MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4dd9d9953ffac418546a28e23d52ccc8c92d863f0495c8980070457088f94297. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 4dd9d9953ffac418546a28e23d52ccc8c92d863f0495c8980070457088f94297
SHA3-384 hash: 7c9e51fb620baf2a1abecfa9afae135da171543e855a068a6d84d18e1b087c72e352f97ce521b55f9d12b8496a643d0c
SHA1 hash: 6ec7b4af6a7e16c086949e374c71bab636deff0e
MD5 hash: 7367d0e845d84727026a9c4170377917
humanhash: september-november-nineteen-triple
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-15 03:15:12 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:6FcuQpWx+BL0SWL0gBzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:6F8i+BL0SI0azsP4cbddr7zsP4cbddrk
TLSH T111925CB512896C79FBD0CE399F3C6F4CADE8C2C42124A3ACBA4F39215A1166DC70534A
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=3557f3e8-1600-0000-7702-0605070d0000 pid=3335 /usr/bin/sudo guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341 /tmp/sample.bin guuid=3557f3e8-1600-0000-7702-0605070d0000 pid=3335->guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341 execve guuid=30510bec-1600-0000-7702-0605110d0000 pid=3345 /usr/bin/bash guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=30510bec-1600-0000-7702-0605110d0000 pid=3345 clone guuid=db7c30ec-1600-0000-7702-0605120d0000 pid=3346 /usr/bin/bash guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=db7c30ec-1600-0000-7702-0605120d0000 pid=3346 clone guuid=27f48cec-1600-0000-7702-0605140d0000 pid=3348 /usr/bin/mkdir guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=27f48cec-1600-0000-7702-0605140d0000 pid=3348 execve guuid=46f0d6ec-1600-0000-7702-0605170d0000 pid=3351 /usr/bin/mkdir guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=46f0d6ec-1600-0000-7702-0605170d0000 pid=3351 execve guuid=f21438ed-1600-0000-7702-0605180d0000 pid=3352 /usr/bin/mkdir guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=f21438ed-1600-0000-7702-0605180d0000 pid=3352 execve guuid=3fe98ded-1600-0000-7702-06051a0d0000 pid=3354 /usr/bin/mkdir guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=3fe98ded-1600-0000-7702-06051a0d0000 pid=3354 execve guuid=ef9a02ee-1600-0000-7702-06051d0d0000 pid=3357 /usr/bin/mkdir guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=ef9a02ee-1600-0000-7702-06051d0d0000 pid=3357 execve guuid=11cd5eee-1600-0000-7702-06051e0d0000 pid=3358 /usr/bin/mkdir guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=11cd5eee-1600-0000-7702-06051e0d0000 pid=3358 execve guuid=c9ea14ef-1600-0000-7702-0605200d0000 pid=3360 /usr/bin/mkdir guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=c9ea14ef-1600-0000-7702-0605200d0000 pid=3360 execve guuid=e5a985ef-1600-0000-7702-0605210d0000 pid=3361 /usr/bin/cp guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=e5a985ef-1600-0000-7702-0605210d0000 pid=3361 execve guuid=77f016f0-1600-0000-7702-0605220d0000 pid=3362 /usr/bin/cp guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=77f016f0-1600-0000-7702-0605220d0000 pid=3362 execve guuid=53678cf0-1600-0000-7702-0605240d0000 pid=3364 /usr/bin/cp guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=53678cf0-1600-0000-7702-0605240d0000 pid=3364 execve guuid=669dedf0-1600-0000-7702-0605260d0000 pid=3366 /usr/bin/cp guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=669dedf0-1600-0000-7702-0605260d0000 pid=3366 execve guuid=28bf4ef1-1600-0000-7702-0605280d0000 pid=3368 /usr/bin/cp guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=28bf4ef1-1600-0000-7702-0605280d0000 pid=3368 execve guuid=4058bbf1-1600-0000-7702-06052a0d0000 pid=3370 /usr/bin/cp guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=4058bbf1-1600-0000-7702-06052a0d0000 pid=3370 execve guuid=8ad412f2-1600-0000-7702-06052c0d0000 pid=3372 /usr/bin/cp guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=8ad412f2-1600-0000-7702-06052c0d0000 pid=3372 execve guuid=6fd56af2-1600-0000-7702-06052e0d0000 pid=3374 /usr/bin/cp guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=6fd56af2-1600-0000-7702-06052e0d0000 pid=3374 execve guuid=5d3fbbf2-1600-0000-7702-0605310d0000 pid=3377 /usr/bin/cp guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=5d3fbbf2-1600-0000-7702-0605310d0000 pid=3377 execve guuid=ddf31ef3-1600-0000-7702-0605330d0000 pid=3379 /usr/bin/cp guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=ddf31ef3-1600-0000-7702-0605330d0000 pid=3379 execve guuid=01b586f3-1600-0000-7702-0605340d0000 pid=3380 /usr/bin/cp guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=01b586f3-1600-0000-7702-0605340d0000 pid=3380 execve guuid=0cb9f1f3-1600-0000-7702-0605350d0000 pid=3381 /usr/bin/cp guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=0cb9f1f3-1600-0000-7702-0605350d0000 pid=3381 execve guuid=bfc244f4-1600-0000-7702-0605370d0000 pid=3383 /usr/bin/cp guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=bfc244f4-1600-0000-7702-0605370d0000 pid=3383 execve guuid=7e2f9ff4-1600-0000-7702-0605390d0000 pid=3385 /usr/bin/cp guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=7e2f9ff4-1600-0000-7702-0605390d0000 pid=3385 execve guuid=e937f8f4-1600-0000-7702-06053c0d0000 pid=3388 /usr/bin/cp guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=e937f8f4-1600-0000-7702-06053c0d0000 pid=3388 execve guuid=0dee50f5-1600-0000-7702-06053e0d0000 pid=3390 /usr/bin/touch guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=0dee50f5-1600-0000-7702-06053e0d0000 pid=3390 execve guuid=5e6c8ef5-1600-0000-7702-0605400d0000 pid=3392 /usr/bin/bash guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=5e6c8ef5-1600-0000-7702-0605400d0000 pid=3392 clone guuid=906a95f5-1600-0000-7702-0605410d0000 pid=3393 /usr/bin/bash guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=906a95f5-1600-0000-7702-0605410d0000 pid=3393 clone guuid=d175aef5-1600-0000-7702-0605430d0000 pid=3395 /usr/bin/bash guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=d175aef5-1600-0000-7702-0605430d0000 pid=3395 clone guuid=de98b5f5-1600-0000-7702-0605440d0000 pid=3396 /usr/bin/base64 write-file guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=de98b5f5-1600-0000-7702-0605440d0000 pid=3396 execve guuid=989a33f6-1600-0000-7702-0605470d0000 pid=3399 /usr/bin/bash guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=989a33f6-1600-0000-7702-0605470d0000 pid=3399 execve guuid=3150e3fa-1600-0000-7702-0605650d0000 pid=3429 /usr/bin/rm delete-file guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=3150e3fa-1600-0000-7702-0605650d0000 pid=3429 execve guuid=e5e324fb-1600-0000-7702-0605670d0000 pid=3431 /usr/bin/bash guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=e5e324fb-1600-0000-7702-0605670d0000 pid=3431 clone guuid=3abd2afb-1600-0000-7702-0605680d0000 pid=3432 /usr/bin/bash guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=3abd2afb-1600-0000-7702-0605680d0000 pid=3432 clone guuid=7e2947fb-1600-0000-7702-0605690d0000 pid=3433 /usr/bin/bash guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=7e2947fb-1600-0000-7702-0605690d0000 pid=3433 execve guuid=ae7396fb-1600-0000-7702-06056c0d0000 pid=3436 /usr/bin/rm guuid=16e829eb-1600-0000-7702-06050d0d0000 pid=3341->guuid=ae7396fb-1600-0000-7702-06056c0d0000 pid=3436 execve guuid=73837ef6-1600-0000-7702-0605490d0000 pid=3401 /usr/bin/bash guuid=989a33f6-1600-0000-7702-0605470d0000 pid=3399->guuid=73837ef6-1600-0000-7702-0605490d0000 pid=3401 clone guuid=428f83f6-1600-0000-7702-06054a0d0000 pid=3402 /usr/bin/bash guuid=989a33f6-1600-0000-7702-0605470d0000 pid=3399->guuid=428f83f6-1600-0000-7702-06054a0d0000 pid=3402 clone guuid=1a7899f6-1600-0000-7702-06054b0d0000 pid=3403 /usr/bin/ls guuid=989a33f6-1600-0000-7702-0605470d0000 pid=3399->guuid=1a7899f6-1600-0000-7702-06054b0d0000 pid=3403 execve guuid=03fd08f7-1600-0000-7702-06054e0d0000 pid=3406 /usr/bin/cat guuid=989a33f6-1600-0000-7702-0605470d0000 pid=3399->guuid=03fd08f7-1600-0000-7702-06054e0d0000 pid=3406 execve guuid=d8ee47f7-1600-0000-7702-0605500d0000 pid=3408 /usr/bin/ls guuid=989a33f6-1600-0000-7702-0605470d0000 pid=3399->guuid=d8ee47f7-1600-0000-7702-0605500d0000 pid=3408 execve guuid=f0c0b1f7-1600-0000-7702-0605520d0000 pid=3410 /usr/bin/mkdir guuid=989a33f6-1600-0000-7702-0605470d0000 pid=3399->guuid=f0c0b1f7-1600-0000-7702-0605520d0000 pid=3410 execve guuid=718e08f8-1600-0000-7702-0605550d0000 pid=3413 /usr/bin/mv guuid=989a33f6-1600-0000-7702-0605470d0000 pid=3399->guuid=718e08f8-1600-0000-7702-0605550d0000 pid=3413 execve guuid=472f65f8-1600-0000-7702-0605570d0000 pid=3415 /usr/bin/bash guuid=989a33f6-1600-0000-7702-0605470d0000 pid=3399->guuid=472f65f8-1600-0000-7702-0605570d0000 pid=3415 clone guuid=1b5e6af8-1600-0000-7702-0605580d0000 pid=3416 /usr/bin/base64 write-file guuid=989a33f6-1600-0000-7702-0605470d0000 pid=3399->guuid=1b5e6af8-1600-0000-7702-0605580d0000 pid=3416 execve guuid=f4bcc7f8-1600-0000-7702-0605590d0000 pid=3417 /usr/bin/rm delete-file guuid=989a33f6-1600-0000-7702-0605470d0000 pid=3399->guuid=f4bcc7f8-1600-0000-7702-0605590d0000 pid=3417 execve guuid=62c82bf9-1600-0000-7702-06055a0d0000 pid=3418 /usr/bin/ls guuid=989a33f6-1600-0000-7702-0605470d0000 pid=3399->guuid=62c82bf9-1600-0000-7702-06055a0d0000 pid=3418 execve guuid=2b28a1f9-1600-0000-7702-06055b0d0000 pid=3419 /usr/bin/bash guuid=989a33f6-1600-0000-7702-0605470d0000 pid=3399->guuid=2b28a1f9-1600-0000-7702-06055b0d0000 pid=3419 clone guuid=da19a7f9-1600-0000-7702-06055c0d0000 pid=3420 /usr/bin/base64 write-file guuid=989a33f6-1600-0000-7702-0605470d0000 pid=3399->guuid=da19a7f9-1600-0000-7702-06055c0d0000 pid=3420 execve guuid=35c2eff9-1600-0000-7702-06055e0d0000 pid=3422 /usr/bin/ls guuid=989a33f6-1600-0000-7702-0605470d0000 pid=3399->guuid=35c2eff9-1600-0000-7702-06055e0d0000 pid=3422 execve guuid=31094bfa-1600-0000-7702-0605600d0000 pid=3424 /usr/bin/cat guuid=989a33f6-1600-0000-7702-0605470d0000 pid=3399->guuid=31094bfa-1600-0000-7702-0605600d0000 pid=3424 execve guuid=467e85fa-1600-0000-7702-0605620d0000 pid=3426 /usr/bin/ls guuid=989a33f6-1600-0000-7702-0605470d0000 pid=3399->guuid=467e85fa-1600-0000-7702-0605620d0000 pid=3426 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-15 03:17:51 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 4dd9d9953ffac418546a28e23d52ccc8c92d863f0495c8980070457088f94297

(this sample)

  
Delivery method
Distributed via web download

Comments