MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 309a02bf084c78dc98627209ab63cff1b436f42bcf083e712b780d4ba63bd0ba. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA 1 File information Comments

SHA256 hash: 309a02bf084c78dc98627209ab63cff1b436f42bcf083e712b780d4ba63bd0ba
SHA3-384 hash: bd13a5aaf98b7535768d5af63a0c57f7777f2edfa642eac48ccaa9df32e2e8bcba75637e487cde3f5d8f68569267ef12
SHA1 hash: 6627d21e7d13db56e4b83d09f2a3aed09369a61a
MD5 hash: f7543a2af2209c37a1ac7b746ab6b551
humanhash: winter-lemon-stream-twelve
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-24 03:48:19 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:mFcuQpWx+BL0SWL0gtzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:mF8i+BL0SI02zsP4cbddr7zsP4cbddrk
TLSH T146925DB512896C79FBD1CE39AF3C6F4CADE8C2C42124E3ACBA4F39205A1166DC705359
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Gathering data
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=d61d65ac-1a00-0000-251f-06be960a0000 pid=2710 /usr/bin/sudo guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718 /tmp/sample.bin guuid=d61d65ac-1a00-0000-251f-06be960a0000 pid=2710->guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718 execve guuid=b4ee63ae-1a00-0000-251f-06bea00a0000 pid=2720 /usr/bin/bash guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=b4ee63ae-1a00-0000-251f-06bea00a0000 pid=2720 clone guuid=720e6bae-1a00-0000-251f-06bea10a0000 pid=2721 /usr/bin/bash guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=720e6bae-1a00-0000-251f-06bea10a0000 pid=2721 clone guuid=e7b6a3ae-1a00-0000-251f-06bea30a0000 pid=2723 /usr/bin/mkdir guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=e7b6a3ae-1a00-0000-251f-06bea30a0000 pid=2723 execve guuid=08fbf2ae-1a00-0000-251f-06bea50a0000 pid=2725 /usr/bin/mkdir guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=08fbf2ae-1a00-0000-251f-06bea50a0000 pid=2725 execve guuid=4a5641af-1a00-0000-251f-06bea70a0000 pid=2727 /usr/bin/mkdir guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=4a5641af-1a00-0000-251f-06bea70a0000 pid=2727 execve guuid=a738b1af-1a00-0000-251f-06bea90a0000 pid=2729 /usr/bin/mkdir guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=a738b1af-1a00-0000-251f-06bea90a0000 pid=2729 execve guuid=652708b0-1a00-0000-251f-06beac0a0000 pid=2732 /usr/bin/mkdir guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=652708b0-1a00-0000-251f-06beac0a0000 pid=2732 execve guuid=c5076fb0-1a00-0000-251f-06beae0a0000 pid=2734 /usr/bin/mkdir guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=c5076fb0-1a00-0000-251f-06beae0a0000 pid=2734 execve guuid=5529ebb0-1a00-0000-251f-06beb00a0000 pid=2736 /usr/bin/mkdir guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=5529ebb0-1a00-0000-251f-06beb00a0000 pid=2736 execve guuid=186d45b1-1a00-0000-251f-06beb20a0000 pid=2738 /usr/bin/cp guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=186d45b1-1a00-0000-251f-06beb20a0000 pid=2738 execve guuid=8566a4b1-1a00-0000-251f-06beb40a0000 pid=2740 /usr/bin/cp guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=8566a4b1-1a00-0000-251f-06beb40a0000 pid=2740 execve guuid=862538b2-1a00-0000-251f-06beb60a0000 pid=2742 /usr/bin/cp guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=862538b2-1a00-0000-251f-06beb60a0000 pid=2742 execve guuid=273499b2-1a00-0000-251f-06beb80a0000 pid=2744 /usr/bin/cp guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=273499b2-1a00-0000-251f-06beb80a0000 pid=2744 execve guuid=a9370ab3-1a00-0000-251f-06beba0a0000 pid=2746 /usr/bin/cp guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=a9370ab3-1a00-0000-251f-06beba0a0000 pid=2746 execve guuid=ae4969b3-1a00-0000-251f-06bebb0a0000 pid=2747 /usr/bin/cp guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=ae4969b3-1a00-0000-251f-06bebb0a0000 pid=2747 execve guuid=bed830b4-1a00-0000-251f-06bebf0a0000 pid=2751 /usr/bin/cp guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=bed830b4-1a00-0000-251f-06bebf0a0000 pid=2751 execve guuid=db99d3b4-1a00-0000-251f-06bec00a0000 pid=2752 /usr/bin/cp guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=db99d3b4-1a00-0000-251f-06bec00a0000 pid=2752 execve guuid=2e6746b5-1a00-0000-251f-06bec20a0000 pid=2754 /usr/bin/cp guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=2e6746b5-1a00-0000-251f-06bec20a0000 pid=2754 execve guuid=e71bb0b5-1a00-0000-251f-06bec40a0000 pid=2756 /usr/bin/cp guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=e71bb0b5-1a00-0000-251f-06bec40a0000 pid=2756 execve guuid=a4b348b6-1a00-0000-251f-06bec80a0000 pid=2760 /usr/bin/cp guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=a4b348b6-1a00-0000-251f-06bec80a0000 pid=2760 execve guuid=1901d8b6-1a00-0000-251f-06becb0a0000 pid=2763 /usr/bin/cp guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=1901d8b6-1a00-0000-251f-06becb0a0000 pid=2763 execve guuid=0a8b63b7-1a00-0000-251f-06becd0a0000 pid=2765 /usr/bin/cp guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=0a8b63b7-1a00-0000-251f-06becd0a0000 pid=2765 execve guuid=1c84d1b7-1a00-0000-251f-06becf0a0000 pid=2767 /usr/bin/cp guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=1c84d1b7-1a00-0000-251f-06becf0a0000 pid=2767 execve guuid=100642b8-1a00-0000-251f-06bed10a0000 pid=2769 /usr/bin/cp guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=100642b8-1a00-0000-251f-06bed10a0000 pid=2769 execve guuid=1136c3b8-1a00-0000-251f-06bed20a0000 pid=2770 /usr/bin/touch guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=1136c3b8-1a00-0000-251f-06bed20a0000 pid=2770 execve guuid=0c0629b9-1a00-0000-251f-06bed40a0000 pid=2772 /usr/bin/bash guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=0c0629b9-1a00-0000-251f-06bed40a0000 pid=2772 clone guuid=dc5f36b9-1a00-0000-251f-06bed50a0000 pid=2773 /usr/bin/bash guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=dc5f36b9-1a00-0000-251f-06bed50a0000 pid=2773 clone guuid=a12962b9-1a00-0000-251f-06bed60a0000 pid=2774 /usr/bin/bash guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=a12962b9-1a00-0000-251f-06bed60a0000 pid=2774 clone guuid=d4c77cb9-1a00-0000-251f-06bed70a0000 pid=2775 /usr/bin/base64 write-file guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=d4c77cb9-1a00-0000-251f-06bed70a0000 pid=2775 execve guuid=f4bf2bba-1a00-0000-251f-06bed80a0000 pid=2776 /usr/bin/bash guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=f4bf2bba-1a00-0000-251f-06bed80a0000 pid=2776 execve guuid=c0be1fc0-1a00-0000-251f-06bef30a0000 pid=2803 /usr/bin/rm delete-file guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=c0be1fc0-1a00-0000-251f-06bef30a0000 pid=2803 execve guuid=09f08bc0-1a00-0000-251f-06bef50a0000 pid=2805 /usr/bin/bash guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=09f08bc0-1a00-0000-251f-06bef50a0000 pid=2805 clone guuid=86f79ac0-1a00-0000-251f-06bef60a0000 pid=2806 /usr/bin/bash guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=86f79ac0-1a00-0000-251f-06bef60a0000 pid=2806 clone guuid=c84dc9c0-1a00-0000-251f-06bef80a0000 pid=2808 /usr/bin/bash guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=c84dc9c0-1a00-0000-251f-06bef80a0000 pid=2808 execve guuid=0bf94fc1-1a00-0000-251f-06befa0a0000 pid=2810 /usr/bin/rm guuid=bf390eae-1a00-0000-251f-06be9e0a0000 pid=2718->guuid=0bf94fc1-1a00-0000-251f-06befa0a0000 pid=2810 execve guuid=769094ba-1a00-0000-251f-06bed90a0000 pid=2777 /usr/bin/bash guuid=f4bf2bba-1a00-0000-251f-06bed80a0000 pid=2776->guuid=769094ba-1a00-0000-251f-06bed90a0000 pid=2777 clone guuid=8a5a9bba-1a00-0000-251f-06beda0a0000 pid=2778 /usr/bin/bash guuid=f4bf2bba-1a00-0000-251f-06bed80a0000 pid=2776->guuid=8a5a9bba-1a00-0000-251f-06beda0a0000 pid=2778 clone guuid=4155c3ba-1a00-0000-251f-06bedc0a0000 pid=2780 /usr/bin/ls guuid=f4bf2bba-1a00-0000-251f-06bed80a0000 pid=2776->guuid=4155c3ba-1a00-0000-251f-06bedc0a0000 pid=2780 execve guuid=e06e7abb-1a00-0000-251f-06bedf0a0000 pid=2783 /usr/bin/cat guuid=f4bf2bba-1a00-0000-251f-06bed80a0000 pid=2776->guuid=e06e7abb-1a00-0000-251f-06bedf0a0000 pid=2783 execve guuid=bac9d4bb-1a00-0000-251f-06bee20a0000 pid=2786 /usr/bin/ls guuid=f4bf2bba-1a00-0000-251f-06bed80a0000 pid=2776->guuid=bac9d4bb-1a00-0000-251f-06bee20a0000 pid=2786 execve guuid=a96e4dbc-1a00-0000-251f-06bee40a0000 pid=2788 /usr/bin/mkdir guuid=f4bf2bba-1a00-0000-251f-06bed80a0000 pid=2776->guuid=a96e4dbc-1a00-0000-251f-06bee40a0000 pid=2788 execve guuid=b340bebc-1a00-0000-251f-06bee50a0000 pid=2789 /usr/bin/mv guuid=f4bf2bba-1a00-0000-251f-06bed80a0000 pid=2776->guuid=b340bebc-1a00-0000-251f-06bee50a0000 pid=2789 execve guuid=454635bd-1a00-0000-251f-06bee70a0000 pid=2791 /usr/bin/bash guuid=f4bf2bba-1a00-0000-251f-06bed80a0000 pid=2776->guuid=454635bd-1a00-0000-251f-06bee70a0000 pid=2791 clone guuid=bb763cbd-1a00-0000-251f-06bee80a0000 pid=2792 /usr/bin/base64 write-file guuid=f4bf2bba-1a00-0000-251f-06bed80a0000 pid=2776->guuid=bb763cbd-1a00-0000-251f-06bee80a0000 pid=2792 execve guuid=53c39cbd-1a00-0000-251f-06bee90a0000 pid=2793 /usr/bin/rm delete-file guuid=f4bf2bba-1a00-0000-251f-06bed80a0000 pid=2776->guuid=53c39cbd-1a00-0000-251f-06bee90a0000 pid=2793 execve guuid=dc6ff9bd-1a00-0000-251f-06beea0a0000 pid=2794 /usr/bin/ls guuid=f4bf2bba-1a00-0000-251f-06bed80a0000 pid=2776->guuid=dc6ff9bd-1a00-0000-251f-06beea0a0000 pid=2794 execve guuid=45fe62be-1a00-0000-251f-06beeb0a0000 pid=2795 /usr/bin/bash guuid=f4bf2bba-1a00-0000-251f-06bed80a0000 pid=2776->guuid=45fe62be-1a00-0000-251f-06beeb0a0000 pid=2795 clone guuid=c59768be-1a00-0000-251f-06beec0a0000 pid=2796 /usr/bin/base64 write-file guuid=f4bf2bba-1a00-0000-251f-06bed80a0000 pid=2776->guuid=c59768be-1a00-0000-251f-06beec0a0000 pid=2796 execve guuid=cb90c1be-1a00-0000-251f-06beed0a0000 pid=2797 /usr/bin/ls guuid=f4bf2bba-1a00-0000-251f-06bed80a0000 pid=2776->guuid=cb90c1be-1a00-0000-251f-06beed0a0000 pid=2797 execve guuid=eb1068bf-1a00-0000-251f-06beef0a0000 pid=2799 /usr/bin/cat guuid=f4bf2bba-1a00-0000-251f-06bed80a0000 pid=2776->guuid=eb1068bf-1a00-0000-251f-06beef0a0000 pid=2799 execve guuid=f509a4bf-1a00-0000-251f-06bef10a0000 pid=2801 /usr/bin/ls guuid=f4bf2bba-1a00-0000-251f-06bed80a0000 pid=2776->guuid=f509a4bf-1a00-0000-251f-06bef10a0000 pid=2801 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Gathering data
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 309a02bf084c78dc98627209ab63cff1b436f42bcf083e712b780d4ba63bd0ba

(this sample)

  
Delivery method
Distributed via web download

Comments