MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3b4c85d2e41273f33e8d6aff06ddf4b75a242a85d65ecd6207b321c9fd8722b5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 3b4c85d2e41273f33e8d6aff06ddf4b75a242a85d65ecd6207b321c9fd8722b5
SHA3-384 hash: f31867dde6cbd82a3ed658cfc1a12794103f8bea3c20f628d901082bea1c8ffad3543a3b6dce6e250feea0b1f5a08708
SHA1 hash: 98ce0e98121c5c3de81499257be5c240a209bc5f
MD5 hash: 5ca6709547122f51ecea48565e506e76
humanhash: green-sad-winner-pluto
File name:k.php
Download: download sample
File size:19'491 bytes
First seen:2026-03-15 08:16:39 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:BCncuxOLnVYMSFzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:BJuQL+FzsP4cbddr7zsP4cbddrk
TLSH T198925CB506496C79BBC0CE799F3C7F0CADE482C42129E39DBA1F39714A2165DC60935D
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=0662a99b-1600-0000-a38b-00684c0d0000 pid=3404 /usr/bin/sudo guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413 /tmp/sample.bin guuid=0662a99b-1600-0000-a38b-00684c0d0000 pid=3404->guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413 execve guuid=99222f9e-1600-0000-a38b-0068570d0000 pid=3415 /usr/bin/bash guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=99222f9e-1600-0000-a38b-0068570d0000 pid=3415 clone guuid=e47a369e-1600-0000-a38b-0068580d0000 pid=3416 /usr/bin/bash guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=e47a369e-1600-0000-a38b-0068580d0000 pid=3416 clone guuid=e16e6c9e-1600-0000-a38b-00685a0d0000 pid=3418 /usr/bin/mkdir guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=e16e6c9e-1600-0000-a38b-00685a0d0000 pid=3418 execve guuid=2e35c29e-1600-0000-a38b-00685c0d0000 pid=3420 /usr/bin/mkdir guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=2e35c29e-1600-0000-a38b-00685c0d0000 pid=3420 execve guuid=b92f119f-1600-0000-a38b-00685e0d0000 pid=3422 /usr/bin/mkdir guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=b92f119f-1600-0000-a38b-00685e0d0000 pid=3422 execve guuid=db8a639f-1600-0000-a38b-0068600d0000 pid=3424 /usr/bin/mkdir guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=db8a639f-1600-0000-a38b-0068600d0000 pid=3424 execve guuid=cb24b59f-1600-0000-a38b-0068620d0000 pid=3426 /usr/bin/mkdir guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=cb24b59f-1600-0000-a38b-0068620d0000 pid=3426 execve guuid=e19008a0-1600-0000-a38b-0068640d0000 pid=3428 /usr/bin/mkdir guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=e19008a0-1600-0000-a38b-0068640d0000 pid=3428 execve guuid=8b785ea0-1600-0000-a38b-0068660d0000 pid=3430 /usr/bin/mkdir guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=8b785ea0-1600-0000-a38b-0068660d0000 pid=3430 execve guuid=6eceb5a0-1600-0000-a38b-0068680d0000 pid=3432 /usr/bin/cp guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=6eceb5a0-1600-0000-a38b-0068680d0000 pid=3432 execve guuid=875210a1-1600-0000-a38b-00686a0d0000 pid=3434 /usr/bin/cp guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=875210a1-1600-0000-a38b-00686a0d0000 pid=3434 execve guuid=e0b6b0a1-1600-0000-a38b-00686d0d0000 pid=3437 /usr/bin/cp guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=e0b6b0a1-1600-0000-a38b-00686d0d0000 pid=3437 execve guuid=daa824a2-1600-0000-a38b-0068700d0000 pid=3440 /usr/bin/cp guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=daa824a2-1600-0000-a38b-0068700d0000 pid=3440 execve guuid=eab591a2-1600-0000-a38b-0068730d0000 pid=3443 /usr/bin/cp guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=eab591a2-1600-0000-a38b-0068730d0000 pid=3443 execve guuid=4bd3eda2-1600-0000-a38b-0068750d0000 pid=3445 /usr/bin/cp guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=4bd3eda2-1600-0000-a38b-0068750d0000 pid=3445 execve guuid=0fdd57a3-1600-0000-a38b-0068780d0000 pid=3448 /usr/bin/cp guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=0fdd57a3-1600-0000-a38b-0068780d0000 pid=3448 execve guuid=db86ada3-1600-0000-a38b-00687a0d0000 pid=3450 /usr/bin/cp guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=db86ada3-1600-0000-a38b-00687a0d0000 pid=3450 execve guuid=0dae09a4-1600-0000-a38b-00687c0d0000 pid=3452 /usr/bin/cp guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=0dae09a4-1600-0000-a38b-00687c0d0000 pid=3452 execve guuid=d8eb60a4-1600-0000-a38b-00687f0d0000 pid=3455 /usr/bin/cp guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=d8eb60a4-1600-0000-a38b-00687f0d0000 pid=3455 execve guuid=c44cbda4-1600-0000-a38b-0068810d0000 pid=3457 /usr/bin/cp guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=c44cbda4-1600-0000-a38b-0068810d0000 pid=3457 execve guuid=1dbd25a5-1600-0000-a38b-0068840d0000 pid=3460 /usr/bin/cp guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=1dbd25a5-1600-0000-a38b-0068840d0000 pid=3460 execve guuid=5f3690a5-1600-0000-a38b-0068860d0000 pid=3462 /usr/bin/cp guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=5f3690a5-1600-0000-a38b-0068860d0000 pid=3462 execve guuid=42b3eea5-1600-0000-a38b-0068880d0000 pid=3464 /usr/bin/cp guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=42b3eea5-1600-0000-a38b-0068880d0000 pid=3464 execve guuid=89fb65a6-1600-0000-a38b-00688b0d0000 pid=3467 /usr/bin/cp guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=89fb65a6-1600-0000-a38b-00688b0d0000 pid=3467 execve guuid=c564c5a6-1600-0000-a38b-00688e0d0000 pid=3470 /usr/bin/touch guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=c564c5a6-1600-0000-a38b-00688e0d0000 pid=3470 execve guuid=d5e52da7-1600-0000-a38b-0068900d0000 pid=3472 /usr/bin/bash guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=d5e52da7-1600-0000-a38b-0068900d0000 pid=3472 clone guuid=53ba33a7-1600-0000-a38b-0068910d0000 pid=3473 /usr/bin/bash guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=53ba33a7-1600-0000-a38b-0068910d0000 pid=3473 clone guuid=f70776a7-1600-0000-a38b-0068930d0000 pid=3475 /usr/bin/bash guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=f70776a7-1600-0000-a38b-0068930d0000 pid=3475 clone guuid=78ec7ba7-1600-0000-a38b-0068940d0000 pid=3476 /usr/bin/base64 write-file guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=78ec7ba7-1600-0000-a38b-0068940d0000 pid=3476 execve guuid=9312f9a7-1600-0000-a38b-0068970d0000 pid=3479 /usr/bin/bash guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=9312f9a7-1600-0000-a38b-0068970d0000 pid=3479 execve guuid=ea95b6ac-1600-0000-a38b-0068b90d0000 pid=3513 /usr/bin/rm delete-file guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=ea95b6ac-1600-0000-a38b-0068b90d0000 pid=3513 execve guuid=1d6dfeac-1600-0000-a38b-0068bb0d0000 pid=3515 /usr/bin/bash guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=1d6dfeac-1600-0000-a38b-0068bb0d0000 pid=3515 clone guuid=f2f81cad-1600-0000-a38b-0068bd0d0000 pid=3517 /usr/bin/bash guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=f2f81cad-1600-0000-a38b-0068bd0d0000 pid=3517 clone guuid=055a93ad-1600-0000-a38b-0068bf0d0000 pid=3519 /usr/bin/bash guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=055a93ad-1600-0000-a38b-0068bf0d0000 pid=3519 execve guuid=c17a03ae-1600-0000-a38b-0068c20d0000 pid=3522 /usr/bin/rm guuid=9220dd9d-1600-0000-a38b-0068550d0000 pid=3413->guuid=c17a03ae-1600-0000-a38b-0068c20d0000 pid=3522 execve guuid=acf563a8-1600-0000-a38b-00689a0d0000 pid=3482 /usr/bin/bash guuid=9312f9a7-1600-0000-a38b-0068970d0000 pid=3479->guuid=acf563a8-1600-0000-a38b-00689a0d0000 pid=3482 clone guuid=e28c70a8-1600-0000-a38b-00689b0d0000 pid=3483 /usr/bin/bash guuid=9312f9a7-1600-0000-a38b-0068970d0000 pid=3479->guuid=e28c70a8-1600-0000-a38b-00689b0d0000 pid=3483 clone guuid=3f398ca8-1600-0000-a38b-00689c0d0000 pid=3484 /usr/bin/ls guuid=9312f9a7-1600-0000-a38b-0068970d0000 pid=3479->guuid=3f398ca8-1600-0000-a38b-00689c0d0000 pid=3484 execve guuid=3787fca8-1600-0000-a38b-00689e0d0000 pid=3486 /usr/bin/cat guuid=9312f9a7-1600-0000-a38b-0068970d0000 pid=3479->guuid=3787fca8-1600-0000-a38b-00689e0d0000 pid=3486 execve guuid=88d639a9-1600-0000-a38b-0068a00d0000 pid=3488 /usr/bin/ls guuid=9312f9a7-1600-0000-a38b-0068970d0000 pid=3479->guuid=88d639a9-1600-0000-a38b-0068a00d0000 pid=3488 execve guuid=811ba2a9-1600-0000-a38b-0068a30d0000 pid=3491 /usr/bin/mkdir guuid=9312f9a7-1600-0000-a38b-0068970d0000 pid=3479->guuid=811ba2a9-1600-0000-a38b-0068a30d0000 pid=3491 execve guuid=295ff2a9-1600-0000-a38b-0068a50d0000 pid=3493 /usr/bin/mv guuid=9312f9a7-1600-0000-a38b-0068970d0000 pid=3479->guuid=295ff2a9-1600-0000-a38b-0068a50d0000 pid=3493 execve guuid=543252aa-1600-0000-a38b-0068a70d0000 pid=3495 /usr/bin/bash guuid=9312f9a7-1600-0000-a38b-0068970d0000 pid=3479->guuid=543252aa-1600-0000-a38b-0068a70d0000 pid=3495 clone guuid=11975aaa-1600-0000-a38b-0068a80d0000 pid=3496 /usr/bin/base64 write-file guuid=9312f9a7-1600-0000-a38b-0068970d0000 pid=3479->guuid=11975aaa-1600-0000-a38b-0068a80d0000 pid=3496 execve guuid=7724a9aa-1600-0000-a38b-0068aa0d0000 pid=3498 /usr/bin/rm delete-file guuid=9312f9a7-1600-0000-a38b-0068970d0000 pid=3479->guuid=7724a9aa-1600-0000-a38b-0068aa0d0000 pid=3498 execve guuid=10b7eaaa-1600-0000-a38b-0068ac0d0000 pid=3500 /usr/bin/ls guuid=9312f9a7-1600-0000-a38b-0068970d0000 pid=3479->guuid=10b7eaaa-1600-0000-a38b-0068ac0d0000 pid=3500 execve guuid=e8c14aab-1600-0000-a38b-0068af0d0000 pid=3503 /usr/bin/bash guuid=9312f9a7-1600-0000-a38b-0068970d0000 pid=3479->guuid=e8c14aab-1600-0000-a38b-0068af0d0000 pid=3503 clone guuid=ffa250ab-1600-0000-a38b-0068b00d0000 pid=3504 /usr/bin/base64 write-file guuid=9312f9a7-1600-0000-a38b-0068970d0000 pid=3479->guuid=ffa250ab-1600-0000-a38b-0068b00d0000 pid=3504 execve guuid=b32a9cab-1600-0000-a38b-0068b20d0000 pid=3506 /usr/bin/ls guuid=9312f9a7-1600-0000-a38b-0068970d0000 pid=3479->guuid=b32a9cab-1600-0000-a38b-0068b20d0000 pid=3506 execve guuid=b9cafdab-1600-0000-a38b-0068b40d0000 pid=3508 /usr/bin/cat guuid=9312f9a7-1600-0000-a38b-0068970d0000 pid=3479->guuid=b9cafdab-1600-0000-a38b-0068b40d0000 pid=3508 execve guuid=71b742ac-1600-0000-a38b-0068b60d0000 pid=3510 /usr/bin/ls guuid=9312f9a7-1600-0000-a38b-0068970d0000 pid=3479->guuid=71b742ac-1600-0000-a38b-0068b60d0000 pid=3510 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-15 08:17:21 UTC
File Type:
Text (Shell)
AV detection:
10 of 23 (43.48%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 3b4c85d2e41273f33e8d6aff06ddf4b75a242a85d65ecd6207b321c9fd8722b5

(this sample)

  
Delivery method
Distributed via web download

Comments