execve guuid=7ea83226-1700-0000-957a-5f0e9a0d0000 pid=3482 /usr/bin/rm delete-file guuid=833eeb23-1700-0000-957a-5f0e860d0000 pid=3462->guuid=7ea83226-1700-0000-957a-5f0e9a0d0000 pid=3482 execve guuid=dee37526-1700-0000-957a-5f0e9c0d0000 pid=3484 /usr/bin/ls guuid=833eeb23-1700-0000-957a-5f0e860d0000 pid=3462->guuid=dee37526-1700-0000-957a-5f0e9c0d0000 pid=3484 execve guuid=d585d126-1700-0000-957a-5f0e9f0d0000 pid=3487 /usr/bin/bash guuid=833eeb23-1700-0000-957a-5f0e860d0000 pid=3462->guuid=d585d126-1700-0000-957a-5f0e9f0d0000 pid=3487 clone guuid=0897d626-1700-0000-957a-5f0ea00d0000 pid=3488 /usr/bin/base64 write-file guuid=833eeb23-1700-0000-957a-5f0e860d0000 pid=3462->guuid=0897d626-1700-0000-957a-5f0ea00d0000 pid=3488 execve guuid=04002027-1700-0000-957a-5f0ea20d0000 pid=3490 /usr/bin/ls guuid=833eeb23-1700-0000-957a-5f0e860d0000 pid=3462->guuid=04002027-1700-0000-957a-5f0ea20d0000 pid=3490 execve guuid=dcc57b27-1700-0000-957a-5f0ea40d0000 pid=3492 /usr/bin/cat guuid=833eeb23-1700-0000-957a-5f0e860d0000 pid=3462->guuid=dcc57b27-1700-0000-957a-5f0ea40d0000 pid=3492 execve guuid=72e5ba27-1700-0000-957a-5f0ea60d0000 pid=3494 /usr/bin/ls guuid=833eeb23-1700-0000-957a-5f0e860d0000 pid=3462->guuid=72e5ba27-1700-0000-957a-5f0ea60d0000 pid=3494 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-17 15:33:22 UTC
File Type:
Text (Shell)
AV detection:
10 of 22 (45.45%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 21475c8a690e49e9a7ac6dd4b96621d9c0536a75403d1187cdbd4af1e7c681c2

(this sample)

  
Delivery method
Distributed via web download

Comments