MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 436f1bc944071cfd32a8f6bd3efb3736d40ef39a8a8510e134b92da88ccf920d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 436f1bc944071cfd32a8f6bd3efb3736d40ef39a8a8510e134b92da88ccf920d
SHA3-384 hash: cef68252bf7685fef89e20ff225e6135e837e01e04b3d762fafc675b7605ee051cb3f32fcbe94d9c3fb2360ddaede916
SHA1 hash: 10fbb4d33dab3ebb8ec12ce593d518b461f6e904
MD5 hash: f3a79f381d3fc8ebd008fb1c901990e1
humanhash: helium-beryllium-fourteen-steak
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-22 08:43:48 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:V/YMKQcuQpWx+BL0SWL0gWzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:xYVQ8i+BL0SI01zsP4cbddr7zsP4cbdu
TLSH T1AE925DB412896C79FBD1CE39AF3C6F4DADE882C42124A3ACBA4F39215A1166DC70535D
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=8a1dde64-1700-0000-0deb-fc07500e0000 pid=3664 /usr/bin/sudo guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670 /tmp/sample.bin guuid=8a1dde64-1700-0000-0deb-fc07500e0000 pid=3664->guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670 execve guuid=fd4b6067-1700-0000-0deb-fc07570e0000 pid=3671 /usr/bin/bash guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=fd4b6067-1700-0000-0deb-fc07570e0000 pid=3671 clone guuid=3b836a67-1700-0000-0deb-fc07580e0000 pid=3672 /usr/bin/bash guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=3b836a67-1700-0000-0deb-fc07580e0000 pid=3672 clone guuid=0b83ac67-1700-0000-0deb-fc07590e0000 pid=3673 /usr/bin/mkdir guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=0b83ac67-1700-0000-0deb-fc07590e0000 pid=3673 execve guuid=bad82368-1700-0000-0deb-fc075a0e0000 pid=3674 /usr/bin/mkdir guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=bad82368-1700-0000-0deb-fc075a0e0000 pid=3674 execve guuid=aaaa8968-1700-0000-0deb-fc075b0e0000 pid=3675 /usr/bin/mkdir guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=aaaa8968-1700-0000-0deb-fc075b0e0000 pid=3675 execve guuid=4a71f368-1700-0000-0deb-fc075c0e0000 pid=3676 /usr/bin/mkdir guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=4a71f368-1700-0000-0deb-fc075c0e0000 pid=3676 execve guuid=189b5d69-1700-0000-0deb-fc075d0e0000 pid=3677 /usr/bin/mkdir guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=189b5d69-1700-0000-0deb-fc075d0e0000 pid=3677 execve guuid=d964c069-1700-0000-0deb-fc075e0e0000 pid=3678 /usr/bin/mkdir guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=d964c069-1700-0000-0deb-fc075e0e0000 pid=3678 execve guuid=bd242a6a-1700-0000-0deb-fc075f0e0000 pid=3679 /usr/bin/mkdir guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=bd242a6a-1700-0000-0deb-fc075f0e0000 pid=3679 execve guuid=6baa976a-1700-0000-0deb-fc07600e0000 pid=3680 /usr/bin/cp guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=6baa976a-1700-0000-0deb-fc07600e0000 pid=3680 execve guuid=8ba9ee6a-1700-0000-0deb-fc07640e0000 pid=3684 /usr/bin/cp guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=8ba9ee6a-1700-0000-0deb-fc07640e0000 pid=3684 execve guuid=2c3a566b-1700-0000-0deb-fc07680e0000 pid=3688 /usr/bin/cp guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=2c3a566b-1700-0000-0deb-fc07680e0000 pid=3688 execve guuid=7e68a76b-1700-0000-0deb-fc076a0e0000 pid=3690 /usr/bin/cp guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=7e68a76b-1700-0000-0deb-fc076a0e0000 pid=3690 execve guuid=4557fd6b-1700-0000-0deb-fc076c0e0000 pid=3692 /usr/bin/cp guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=4557fd6b-1700-0000-0deb-fc076c0e0000 pid=3692 execve guuid=f4c04c6c-1700-0000-0deb-fc076e0e0000 pid=3694 /usr/bin/cp guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=f4c04c6c-1700-0000-0deb-fc076e0e0000 pid=3694 execve guuid=cd43a56c-1700-0000-0deb-fc07710e0000 pid=3697 /usr/bin/cp guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=cd43a56c-1700-0000-0deb-fc07710e0000 pid=3697 execve guuid=78e9fe6c-1700-0000-0deb-fc07740e0000 pid=3700 /usr/bin/cp guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=78e9fe6c-1700-0000-0deb-fc07740e0000 pid=3700 execve guuid=d1bd526d-1700-0000-0deb-fc07760e0000 pid=3702 /usr/bin/cp guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=d1bd526d-1700-0000-0deb-fc07760e0000 pid=3702 execve guuid=7caafc6d-1700-0000-0deb-fc07780e0000 pid=3704 /usr/bin/cp guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=7caafc6d-1700-0000-0deb-fc07780e0000 pid=3704 execve guuid=5e54536e-1700-0000-0deb-fc077a0e0000 pid=3706 /usr/bin/cp guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=5e54536e-1700-0000-0deb-fc077a0e0000 pid=3706 execve guuid=67e4b86e-1700-0000-0deb-fc077c0e0000 pid=3708 /usr/bin/cp guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=67e4b86e-1700-0000-0deb-fc077c0e0000 pid=3708 execve guuid=f936216f-1700-0000-0deb-fc077f0e0000 pid=3711 /usr/bin/cp guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=f936216f-1700-0000-0deb-fc077f0e0000 pid=3711 execve guuid=fdd3766f-1700-0000-0deb-fc07810e0000 pid=3713 /usr/bin/cp guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=fdd3766f-1700-0000-0deb-fc07810e0000 pid=3713 execve guuid=0fb60f70-1700-0000-0deb-fc07850e0000 pid=3717 /usr/bin/cp guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=0fb60f70-1700-0000-0deb-fc07850e0000 pid=3717 execve guuid=49098870-1700-0000-0deb-fc07860e0000 pid=3718 /usr/bin/touch guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=49098870-1700-0000-0deb-fc07860e0000 pid=3718 execve guuid=867fd770-1700-0000-0deb-fc07880e0000 pid=3720 /usr/bin/bash guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=867fd770-1700-0000-0deb-fc07880e0000 pid=3720 clone guuid=9f28e070-1700-0000-0deb-fc07890e0000 pid=3721 /usr/bin/bash guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=9f28e070-1700-0000-0deb-fc07890e0000 pid=3721 clone guuid=59bc0f71-1700-0000-0deb-fc078b0e0000 pid=3723 /usr/bin/bash guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=59bc0f71-1700-0000-0deb-fc078b0e0000 pid=3723 clone guuid=7a8c2171-1700-0000-0deb-fc078d0e0000 pid=3725 /usr/bin/base64 write-file guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=7a8c2171-1700-0000-0deb-fc078d0e0000 pid=3725 execve guuid=a63ba871-1700-0000-0deb-fc07910e0000 pid=3729 /usr/bin/bash guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=a63ba871-1700-0000-0deb-fc07910e0000 pid=3729 execve guuid=a3b69078-1700-0000-0deb-fc07bd0e0000 pid=3773 /usr/bin/rm delete-file guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=a3b69078-1700-0000-0deb-fc07bd0e0000 pid=3773 execve guuid=3595d978-1700-0000-0deb-fc07c10e0000 pid=3777 /usr/bin/bash guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=3595d978-1700-0000-0deb-fc07c10e0000 pid=3777 clone guuid=3602e278-1700-0000-0deb-fc07c20e0000 pid=3778 /usr/bin/bash guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=3602e278-1700-0000-0deb-fc07c20e0000 pid=3778 clone guuid=b1260779-1700-0000-0deb-fc07c30e0000 pid=3779 /usr/bin/bash guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=b1260779-1700-0000-0deb-fc07c30e0000 pid=3779 execve guuid=ae8e6179-1700-0000-0deb-fc07c60e0000 pid=3782 /usr/bin/rm guuid=7bd2e866-1700-0000-0deb-fc07560e0000 pid=3670->guuid=ae8e6179-1700-0000-0deb-fc07c60e0000 pid=3782 execve guuid=545f9f72-1700-0000-0deb-fc07950e0000 pid=3733 /usr/bin/bash guuid=a63ba871-1700-0000-0deb-fc07910e0000 pid=3729->guuid=545f9f72-1700-0000-0deb-fc07950e0000 pid=3733 clone guuid=64a0b772-1700-0000-0deb-fc07960e0000 pid=3734 /usr/bin/bash guuid=a63ba871-1700-0000-0deb-fc07910e0000 pid=3729->guuid=64a0b772-1700-0000-0deb-fc07960e0000 pid=3734 clone guuid=c02cd372-1700-0000-0deb-fc079a0e0000 pid=3738 /usr/bin/ls guuid=a63ba871-1700-0000-0deb-fc07910e0000 pid=3729->guuid=c02cd372-1700-0000-0deb-fc079a0e0000 pid=3738 execve guuid=5580c173-1700-0000-0deb-fc079d0e0000 pid=3741 /usr/bin/cat guuid=a63ba871-1700-0000-0deb-fc07910e0000 pid=3729->guuid=5580c173-1700-0000-0deb-fc079d0e0000 pid=3741 execve guuid=72920b74-1700-0000-0deb-fc079f0e0000 pid=3743 /usr/bin/ls guuid=a63ba871-1700-0000-0deb-fc07910e0000 pid=3729->guuid=72920b74-1700-0000-0deb-fc079f0e0000 pid=3743 execve guuid=c4fca074-1700-0000-0deb-fc07a20e0000 pid=3746 /usr/bin/mkdir guuid=a63ba871-1700-0000-0deb-fc07910e0000 pid=3729->guuid=c4fca074-1700-0000-0deb-fc07a20e0000 pid=3746 execve guuid=e2e20a75-1700-0000-0deb-fc07a40e0000 pid=3748 /usr/bin/mv guuid=a63ba871-1700-0000-0deb-fc07910e0000 pid=3729->guuid=e2e20a75-1700-0000-0deb-fc07a40e0000 pid=3748 execve guuid=7e588175-1700-0000-0deb-fc07a80e0000 pid=3752 /usr/bin/bash guuid=a63ba871-1700-0000-0deb-fc07910e0000 pid=3729->guuid=7e588175-1700-0000-0deb-fc07a80e0000 pid=3752 clone guuid=f5308975-1700-0000-0deb-fc07a90e0000 pid=3753 /usr/bin/base64 write-file guuid=a63ba871-1700-0000-0deb-fc07910e0000 pid=3729->guuid=f5308975-1700-0000-0deb-fc07a90e0000 pid=3753 execve guuid=3d1ed175-1700-0000-0deb-fc07aa0e0000 pid=3754 /usr/bin/rm delete-file guuid=a63ba871-1700-0000-0deb-fc07910e0000 pid=3729->guuid=3d1ed175-1700-0000-0deb-fc07aa0e0000 pid=3754 execve guuid=df143476-1700-0000-0deb-fc07ad0e0000 pid=3757 /usr/bin/ls guuid=a63ba871-1700-0000-0deb-fc07910e0000 pid=3729->guuid=df143476-1700-0000-0deb-fc07ad0e0000 pid=3757 execve guuid=299da076-1700-0000-0deb-fc07b00e0000 pid=3760 /usr/bin/bash guuid=a63ba871-1700-0000-0deb-fc07910e0000 pid=3729->guuid=299da076-1700-0000-0deb-fc07b00e0000 pid=3760 clone guuid=7e26aa76-1700-0000-0deb-fc07b10e0000 pid=3761 /usr/bin/base64 write-file guuid=a63ba871-1700-0000-0deb-fc07910e0000 pid=3729->guuid=7e26aa76-1700-0000-0deb-fc07b10e0000 pid=3761 execve guuid=2dc42177-1700-0000-0deb-fc07b50e0000 pid=3765 /usr/bin/ls guuid=a63ba871-1700-0000-0deb-fc07910e0000 pid=3729->guuid=2dc42177-1700-0000-0deb-fc07b50e0000 pid=3765 execve guuid=0804ce77-1700-0000-0deb-fc07b70e0000 pid=3767 /usr/bin/cat guuid=a63ba871-1700-0000-0deb-fc07910e0000 pid=3729->guuid=0804ce77-1700-0000-0deb-fc07b70e0000 pid=3767 execve guuid=61091e78-1700-0000-0deb-fc07b90e0000 pid=3769 /usr/bin/ls guuid=a63ba871-1700-0000-0deb-fc07910e0000 pid=3729->guuid=61091e78-1700-0000-0deb-fc07b90e0000 pid=3769 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-22 08:44:24 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 436f1bc944071cfd32a8f6bd3efb3736d40ef39a8a8510e134b92da88ccf920d

(this sample)

  
Delivery method
Distributed via web download

Comments