MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 22c7580541af6902f4af5e44a1fca89ca0a8c172f6e386fc39f96ca4af81fa43. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 22c7580541af6902f4af5e44a1fca89ca0a8c172f6e386fc39f96ca4af81fa43
SHA3-384 hash: ceb4308b93e797153947f0e6ec21e04f5fd66a0fa11ba89235c658c403ec70da9aa7a7a935fd3a03f266f7ee25013e57
SHA1 hash: 3e66d7cd3f6db2add822de542cb19803b29ad56b
MD5 hash: c1852e25c07c758fb23388f7db07bb2f
humanhash: eleven-cola-steak-november
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-10 14:57:19 UTC
Last seen:2026-03-11 11:15:53 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 384:oScuQpWx+BL0SWL0gazsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:oS8i+BL0SI0xzsP4cbddr7zsP4cbddrk
TLSH T1D4925CB512496D79FBD1CE39AF3C6F4CADE8C2C42124A3ACBA4F39215A1166DC70534D
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
2
# of downloads :
48
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=0d984335-1700-0000-92eb-0ca2c00d0000 pid=3520 /usr/bin/sudo guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526 /tmp/sample.bin guuid=0d984335-1700-0000-92eb-0ca2c00d0000 pid=3520->guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526 execve guuid=169cf237-1700-0000-92eb-0ca2c80d0000 pid=3528 /usr/bin/bash guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=169cf237-1700-0000-92eb-0ca2c80d0000 pid=3528 clone guuid=89bcf837-1700-0000-92eb-0ca2c90d0000 pid=3529 /usr/bin/bash guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=89bcf837-1700-0000-92eb-0ca2c90d0000 pid=3529 clone guuid=01c51a38-1700-0000-92eb-0ca2cb0d0000 pid=3531 /usr/bin/mkdir guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=01c51a38-1700-0000-92eb-0ca2cb0d0000 pid=3531 execve guuid=19417138-1700-0000-92eb-0ca2cd0d0000 pid=3533 /usr/bin/mkdir guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=19417138-1700-0000-92eb-0ca2cd0d0000 pid=3533 execve guuid=c8febe38-1700-0000-92eb-0ca2cf0d0000 pid=3535 /usr/bin/mkdir guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=c8febe38-1700-0000-92eb-0ca2cf0d0000 pid=3535 execve guuid=5cc70b39-1700-0000-92eb-0ca2d10d0000 pid=3537 /usr/bin/mkdir guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=5cc70b39-1700-0000-92eb-0ca2d10d0000 pid=3537 execve guuid=8f636639-1700-0000-92eb-0ca2d30d0000 pid=3539 /usr/bin/mkdir guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=8f636639-1700-0000-92eb-0ca2d30d0000 pid=3539 execve guuid=f112b639-1700-0000-92eb-0ca2d60d0000 pid=3542 /usr/bin/mkdir guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=f112b639-1700-0000-92eb-0ca2d60d0000 pid=3542 execve guuid=e90c073a-1700-0000-92eb-0ca2d80d0000 pid=3544 /usr/bin/mkdir guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=e90c073a-1700-0000-92eb-0ca2d80d0000 pid=3544 execve guuid=76f75b3a-1700-0000-92eb-0ca2da0d0000 pid=3546 /usr/bin/cp guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=76f75b3a-1700-0000-92eb-0ca2da0d0000 pid=3546 execve guuid=8b83bf3a-1700-0000-92eb-0ca2dc0d0000 pid=3548 /usr/bin/cp guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=8b83bf3a-1700-0000-92eb-0ca2dc0d0000 pid=3548 execve guuid=5b6e193b-1700-0000-92eb-0ca2df0d0000 pid=3551 /usr/bin/cp guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=5b6e193b-1700-0000-92eb-0ca2df0d0000 pid=3551 execve guuid=6c33783b-1700-0000-92eb-0ca2e10d0000 pid=3553 /usr/bin/cp guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=6c33783b-1700-0000-92eb-0ca2e10d0000 pid=3553 execve guuid=5fddd13b-1700-0000-92eb-0ca2e40d0000 pid=3556 /usr/bin/cp guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=5fddd13b-1700-0000-92eb-0ca2e40d0000 pid=3556 execve guuid=a5e32f3c-1700-0000-92eb-0ca2e60d0000 pid=3558 /usr/bin/cp guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=a5e32f3c-1700-0000-92eb-0ca2e60d0000 pid=3558 execve guuid=ebcc7f3c-1700-0000-92eb-0ca2e80d0000 pid=3560 /usr/bin/cp guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=ebcc7f3c-1700-0000-92eb-0ca2e80d0000 pid=3560 execve guuid=277fda3c-1700-0000-92eb-0ca2eb0d0000 pid=3563 /usr/bin/cp guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=277fda3c-1700-0000-92eb-0ca2eb0d0000 pid=3563 execve guuid=0ff72b3d-1700-0000-92eb-0ca2ed0d0000 pid=3565 /usr/bin/cp guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=0ff72b3d-1700-0000-92eb-0ca2ed0d0000 pid=3565 execve guuid=cfb9773d-1700-0000-92eb-0ca2f00d0000 pid=3568 /usr/bin/cp guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=cfb9773d-1700-0000-92eb-0ca2f00d0000 pid=3568 execve guuid=dcf7cb3d-1700-0000-92eb-0ca2f20d0000 pid=3570 /usr/bin/cp guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=dcf7cb3d-1700-0000-92eb-0ca2f20d0000 pid=3570 execve guuid=4d511c3e-1700-0000-92eb-0ca2f40d0000 pid=3572 /usr/bin/cp guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=4d511c3e-1700-0000-92eb-0ca2f40d0000 pid=3572 execve guuid=dc98803e-1700-0000-92eb-0ca2f90d0000 pid=3577 /usr/bin/cp guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=dc98803e-1700-0000-92eb-0ca2f90d0000 pid=3577 execve guuid=4fa7d03e-1700-0000-92eb-0ca2fb0d0000 pid=3579 /usr/bin/cp guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=4fa7d03e-1700-0000-92eb-0ca2fb0d0000 pid=3579 execve guuid=48b4223f-1700-0000-92eb-0ca2fd0d0000 pid=3581 /usr/bin/cp guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=48b4223f-1700-0000-92eb-0ca2fd0d0000 pid=3581 execve guuid=02c07e3f-1700-0000-92eb-0ca2fe0d0000 pid=3582 /usr/bin/touch guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=02c07e3f-1700-0000-92eb-0ca2fe0d0000 pid=3582 execve guuid=bc2bbb3f-1700-0000-92eb-0ca2000e0000 pid=3584 /usr/bin/bash guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=bc2bbb3f-1700-0000-92eb-0ca2000e0000 pid=3584 clone guuid=f65dc13f-1700-0000-92eb-0ca2010e0000 pid=3585 /usr/bin/bash guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=f65dc13f-1700-0000-92eb-0ca2010e0000 pid=3585 clone guuid=cfd2df3f-1700-0000-92eb-0ca2030e0000 pid=3587 /usr/bin/bash guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=cfd2df3f-1700-0000-92eb-0ca2030e0000 pid=3587 clone guuid=7773e73f-1700-0000-92eb-0ca2040e0000 pid=3588 /usr/bin/base64 write-file guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=7773e73f-1700-0000-92eb-0ca2040e0000 pid=3588 execve guuid=61486640-1700-0000-92eb-0ca2070e0000 pid=3591 /usr/bin/bash guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=61486640-1700-0000-92eb-0ca2070e0000 pid=3591 execve guuid=dce61f45-1700-0000-92eb-0ca2270e0000 pid=3623 /usr/bin/rm delete-file guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=dce61f45-1700-0000-92eb-0ca2270e0000 pid=3623 execve guuid=d9086445-1700-0000-92eb-0ca2290e0000 pid=3625 /usr/bin/bash guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=d9086445-1700-0000-92eb-0ca2290e0000 pid=3625 clone guuid=8e6c6a45-1700-0000-92eb-0ca22a0e0000 pid=3626 /usr/bin/bash guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=8e6c6a45-1700-0000-92eb-0ca22a0e0000 pid=3626 clone guuid=04ac8345-1700-0000-92eb-0ca22b0e0000 pid=3627 /usr/bin/bash guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=04ac8345-1700-0000-92eb-0ca22b0e0000 pid=3627 execve guuid=1b85c945-1700-0000-92eb-0ca22e0e0000 pid=3630 /usr/bin/rm guuid=236b9c37-1700-0000-92eb-0ca2c60d0000 pid=3526->guuid=1b85c945-1700-0000-92eb-0ca22e0e0000 pid=3630 execve guuid=5ea3b740-1700-0000-92eb-0ca2090e0000 pid=3593 /usr/bin/bash guuid=61486640-1700-0000-92eb-0ca2070e0000 pid=3591->guuid=5ea3b740-1700-0000-92eb-0ca2090e0000 pid=3593 clone guuid=5ca9bd40-1700-0000-92eb-0ca20a0e0000 pid=3594 /usr/bin/bash guuid=61486640-1700-0000-92eb-0ca2070e0000 pid=3591->guuid=5ca9bd40-1700-0000-92eb-0ca20a0e0000 pid=3594 clone guuid=de55e240-1700-0000-92eb-0ca20b0e0000 pid=3595 /usr/bin/ls guuid=61486640-1700-0000-92eb-0ca2070e0000 pid=3591->guuid=de55e240-1700-0000-92eb-0ca20b0e0000 pid=3595 execve guuid=f2775b41-1700-0000-92eb-0ca20e0e0000 pid=3598 /usr/bin/cat guuid=61486640-1700-0000-92eb-0ca2070e0000 pid=3591->guuid=f2775b41-1700-0000-92eb-0ca20e0e0000 pid=3598 execve guuid=16ea9741-1700-0000-92eb-0ca2100e0000 pid=3600 /usr/bin/ls guuid=61486640-1700-0000-92eb-0ca2070e0000 pid=3591->guuid=16ea9741-1700-0000-92eb-0ca2100e0000 pid=3600 execve guuid=5ecbfe41-1700-0000-92eb-0ca2110e0000 pid=3601 /usr/bin/mkdir guuid=61486640-1700-0000-92eb-0ca2070e0000 pid=3591->guuid=5ecbfe41-1700-0000-92eb-0ca2110e0000 pid=3601 execve guuid=61fe5442-1700-0000-92eb-0ca2140e0000 pid=3604 /usr/bin/mv guuid=61486640-1700-0000-92eb-0ca2070e0000 pid=3591->guuid=61fe5442-1700-0000-92eb-0ca2140e0000 pid=3604 execve guuid=4488b042-1700-0000-92eb-0ca2160e0000 pid=3606 /usr/bin/bash guuid=61486640-1700-0000-92eb-0ca2070e0000 pid=3591->guuid=4488b042-1700-0000-92eb-0ca2160e0000 pid=3606 clone guuid=3830b842-1700-0000-92eb-0ca2170e0000 pid=3607 /usr/bin/base64 write-file guuid=61486640-1700-0000-92eb-0ca2070e0000 pid=3591->guuid=3830b842-1700-0000-92eb-0ca2170e0000 pid=3607 execve guuid=fbdb0a43-1700-0000-92eb-0ca2190e0000 pid=3609 /usr/bin/rm delete-file guuid=61486640-1700-0000-92eb-0ca2070e0000 pid=3591->guuid=fbdb0a43-1700-0000-92eb-0ca2190e0000 pid=3609 execve guuid=784f4f43-1700-0000-92eb-0ca21b0e0000 pid=3611 /usr/bin/ls guuid=61486640-1700-0000-92eb-0ca2070e0000 pid=3591->guuid=784f4f43-1700-0000-92eb-0ca21b0e0000 pid=3611 execve guuid=3779b043-1700-0000-92eb-0ca21d0e0000 pid=3613 /usr/bin/bash guuid=61486640-1700-0000-92eb-0ca2070e0000 pid=3591->guuid=3779b043-1700-0000-92eb-0ca21d0e0000 pid=3613 clone guuid=064eb843-1700-0000-92eb-0ca21e0e0000 pid=3614 /usr/bin/base64 write-file guuid=61486640-1700-0000-92eb-0ca2070e0000 pid=3591->guuid=064eb843-1700-0000-92eb-0ca21e0e0000 pid=3614 execve guuid=4a990a44-1700-0000-92eb-0ca2200e0000 pid=3616 /usr/bin/ls guuid=61486640-1700-0000-92eb-0ca2070e0000 pid=3591->guuid=4a990a44-1700-0000-92eb-0ca2200e0000 pid=3616 execve guuid=10877444-1700-0000-92eb-0ca2230e0000 pid=3619 /usr/bin/cat guuid=61486640-1700-0000-92eb-0ca2070e0000 pid=3591->guuid=10877444-1700-0000-92eb-0ca2230e0000 pid=3619 execve guuid=e38cb744-1700-0000-92eb-0ca2250e0000 pid=3621 /usr/bin/ls guuid=61486640-1700-0000-92eb-0ca2070e0000 pid=3591->guuid=e38cb744-1700-0000-92eb-0ca2250e0000 pid=3621 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-10 14:58:15 UTC
File Type:
Text (Shell)
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 22c7580541af6902f4af5e44a1fca89ca0a8c172f6e386fc39f96ca4af81fa43

(this sample)

  
Delivery method
Distributed via web download

Comments