MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2ac6936670f5cb962b45c4487de2b0d20034afd38a8038c9465425dc96f10a61. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 2ac6936670f5cb962b45c4487de2b0d20034afd38a8038c9465425dc96f10a61
SHA3-384 hash: 13e2795ea354e8187b1869c1fbbe15ad738115670e420fc187a6eacdbba814b7fa730fdd7c915eae8c801585fc17de83
SHA1 hash: 5e9d00465e5edd60677440c020f59fbb92b4d199
MD5 hash: a1cf0e091c3754bcebe1ae87a82b32e1
humanhash: september-carbon-princess-uniform
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-17 08:19:08 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:zFcuQpWx+BL0SWL0g6zsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:zF8i+BL0SI0tzsP4cbddr7zsP4cbddrk
TLSH T180925DB512896C79FBD0CE39AF3C7F4DADE8C2C42124A3ACBA4F39215A1166DC705359
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
103
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=49a440ad-1600-0000-8101-baec800c0000 pid=3200 /usr/bin/sudo guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201 /tmp/sample.bin guuid=49a440ad-1600-0000-8101-baec800c0000 pid=3200->guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201 execve guuid=680852b0-1600-0000-8101-baec820c0000 pid=3202 /usr/bin/bash guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=680852b0-1600-0000-8101-baec820c0000 pid=3202 clone guuid=add161b0-1600-0000-8101-baec830c0000 pid=3203 /usr/bin/bash guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=add161b0-1600-0000-8101-baec830c0000 pid=3203 clone guuid=90baa5b0-1600-0000-8101-baec840c0000 pid=3204 /usr/bin/mkdir guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=90baa5b0-1600-0000-8101-baec840c0000 pid=3204 execve guuid=f3812db1-1600-0000-8101-baec850c0000 pid=3205 /usr/bin/mkdir guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=f3812db1-1600-0000-8101-baec850c0000 pid=3205 execve guuid=327bcbb1-1600-0000-8101-baec860c0000 pid=3206 /usr/bin/mkdir guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=327bcbb1-1600-0000-8101-baec860c0000 pid=3206 execve guuid=c4364bb2-1600-0000-8101-baec870c0000 pid=3207 /usr/bin/mkdir guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=c4364bb2-1600-0000-8101-baec870c0000 pid=3207 execve guuid=8cc5cfb2-1600-0000-8101-baec880c0000 pid=3208 /usr/bin/mkdir guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=8cc5cfb2-1600-0000-8101-baec880c0000 pid=3208 execve guuid=2aaa4cb3-1600-0000-8101-baec890c0000 pid=3209 /usr/bin/mkdir guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=2aaa4cb3-1600-0000-8101-baec890c0000 pid=3209 execve guuid=5291c0b3-1600-0000-8101-baec8a0c0000 pid=3210 /usr/bin/mkdir guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=5291c0b3-1600-0000-8101-baec8a0c0000 pid=3210 execve guuid=a4f830b4-1600-0000-8101-baec8b0c0000 pid=3211 /usr/bin/cp guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=a4f830b4-1600-0000-8101-baec8b0c0000 pid=3211 execve guuid=edadaab4-1600-0000-8101-baec8c0c0000 pid=3212 /usr/bin/cp guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=edadaab4-1600-0000-8101-baec8c0c0000 pid=3212 execve guuid=cb7a7eb5-1600-0000-8101-baec8d0c0000 pid=3213 /usr/bin/cp guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=cb7a7eb5-1600-0000-8101-baec8d0c0000 pid=3213 execve guuid=4a9efab5-1600-0000-8101-baec8e0c0000 pid=3214 /usr/bin/cp guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=4a9efab5-1600-0000-8101-baec8e0c0000 pid=3214 execve guuid=4d9d77b6-1600-0000-8101-baec8f0c0000 pid=3215 /usr/bin/cp guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=4d9d77b6-1600-0000-8101-baec8f0c0000 pid=3215 execve guuid=6b70f1b6-1600-0000-8101-baec900c0000 pid=3216 /usr/bin/cp guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=6b70f1b6-1600-0000-8101-baec900c0000 pid=3216 execve guuid=48a15ab7-1600-0000-8101-baec920c0000 pid=3218 /usr/bin/cp guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=48a15ab7-1600-0000-8101-baec920c0000 pid=3218 execve guuid=6557deb7-1600-0000-8101-baec930c0000 pid=3219 /usr/bin/cp guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=6557deb7-1600-0000-8101-baec930c0000 pid=3219 execve guuid=ebca4bb8-1600-0000-8101-baec940c0000 pid=3220 /usr/bin/cp guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=ebca4bb8-1600-0000-8101-baec940c0000 pid=3220 execve guuid=d854dfb8-1600-0000-8101-baec960c0000 pid=3222 /usr/bin/cp guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=d854dfb8-1600-0000-8101-baec960c0000 pid=3222 execve guuid=b03132b9-1600-0000-8101-baec990c0000 pid=3225 /usr/bin/cp guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=b03132b9-1600-0000-8101-baec990c0000 pid=3225 execve guuid=b0af82b9-1600-0000-8101-baec9b0c0000 pid=3227 /usr/bin/cp guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=b0af82b9-1600-0000-8101-baec9b0c0000 pid=3227 execve guuid=d658d6b9-1600-0000-8101-baec9d0c0000 pid=3229 /usr/bin/cp guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=d658d6b9-1600-0000-8101-baec9d0c0000 pid=3229 execve guuid=6ee838ba-1600-0000-8101-baec9f0c0000 pid=3231 /usr/bin/cp guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=6ee838ba-1600-0000-8101-baec9f0c0000 pid=3231 execve guuid=2ddcb3ba-1600-0000-8101-baeca00c0000 pid=3232 /usr/bin/cp guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=2ddcb3ba-1600-0000-8101-baeca00c0000 pid=3232 execve guuid=979c34bb-1600-0000-8101-baeca20c0000 pid=3234 /usr/bin/touch guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=979c34bb-1600-0000-8101-baeca20c0000 pid=3234 execve guuid=8b7f73bb-1600-0000-8101-baeca30c0000 pid=3235 /usr/bin/bash guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=8b7f73bb-1600-0000-8101-baeca30c0000 pid=3235 clone guuid=82de7bbb-1600-0000-8101-baeca40c0000 pid=3236 /usr/bin/bash guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=82de7bbb-1600-0000-8101-baeca40c0000 pid=3236 clone guuid=7b5fa2bb-1600-0000-8101-baeca50c0000 pid=3237 /usr/bin/bash guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=7b5fa2bb-1600-0000-8101-baeca50c0000 pid=3237 clone guuid=e1daaabb-1600-0000-8101-baeca60c0000 pid=3238 /usr/bin/base64 write-file guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=e1daaabb-1600-0000-8101-baeca60c0000 pid=3238 execve guuid=4b8b51bc-1600-0000-8101-baeca70c0000 pid=3239 /usr/bin/bash guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=4b8b51bc-1600-0000-8101-baeca70c0000 pid=3239 execve guuid=087ea7c1-1600-0000-8101-baecbf0c0000 pid=3263 /usr/bin/rm delete-file guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=087ea7c1-1600-0000-8101-baecbf0c0000 pid=3263 execve guuid=b1bde7c1-1600-0000-8101-baecc20c0000 pid=3266 /usr/bin/bash guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=b1bde7c1-1600-0000-8101-baecc20c0000 pid=3266 clone guuid=fcb8eec1-1600-0000-8101-baecc30c0000 pid=3267 /usr/bin/bash guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=fcb8eec1-1600-0000-8101-baecc30c0000 pid=3267 clone guuid=d80e0bc2-1600-0000-8101-baecc40c0000 pid=3268 /usr/bin/bash guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=d80e0bc2-1600-0000-8101-baecc40c0000 pid=3268 execve guuid=27c854c2-1600-0000-8101-baecc60c0000 pid=3270 /usr/bin/rm guuid=79b583af-1600-0000-8101-baec810c0000 pid=3201->guuid=27c854c2-1600-0000-8101-baecc60c0000 pid=3270 execve guuid=2e89afbc-1600-0000-8101-baeca80c0000 pid=3240 /usr/bin/bash guuid=4b8b51bc-1600-0000-8101-baeca70c0000 pid=3239->guuid=2e89afbc-1600-0000-8101-baeca80c0000 pid=3240 clone guuid=96b5b5bc-1600-0000-8101-baecaa0c0000 pid=3242 /usr/bin/bash guuid=4b8b51bc-1600-0000-8101-baeca70c0000 pid=3239->guuid=96b5b5bc-1600-0000-8101-baecaa0c0000 pid=3242 clone guuid=ed5cd2bc-1600-0000-8101-baecab0c0000 pid=3243 /usr/bin/ls guuid=4b8b51bc-1600-0000-8101-baeca70c0000 pid=3239->guuid=ed5cd2bc-1600-0000-8101-baecab0c0000 pid=3243 execve guuid=f9f030bd-1600-0000-8101-baecae0c0000 pid=3246 /usr/bin/cat guuid=4b8b51bc-1600-0000-8101-baeca70c0000 pid=3239->guuid=f9f030bd-1600-0000-8101-baecae0c0000 pid=3246 execve guuid=3005c3bd-1600-0000-8101-baecb10c0000 pid=3249 /usr/bin/ls guuid=4b8b51bc-1600-0000-8101-baeca70c0000 pid=3239->guuid=3005c3bd-1600-0000-8101-baecb10c0000 pid=3249 execve guuid=eec234be-1600-0000-8101-baecb20c0000 pid=3250 /usr/bin/mkdir guuid=4b8b51bc-1600-0000-8101-baeca70c0000 pid=3239->guuid=eec234be-1600-0000-8101-baecb20c0000 pid=3250 execve guuid=094f8abe-1600-0000-8101-baecb40c0000 pid=3252 /usr/bin/mv guuid=4b8b51bc-1600-0000-8101-baeca70c0000 pid=3239->guuid=094f8abe-1600-0000-8101-baecb40c0000 pid=3252 execve guuid=b73b03bf-1600-0000-8101-baecb50c0000 pid=3253 /usr/bin/bash guuid=4b8b51bc-1600-0000-8101-baeca70c0000 pid=3239->guuid=b73b03bf-1600-0000-8101-baecb50c0000 pid=3253 clone guuid=e03d0abf-1600-0000-8101-baecb60c0000 pid=3254 /usr/bin/base64 write-file guuid=4b8b51bc-1600-0000-8101-baeca70c0000 pid=3239->guuid=e03d0abf-1600-0000-8101-baecb60c0000 pid=3254 execve guuid=b92663bf-1600-0000-8101-baecb70c0000 pid=3255 /usr/bin/rm delete-file guuid=4b8b51bc-1600-0000-8101-baeca70c0000 pid=3239->guuid=b92663bf-1600-0000-8101-baecb70c0000 pid=3255 execve guuid=0b8bb6bf-1600-0000-8101-baecb80c0000 pid=3256 /usr/bin/ls guuid=4b8b51bc-1600-0000-8101-baeca70c0000 pid=3239->guuid=0b8bb6bf-1600-0000-8101-baecb80c0000 pid=3256 execve guuid=189621c0-1600-0000-8101-baecb90c0000 pid=3257 /usr/bin/bash guuid=4b8b51bc-1600-0000-8101-baeca70c0000 pid=3239->guuid=189621c0-1600-0000-8101-baecb90c0000 pid=3257 clone guuid=543a29c0-1600-0000-8101-baecba0c0000 pid=3258 /usr/bin/base64 write-file guuid=4b8b51bc-1600-0000-8101-baeca70c0000 pid=3239->guuid=543a29c0-1600-0000-8101-baecba0c0000 pid=3258 execve guuid=595d6dc0-1600-0000-8101-baecbc0c0000 pid=3260 /usr/bin/ls guuid=4b8b51bc-1600-0000-8101-baeca70c0000 pid=3239->guuid=595d6dc0-1600-0000-8101-baecbc0c0000 pid=3260 execve guuid=a46ae4c0-1600-0000-8101-baecbd0c0000 pid=3261 /usr/bin/cat guuid=4b8b51bc-1600-0000-8101-baeca70c0000 pid=3239->guuid=a46ae4c0-1600-0000-8101-baecbd0c0000 pid=3261 execve guuid=b4682fc1-1600-0000-8101-baecbe0c0000 pid=3262 /usr/bin/ls guuid=4b8b51bc-1600-0000-8101-baeca70c0000 pid=3239->guuid=b4682fc1-1600-0000-8101-baecbe0c0000 pid=3262 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-17 08:20:49 UTC
File Type:
Text (Shell)
AV detection:
12 of 22 (54.55%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 2ac6936670f5cb962b45c4487de2b0d20034afd38a8038c9465425dc96f10a61

(this sample)

  
Delivery method
Distributed via web download

Comments