MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3ac2683056b9d6075c0cbe41d231ef025b97c0a9e2be2e6cced040387b0b50db. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 3ac2683056b9d6075c0cbe41d231ef025b97c0a9e2be2e6cced040387b0b50db
SHA3-384 hash: 9164a176bca28591fcb09a5c03600b57e813ea0d17ac8423f2d350f6fd4ef490c785b854ad263fc30f7f7ac10fe44807
SHA1 hash: 4660aba10cca369b596957bdef1600ba20aad8d0
MD5 hash: f270f345b6005ee08955c890a26bcfac
humanhash: north-october-robin-nitrogen
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-26 21:57:01 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:t/cuQpWx+BL0SWL0gwzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:t/8i+BL0SI0zzsP4cbddr7zsP4cbddrk
TLSH T1AD925CB412896C79FBD1CE399F3C6F4DADE8C2C42124A3ACBA4F39215A1166DC70535A
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
47
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Result
Gathering data
Verdict:
Malicious
File Type:
Script
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=d20c9c9d-1600-0000-7862-57ade40e0000 pid=3812 /usr/bin/sudo guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819 /tmp/sample.bin guuid=d20c9c9d-1600-0000-7862-57ade40e0000 pid=3812->guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819 execve guuid=5ebb7ba0-1600-0000-7862-57adee0e0000 pid=3822 /usr/bin/bash guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=5ebb7ba0-1600-0000-7862-57adee0e0000 pid=3822 clone guuid=ae9089a0-1600-0000-7862-57adef0e0000 pid=3823 /usr/bin/bash guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=ae9089a0-1600-0000-7862-57adef0e0000 pid=3823 clone guuid=8d9ff1a0-1600-0000-7862-57adf10e0000 pid=3825 /usr/bin/mkdir guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=8d9ff1a0-1600-0000-7862-57adf10e0000 pid=3825 execve guuid=b8c458a1-1600-0000-7862-57adf20e0000 pid=3826 /usr/bin/mkdir guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=b8c458a1-1600-0000-7862-57adf20e0000 pid=3826 execve guuid=b43abca1-1600-0000-7862-57adf60e0000 pid=3830 /usr/bin/mkdir guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=b43abca1-1600-0000-7862-57adf60e0000 pid=3830 execve guuid=b19119a2-1600-0000-7862-57adf70e0000 pid=3831 /usr/bin/mkdir guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=b19119a2-1600-0000-7862-57adf70e0000 pid=3831 execve guuid=74c56ea2-1600-0000-7862-57adfa0e0000 pid=3834 /usr/bin/mkdir guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=74c56ea2-1600-0000-7862-57adfa0e0000 pid=3834 execve guuid=7d4cf3a2-1600-0000-7862-57adff0e0000 pid=3839 /usr/bin/mkdir guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=7d4cf3a2-1600-0000-7862-57adff0e0000 pid=3839 execve guuid=03e450a3-1600-0000-7862-57ad000f0000 pid=3840 /usr/bin/mkdir guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=03e450a3-1600-0000-7862-57ad000f0000 pid=3840 execve guuid=88fda6a3-1600-0000-7862-57ad040f0000 pid=3844 /usr/bin/cp guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=88fda6a3-1600-0000-7862-57ad040f0000 pid=3844 execve guuid=97440ba4-1600-0000-7862-57ad080f0000 pid=3848 /usr/bin/cp guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=97440ba4-1600-0000-7862-57ad080f0000 pid=3848 execve guuid=00e779a4-1600-0000-7862-57ad0a0f0000 pid=3850 /usr/bin/cp guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=00e779a4-1600-0000-7862-57ad0a0f0000 pid=3850 execve guuid=3ddedea4-1600-0000-7862-57ad0c0f0000 pid=3852 /usr/bin/cp guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=3ddedea4-1600-0000-7862-57ad0c0f0000 pid=3852 execve guuid=e1a949a5-1600-0000-7862-57ad0f0f0000 pid=3855 /usr/bin/cp guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=e1a949a5-1600-0000-7862-57ad0f0f0000 pid=3855 execve guuid=8ca5bca5-1600-0000-7862-57ad110f0000 pid=3857 /usr/bin/cp guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=8ca5bca5-1600-0000-7862-57ad110f0000 pid=3857 execve guuid=bf5b26a6-1600-0000-7862-57ad140f0000 pid=3860 /usr/bin/cp guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=bf5b26a6-1600-0000-7862-57ad140f0000 pid=3860 execve guuid=3302c9a6-1600-0000-7862-57ad160f0000 pid=3862 /usr/bin/cp guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=3302c9a6-1600-0000-7862-57ad160f0000 pid=3862 execve guuid=fecd4fa7-1600-0000-7862-57ad170f0000 pid=3863 /usr/bin/cp guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=fecd4fa7-1600-0000-7862-57ad170f0000 pid=3863 execve guuid=bac3b0a7-1600-0000-7862-57ad1b0f0000 pid=3867 /usr/bin/cp guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=bac3b0a7-1600-0000-7862-57ad1b0f0000 pid=3867 execve guuid=29161ea8-1600-0000-7862-57ad1f0f0000 pid=3871 /usr/bin/cp guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=29161ea8-1600-0000-7862-57ad1f0f0000 pid=3871 execve guuid=247491a8-1600-0000-7862-57ad220f0000 pid=3874 /usr/bin/cp guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=247491a8-1600-0000-7862-57ad220f0000 pid=3874 execve guuid=baccfba8-1600-0000-7862-57ad250f0000 pid=3877 /usr/bin/cp guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=baccfba8-1600-0000-7862-57ad250f0000 pid=3877 execve guuid=23ed5ba9-1600-0000-7862-57ad270f0000 pid=3879 /usr/bin/cp guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=23ed5ba9-1600-0000-7862-57ad270f0000 pid=3879 execve guuid=a62f41aa-1600-0000-7862-57ad2a0f0000 pid=3882 /usr/bin/cp guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=a62f41aa-1600-0000-7862-57ad2a0f0000 pid=3882 execve guuid=3f9da8aa-1600-0000-7862-57ad2c0f0000 pid=3884 /usr/bin/touch guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=3f9da8aa-1600-0000-7862-57ad2c0f0000 pid=3884 execve guuid=34a3f1aa-1600-0000-7862-57ad2d0f0000 pid=3885 /usr/bin/bash guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=34a3f1aa-1600-0000-7862-57ad2d0f0000 pid=3885 clone guuid=8b33f9aa-1600-0000-7862-57ad2e0f0000 pid=3886 /usr/bin/bash guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=8b33f9aa-1600-0000-7862-57ad2e0f0000 pid=3886 clone guuid=d24d1aab-1600-0000-7862-57ad2f0f0000 pid=3887 /usr/bin/bash guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=d24d1aab-1600-0000-7862-57ad2f0f0000 pid=3887 clone guuid=9ffc27ab-1600-0000-7862-57ad300f0000 pid=3888 /usr/bin/base64 write-file guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=9ffc27ab-1600-0000-7862-57ad300f0000 pid=3888 execve guuid=2b99c7ab-1600-0000-7862-57ad340f0000 pid=3892 /usr/bin/bash guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=2b99c7ab-1600-0000-7862-57ad340f0000 pid=3892 execve guuid=d8c85bb1-1600-0000-7862-57ad590f0000 pid=3929 /usr/bin/rm delete-file guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=d8c85bb1-1600-0000-7862-57ad590f0000 pid=3929 execve guuid=1409b6b1-1600-0000-7862-57ad5a0f0000 pid=3930 /usr/bin/bash guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=1409b6b1-1600-0000-7862-57ad5a0f0000 pid=3930 clone guuid=22cdc0b1-1600-0000-7862-57ad5b0f0000 pid=3931 /usr/bin/bash guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=22cdc0b1-1600-0000-7862-57ad5b0f0000 pid=3931 clone guuid=0c46f3b1-1600-0000-7862-57ad5c0f0000 pid=3932 /usr/bin/bash guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=0c46f3b1-1600-0000-7862-57ad5c0f0000 pid=3932 execve guuid=871b51b2-1600-0000-7862-57ad600f0000 pid=3936 /usr/bin/rm guuid=7235fa9f-1600-0000-7862-57adeb0e0000 pid=3819->guuid=871b51b2-1600-0000-7862-57ad600f0000 pid=3936 execve guuid=d4f526ac-1600-0000-7862-57ad350f0000 pid=3893 /usr/bin/bash guuid=2b99c7ab-1600-0000-7862-57ad340f0000 pid=3892->guuid=d4f526ac-1600-0000-7862-57ad350f0000 pid=3893 clone guuid=aa7830ac-1600-0000-7862-57ad360f0000 pid=3894 /usr/bin/bash guuid=2b99c7ab-1600-0000-7862-57ad340f0000 pid=3892->guuid=aa7830ac-1600-0000-7862-57ad360f0000 pid=3894 clone guuid=aee25cac-1600-0000-7862-57ad370f0000 pid=3895 /usr/bin/ls guuid=2b99c7ab-1600-0000-7862-57ad340f0000 pid=3892->guuid=aee25cac-1600-0000-7862-57ad370f0000 pid=3895 execve guuid=3cc1c6ac-1600-0000-7862-57ad3b0f0000 pid=3899 /usr/bin/cat guuid=2b99c7ab-1600-0000-7862-57ad340f0000 pid=3892->guuid=3cc1c6ac-1600-0000-7862-57ad3b0f0000 pid=3899 execve guuid=557d0bad-1600-0000-7862-57ad3d0f0000 pid=3901 /usr/bin/ls guuid=2b99c7ab-1600-0000-7862-57ad340f0000 pid=3892->guuid=557d0bad-1600-0000-7862-57ad3d0f0000 pid=3901 execve guuid=36907dad-1600-0000-7862-57ad3f0f0000 pid=3903 /usr/bin/mkdir guuid=2b99c7ab-1600-0000-7862-57ad340f0000 pid=3892->guuid=36907dad-1600-0000-7862-57ad3f0f0000 pid=3903 execve guuid=4d76dcad-1600-0000-7862-57ad430f0000 pid=3907 /usr/bin/mv guuid=2b99c7ab-1600-0000-7862-57ad340f0000 pid=3892->guuid=4d76dcad-1600-0000-7862-57ad430f0000 pid=3907 execve guuid=7c8648ae-1600-0000-7862-57ad470f0000 pid=3911 /usr/bin/bash guuid=2b99c7ab-1600-0000-7862-57ad340f0000 pid=3892->guuid=7c8648ae-1600-0000-7862-57ad470f0000 pid=3911 clone guuid=cdde51ae-1600-0000-7862-57ad480f0000 pid=3912 /usr/bin/base64 write-file guuid=2b99c7ab-1600-0000-7862-57ad340f0000 pid=3892->guuid=cdde51ae-1600-0000-7862-57ad480f0000 pid=3912 execve guuid=5c14d5ae-1600-0000-7862-57ad4a0f0000 pid=3914 /usr/bin/rm delete-file guuid=2b99c7ab-1600-0000-7862-57ad340f0000 pid=3892->guuid=5c14d5ae-1600-0000-7862-57ad4a0f0000 pid=3914 execve guuid=b0141faf-1600-0000-7862-57ad4c0f0000 pid=3916 /usr/bin/ls guuid=2b99c7ab-1600-0000-7862-57ad340f0000 pid=3892->guuid=b0141faf-1600-0000-7862-57ad4c0f0000 pid=3916 execve guuid=8ab993af-1600-0000-7862-57ad4e0f0000 pid=3918 /usr/bin/bash guuid=2b99c7ab-1600-0000-7862-57ad340f0000 pid=3892->guuid=8ab993af-1600-0000-7862-57ad4e0f0000 pid=3918 clone guuid=a2229baf-1600-0000-7862-57ad4f0f0000 pid=3919 /usr/bin/base64 write-file guuid=2b99c7ab-1600-0000-7862-57ad340f0000 pid=3892->guuid=a2229baf-1600-0000-7862-57ad4f0f0000 pid=3919 execve guuid=0c4cefaf-1600-0000-7862-57ad510f0000 pid=3921 /usr/bin/ls guuid=2b99c7ab-1600-0000-7862-57ad340f0000 pid=3892->guuid=0c4cefaf-1600-0000-7862-57ad510f0000 pid=3921 execve guuid=973d68b0-1600-0000-7862-57ad540f0000 pid=3924 /usr/bin/cat guuid=2b99c7ab-1600-0000-7862-57ad340f0000 pid=3892->guuid=973d68b0-1600-0000-7862-57ad540f0000 pid=3924 execve guuid=dd8abdb0-1600-0000-7862-57ad550f0000 pid=3925 /usr/bin/ls guuid=2b99c7ab-1600-0000-7862-57ad340f0000 pid=3892->guuid=dd8abdb0-1600-0000-7862-57ad550f0000 pid=3925 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-03-26 21:57:21 UTC
File Type:
Text (Shell)
AV detection:
17 of 36 (47.22%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 3ac2683056b9d6075c0cbe41d231ef025b97c0a9e2be2e6cced040387b0b50db

(this sample)

  
Delivery method
Distributed via web download

Comments