MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 58a84e7f892cdf58116e79555debf2e2a30daff8158594ca770ddab845237576. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 58a84e7f892cdf58116e79555debf2e2a30daff8158594ca770ddab845237576
SHA3-384 hash: 9cb9b1febdde1a29e0384215c250c10f039fa138a1bca5a9cea8cbbef1b9cbcb1565499bc65b3694441a35666009793d
SHA1 hash: 6e4605f2e35f0bcf3033afe2548e433012fa5bd9
MD5 hash: 0ca1ab4a6816463733a0b6e634503eec
humanhash: twenty-william-earth-louisiana
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-05 21:30:35 UTC
Last seen:2026-03-06 15:51:03 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 384:PscuQpWx+BL0SWL0gAzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:Ps8i+BL0SI0bzsP4cbddr7zsP4cbddrk
TLSH T1FC925CB512896C79FBD0CE399F3C6F4DADE882C42124E3ACBA0F39215A1166DC70535D
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
2
# of downloads :
40
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=d1569c9d-1600-0000-86aa-a296700c0000 pid=3184 /usr/bin/sudo guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190 /tmp/sample.bin guuid=d1569c9d-1600-0000-86aa-a296700c0000 pid=3184->guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190 execve guuid=0db4bfa0-1600-0000-86aa-a296780c0000 pid=3192 /usr/bin/bash guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=0db4bfa0-1600-0000-86aa-a296780c0000 pid=3192 clone guuid=9111cda0-1600-0000-86aa-a296790c0000 pid=3193 /usr/bin/bash guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=9111cda0-1600-0000-86aa-a296790c0000 pid=3193 clone guuid=7c6525a1-1600-0000-86aa-a2967a0c0000 pid=3194 /usr/bin/mkdir guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=7c6525a1-1600-0000-86aa-a2967a0c0000 pid=3194 execve guuid=0c75dda1-1600-0000-86aa-a2967b0c0000 pid=3195 /usr/bin/mkdir guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=0c75dda1-1600-0000-86aa-a2967b0c0000 pid=3195 execve guuid=e0cb66a2-1600-0000-86aa-a2967d0c0000 pid=3197 /usr/bin/mkdir guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=e0cb66a2-1600-0000-86aa-a2967d0c0000 pid=3197 execve guuid=bc47b6a2-1600-0000-86aa-a2967f0c0000 pid=3199 /usr/bin/mkdir guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=bc47b6a2-1600-0000-86aa-a2967f0c0000 pid=3199 execve guuid=12ad0ca3-1600-0000-86aa-a296810c0000 pid=3201 /usr/bin/mkdir guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=12ad0ca3-1600-0000-86aa-a296810c0000 pid=3201 execve guuid=213263a3-1600-0000-86aa-a296830c0000 pid=3203 /usr/bin/mkdir guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=213263a3-1600-0000-86aa-a296830c0000 pid=3203 execve guuid=dfc3c0a3-1600-0000-86aa-a296840c0000 pid=3204 /usr/bin/mkdir guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=dfc3c0a3-1600-0000-86aa-a296840c0000 pid=3204 execve guuid=8c9013a4-1600-0000-86aa-a296860c0000 pid=3206 /usr/bin/cp guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=8c9013a4-1600-0000-86aa-a296860c0000 pid=3206 execve guuid=054676a4-1600-0000-86aa-a296890c0000 pid=3209 /usr/bin/cp guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=054676a4-1600-0000-86aa-a296890c0000 pid=3209 execve guuid=0c8b1ba5-1600-0000-86aa-a2968a0c0000 pid=3210 /usr/bin/cp guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=0c8b1ba5-1600-0000-86aa-a2968a0c0000 pid=3210 execve guuid=6f18a4a5-1600-0000-86aa-a2968d0c0000 pid=3213 /usr/bin/cp guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=6f18a4a5-1600-0000-86aa-a2968d0c0000 pid=3213 execve guuid=414b22a6-1600-0000-86aa-a2968f0c0000 pid=3215 /usr/bin/cp guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=414b22a6-1600-0000-86aa-a2968f0c0000 pid=3215 execve guuid=3637c4a6-1600-0000-86aa-a296900c0000 pid=3216 /usr/bin/cp guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=3637c4a6-1600-0000-86aa-a296900c0000 pid=3216 execve guuid=ddab8ca7-1600-0000-86aa-a296910c0000 pid=3217 /usr/bin/cp guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=ddab8ca7-1600-0000-86aa-a296910c0000 pid=3217 execve guuid=536348a8-1600-0000-86aa-a296920c0000 pid=3218 /usr/bin/cp guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=536348a8-1600-0000-86aa-a296920c0000 pid=3218 execve guuid=9c9411a9-1600-0000-86aa-a296930c0000 pid=3219 /usr/bin/cp guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=9c9411a9-1600-0000-86aa-a296930c0000 pid=3219 execve guuid=ebadeea9-1600-0000-86aa-a296940c0000 pid=3220 /usr/bin/cp guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=ebadeea9-1600-0000-86aa-a296940c0000 pid=3220 execve guuid=d58fcdaa-1600-0000-86aa-a296950c0000 pid=3221 /usr/bin/cp guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=d58fcdaa-1600-0000-86aa-a296950c0000 pid=3221 execve guuid=d165beab-1600-0000-86aa-a296960c0000 pid=3222 /usr/bin/cp guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=d165beab-1600-0000-86aa-a296960c0000 pid=3222 execve guuid=7f9576ac-1600-0000-86aa-a296970c0000 pid=3223 /usr/bin/cp guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=7f9576ac-1600-0000-86aa-a296970c0000 pid=3223 execve guuid=f98223ad-1600-0000-86aa-a296980c0000 pid=3224 /usr/bin/cp guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=f98223ad-1600-0000-86aa-a296980c0000 pid=3224 execve guuid=870cbaad-1600-0000-86aa-a296990c0000 pid=3225 /usr/bin/cp guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=870cbaad-1600-0000-86aa-a296990c0000 pid=3225 execve guuid=e582b3ae-1600-0000-86aa-a2969a0c0000 pid=3226 /usr/bin/touch guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=e582b3ae-1600-0000-86aa-a2969a0c0000 pid=3226 execve guuid=57830faf-1600-0000-86aa-a2969b0c0000 pid=3227 /usr/bin/bash guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=57830faf-1600-0000-86aa-a2969b0c0000 pid=3227 clone guuid=de4e18af-1600-0000-86aa-a2969c0c0000 pid=3228 /usr/bin/bash guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=de4e18af-1600-0000-86aa-a2969c0c0000 pid=3228 clone guuid=87e842af-1600-0000-86aa-a2969d0c0000 pid=3229 /usr/bin/bash guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=87e842af-1600-0000-86aa-a2969d0c0000 pid=3229 clone guuid=80bb4baf-1600-0000-86aa-a2969e0c0000 pid=3230 /usr/bin/base64 write-file guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=80bb4baf-1600-0000-86aa-a2969e0c0000 pid=3230 execve guuid=34e6d0af-1600-0000-86aa-a2969f0c0000 pid=3231 /usr/bin/bash guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=34e6d0af-1600-0000-86aa-a2969f0c0000 pid=3231 execve guuid=67742fb7-1600-0000-86aa-a296b00c0000 pid=3248 /usr/bin/rm delete-file guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=67742fb7-1600-0000-86aa-a296b00c0000 pid=3248 execve guuid=159dabb7-1600-0000-86aa-a296b10c0000 pid=3249 /usr/bin/bash guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=159dabb7-1600-0000-86aa-a296b10c0000 pid=3249 clone guuid=ef00b4b7-1600-0000-86aa-a296b20c0000 pid=3250 /usr/bin/bash guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=ef00b4b7-1600-0000-86aa-a296b20c0000 pid=3250 clone guuid=269fe9b7-1600-0000-86aa-a296b30c0000 pid=3251 /usr/bin/bash guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=269fe9b7-1600-0000-86aa-a296b30c0000 pid=3251 execve guuid=5b1c5fb8-1600-0000-86aa-a296b50c0000 pid=3253 /usr/bin/rm guuid=f3e729a0-1600-0000-86aa-a296760c0000 pid=3190->guuid=5b1c5fb8-1600-0000-86aa-a296b50c0000 pid=3253 execve guuid=8f1238b0-1600-0000-86aa-a296a00c0000 pid=3232 /usr/bin/bash guuid=34e6d0af-1600-0000-86aa-a2969f0c0000 pid=3231->guuid=8f1238b0-1600-0000-86aa-a296a00c0000 pid=3232 clone guuid=00453fb0-1600-0000-86aa-a296a10c0000 pid=3233 /usr/bin/bash guuid=34e6d0af-1600-0000-86aa-a2969f0c0000 pid=3231->guuid=00453fb0-1600-0000-86aa-a296a10c0000 pid=3233 clone guuid=e56a63b0-1600-0000-86aa-a296a20c0000 pid=3234 /usr/bin/ls guuid=34e6d0af-1600-0000-86aa-a2969f0c0000 pid=3231->guuid=e56a63b0-1600-0000-86aa-a296a20c0000 pid=3234 execve guuid=9e7cffb0-1600-0000-86aa-a296a30c0000 pid=3235 /usr/bin/cat guuid=34e6d0af-1600-0000-86aa-a2969f0c0000 pid=3231->guuid=9e7cffb0-1600-0000-86aa-a296a30c0000 pid=3235 execve guuid=c5629eb1-1600-0000-86aa-a296a40c0000 pid=3236 /usr/bin/ls guuid=34e6d0af-1600-0000-86aa-a2969f0c0000 pid=3231->guuid=c5629eb1-1600-0000-86aa-a296a40c0000 pid=3236 execve guuid=682b2ab2-1600-0000-86aa-a296a50c0000 pid=3237 /usr/bin/mkdir guuid=34e6d0af-1600-0000-86aa-a2969f0c0000 pid=3231->guuid=682b2ab2-1600-0000-86aa-a296a50c0000 pid=3237 execve guuid=b187d3b2-1600-0000-86aa-a296a60c0000 pid=3238 /usr/bin/mv guuid=34e6d0af-1600-0000-86aa-a2969f0c0000 pid=3231->guuid=b187d3b2-1600-0000-86aa-a296a60c0000 pid=3238 execve guuid=e5b97fb3-1600-0000-86aa-a296a70c0000 pid=3239 /usr/bin/bash guuid=34e6d0af-1600-0000-86aa-a2969f0c0000 pid=3231->guuid=e5b97fb3-1600-0000-86aa-a296a70c0000 pid=3239 clone guuid=05c787b3-1600-0000-86aa-a296a80c0000 pid=3240 /usr/bin/base64 write-file guuid=34e6d0af-1600-0000-86aa-a2969f0c0000 pid=3231->guuid=05c787b3-1600-0000-86aa-a296a80c0000 pid=3240 execve guuid=8eed25b4-1600-0000-86aa-a296a90c0000 pid=3241 /usr/bin/rm delete-file guuid=34e6d0af-1600-0000-86aa-a2969f0c0000 pid=3231->guuid=8eed25b4-1600-0000-86aa-a296a90c0000 pid=3241 execve guuid=d59385b4-1600-0000-86aa-a296aa0c0000 pid=3242 /usr/bin/ls guuid=34e6d0af-1600-0000-86aa-a2969f0c0000 pid=3231->guuid=d59385b4-1600-0000-86aa-a296aa0c0000 pid=3242 execve guuid=111a13b5-1600-0000-86aa-a296ab0c0000 pid=3243 /usr/bin/bash guuid=34e6d0af-1600-0000-86aa-a2969f0c0000 pid=3231->guuid=111a13b5-1600-0000-86aa-a296ab0c0000 pid=3243 clone guuid=a75a1eb5-1600-0000-86aa-a296ac0c0000 pid=3244 /usr/bin/base64 write-file guuid=34e6d0af-1600-0000-86aa-a2969f0c0000 pid=3231->guuid=a75a1eb5-1600-0000-86aa-a296ac0c0000 pid=3244 execve guuid=2b04a2b5-1600-0000-86aa-a296ad0c0000 pid=3245 /usr/bin/ls guuid=34e6d0af-1600-0000-86aa-a2969f0c0000 pid=3231->guuid=2b04a2b5-1600-0000-86aa-a296ad0c0000 pid=3245 execve guuid=027a30b6-1600-0000-86aa-a296ae0c0000 pid=3246 /usr/bin/cat guuid=34e6d0af-1600-0000-86aa-a2969f0c0000 pid=3231->guuid=027a30b6-1600-0000-86aa-a296ae0c0000 pid=3246 execve guuid=0c6588b6-1600-0000-86aa-a296af0c0000 pid=3247 /usr/bin/ls guuid=34e6d0af-1600-0000-86aa-a2969f0c0000 pid=3231->guuid=0c6588b6-1600-0000-86aa-a296af0c0000 pid=3247 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Gathering data
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 58a84e7f892cdf58116e79555debf2e2a30daff8158594ca770ddab845237576

(this sample)

  
Delivery method
Distributed via web download

Comments