MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6b7497aa426d9d0f44f3d505965080d9315ab9dd5fbfc208cfa346c6b5879505. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 6b7497aa426d9d0f44f3d505965080d9315ab9dd5fbfc208cfa346c6b5879505
SHA3-384 hash: 072ae61792a6105a420689d058dec3abd83f7dbaa20a37a1dff632a76347bc43161c4a35bf0eddc16806e7849e62cba7
SHA1 hash: ca7241491c27932b132c776debfa92ef83910d27
MD5 hash: abfc40c5d7347f95c520232f322577ed
humanhash: november-wisconsin-charlie-foxtrot
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-17 09:32:02 UTC
Last seen:2026-03-18 00:11:58 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 384:gw0M3vgRjGlsaq70zsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:gCmjfAzsP4cbddr7zsP4cbddrk
TLSH T17E925BA916496C79BBC1CE7D9F3C7F0CADE481C02218A39CBE4F39714A2469DDA0635D
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
2
# of downloads :
83
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=3d24f232-1700-0000-964a-9993410f0000 pid=3905 /usr/bin/sudo guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914 /tmp/sample.bin guuid=3d24f232-1700-0000-964a-9993410f0000 pid=3905->guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914 execve guuid=568c2635-1700-0000-964a-99934e0f0000 pid=3918 /usr/bin/bash guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=568c2635-1700-0000-964a-99934e0f0000 pid=3918 clone guuid=ea412f35-1700-0000-964a-99934f0f0000 pid=3919 /usr/bin/bash guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=ea412f35-1700-0000-964a-99934f0f0000 pid=3919 clone guuid=fd7c6835-1700-0000-964a-9993500f0000 pid=3920 /usr/bin/mkdir guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=fd7c6835-1700-0000-964a-9993500f0000 pid=3920 execve guuid=03e2c435-1700-0000-964a-9993540f0000 pid=3924 /usr/bin/mkdir guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=03e2c435-1700-0000-964a-9993540f0000 pid=3924 execve guuid=15341836-1700-0000-964a-9993580f0000 pid=3928 /usr/bin/mkdir guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=15341836-1700-0000-964a-9993580f0000 pid=3928 execve guuid=3a657436-1700-0000-964a-9993590f0000 pid=3929 /usr/bin/mkdir guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=3a657436-1700-0000-964a-9993590f0000 pid=3929 execve guuid=2217c436-1700-0000-964a-99935b0f0000 pid=3931 /usr/bin/mkdir guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=2217c436-1700-0000-964a-99935b0f0000 pid=3931 execve guuid=18351837-1700-0000-964a-99935d0f0000 pid=3933 /usr/bin/mkdir guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=18351837-1700-0000-964a-99935d0f0000 pid=3933 execve guuid=b49a6437-1700-0000-964a-9993610f0000 pid=3937 /usr/bin/mkdir guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=b49a6437-1700-0000-964a-9993610f0000 pid=3937 execve guuid=1c06b237-1700-0000-964a-9993650f0000 pid=3941 /usr/bin/cp guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=1c06b237-1700-0000-964a-9993650f0000 pid=3941 execve guuid=c00f1f38-1700-0000-964a-9993670f0000 pid=3943 /usr/bin/cp guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=c00f1f38-1700-0000-964a-9993670f0000 pid=3943 execve guuid=54fb8538-1700-0000-964a-9993690f0000 pid=3945 /usr/bin/cp guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=54fb8538-1700-0000-964a-9993690f0000 pid=3945 execve guuid=2771ee38-1700-0000-964a-99936c0f0000 pid=3948 /usr/bin/cp guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=2771ee38-1700-0000-964a-99936c0f0000 pid=3948 execve guuid=59dc4d39-1700-0000-964a-99936f0f0000 pid=3951 /usr/bin/cp guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=59dc4d39-1700-0000-964a-99936f0f0000 pid=3951 execve guuid=7fd9aa39-1700-0000-964a-9993710f0000 pid=3953 /usr/bin/cp guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=7fd9aa39-1700-0000-964a-9993710f0000 pid=3953 execve guuid=dfca163a-1700-0000-964a-9993740f0000 pid=3956 /usr/bin/cp guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=dfca163a-1700-0000-964a-9993740f0000 pid=3956 execve guuid=cee96d3a-1700-0000-964a-9993760f0000 pid=3958 /usr/bin/cp guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=cee96d3a-1700-0000-964a-9993760f0000 pid=3958 execve guuid=aa5fd43a-1700-0000-964a-9993780f0000 pid=3960 /usr/bin/cp guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=aa5fd43a-1700-0000-964a-9993780f0000 pid=3960 execve guuid=2ba63e3b-1700-0000-964a-99937c0f0000 pid=3964 /usr/bin/cp guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=2ba63e3b-1700-0000-964a-99937c0f0000 pid=3964 execve guuid=59e6af3b-1700-0000-964a-99937f0f0000 pid=3967 /usr/bin/cp guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=59e6af3b-1700-0000-964a-99937f0f0000 pid=3967 execve guuid=2532173c-1700-0000-964a-9993830f0000 pid=3971 /usr/bin/cp guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=2532173c-1700-0000-964a-9993830f0000 pid=3971 execve guuid=c0ac6b3c-1700-0000-964a-9993850f0000 pid=3973 /usr/bin/cp guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=c0ac6b3c-1700-0000-964a-9993850f0000 pid=3973 execve guuid=76bbdc3c-1700-0000-964a-9993890f0000 pid=3977 /usr/bin/cp guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=76bbdc3c-1700-0000-964a-9993890f0000 pid=3977 execve guuid=2f032d3d-1700-0000-964a-99938d0f0000 pid=3981 /usr/bin/cp guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=2f032d3d-1700-0000-964a-99938d0f0000 pid=3981 execve guuid=0452883d-1700-0000-964a-99938f0f0000 pid=3983 /usr/bin/touch guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=0452883d-1700-0000-964a-99938f0f0000 pid=3983 execve guuid=0224c53d-1700-0000-964a-9993910f0000 pid=3985 /usr/bin/bash guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=0224c53d-1700-0000-964a-9993910f0000 pid=3985 clone guuid=ebc6ca3d-1700-0000-964a-9993920f0000 pid=3986 /usr/bin/bash guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=ebc6ca3d-1700-0000-964a-9993920f0000 pid=3986 clone guuid=37c4e13d-1700-0000-964a-9993930f0000 pid=3987 /usr/bin/bash guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=37c4e13d-1700-0000-964a-9993930f0000 pid=3987 clone guuid=9e83e73d-1700-0000-964a-9993940f0000 pid=3988 /usr/bin/base64 write-file guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=9e83e73d-1700-0000-964a-9993940f0000 pid=3988 execve guuid=ad57a841-1700-0000-964a-99939a0f0000 pid=3994 /usr/bin/bash guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=ad57a841-1700-0000-964a-99939a0f0000 pid=3994 execve guuid=1837c547-1700-0000-964a-9993c20f0000 pid=4034 /usr/bin/rm delete-file guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=1837c547-1700-0000-964a-9993c20f0000 pid=4034 execve guuid=da740b48-1700-0000-964a-9993c60f0000 pid=4038 /usr/bin/bash guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=da740b48-1700-0000-964a-9993c60f0000 pid=4038 clone guuid=f76a1148-1700-0000-964a-9993c70f0000 pid=4039 /usr/bin/bash guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=f76a1148-1700-0000-964a-9993c70f0000 pid=4039 clone guuid=e2ef3848-1700-0000-964a-9993c80f0000 pid=4040 /usr/bin/bash guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=e2ef3848-1700-0000-964a-9993c80f0000 pid=4040 execve guuid=84739748-1700-0000-964a-9993cc0f0000 pid=4044 /usr/bin/rm guuid=0dd4ca34-1700-0000-964a-99934a0f0000 pid=3914->guuid=84739748-1700-0000-964a-9993cc0f0000 pid=4044 execve guuid=854d2642-1700-0000-964a-99939c0f0000 pid=3996 /usr/bin/bash guuid=ad57a841-1700-0000-964a-99939a0f0000 pid=3994->guuid=854d2642-1700-0000-964a-99939c0f0000 pid=3996 clone guuid=06a33042-1700-0000-964a-99939d0f0000 pid=3997 /usr/bin/bash guuid=ad57a841-1700-0000-964a-99939a0f0000 pid=3994->guuid=06a33042-1700-0000-964a-99939d0f0000 pid=3997 clone guuid=b0835642-1700-0000-964a-99939e0f0000 pid=3998 /usr/bin/ls guuid=ad57a841-1700-0000-964a-99939a0f0000 pid=3994->guuid=b0835642-1700-0000-964a-99939e0f0000 pid=3998 execve guuid=dafcdc42-1700-0000-964a-9993a20f0000 pid=4002 /usr/bin/cat guuid=ad57a841-1700-0000-964a-99939a0f0000 pid=3994->guuid=dafcdc42-1700-0000-964a-9993a20f0000 pid=4002 execve guuid=81e76443-1700-0000-964a-9993a60f0000 pid=4006 /usr/bin/ls guuid=ad57a841-1700-0000-964a-99939a0f0000 pid=3994->guuid=81e76443-1700-0000-964a-9993a60f0000 pid=4006 execve guuid=9c0a1a44-1700-0000-964a-9993aa0f0000 pid=4010 /usr/bin/mkdir guuid=ad57a841-1700-0000-964a-99939a0f0000 pid=3994->guuid=9c0a1a44-1700-0000-964a-9993aa0f0000 pid=4010 execve guuid=66289e44-1700-0000-964a-9993ac0f0000 pid=4012 /usr/bin/mv guuid=ad57a841-1700-0000-964a-99939a0f0000 pid=3994->guuid=66289e44-1700-0000-964a-9993ac0f0000 pid=4012 execve guuid=c7950245-1700-0000-964a-9993af0f0000 pid=4015 /usr/bin/bash guuid=ad57a841-1700-0000-964a-99939a0f0000 pid=3994->guuid=c7950245-1700-0000-964a-9993af0f0000 pid=4015 clone guuid=40000d45-1700-0000-964a-9993b00f0000 pid=4016 /usr/bin/base64 write-file guuid=ad57a841-1700-0000-964a-99939a0f0000 pid=3994->guuid=40000d45-1700-0000-964a-9993b00f0000 pid=4016 execve guuid=614f8545-1700-0000-964a-9993b20f0000 pid=4018 /usr/bin/rm delete-file guuid=ad57a841-1700-0000-964a-99939a0f0000 pid=3994->guuid=614f8545-1700-0000-964a-9993b20f0000 pid=4018 execve guuid=3586cd45-1700-0000-964a-9993b40f0000 pid=4020 /usr/bin/ls guuid=ad57a841-1700-0000-964a-99939a0f0000 pid=3994->guuid=3586cd45-1700-0000-964a-9993b40f0000 pid=4020 execve guuid=47673146-1700-0000-964a-9993b80f0000 pid=4024 /usr/bin/bash guuid=ad57a841-1700-0000-964a-99939a0f0000 pid=3994->guuid=47673146-1700-0000-964a-9993b80f0000 pid=4024 clone guuid=96be4246-1700-0000-964a-9993b90f0000 pid=4025 /usr/bin/base64 write-file guuid=ad57a841-1700-0000-964a-99939a0f0000 pid=3994->guuid=96be4246-1700-0000-964a-9993b90f0000 pid=4025 execve guuid=1c2c8e46-1700-0000-964a-9993ba0f0000 pid=4026 /usr/bin/ls guuid=ad57a841-1700-0000-964a-99939a0f0000 pid=3994->guuid=1c2c8e46-1700-0000-964a-9993ba0f0000 pid=4026 execve guuid=5e71ef46-1700-0000-964a-9993be0f0000 pid=4030 /usr/bin/cat guuid=ad57a841-1700-0000-964a-99939a0f0000 pid=3994->guuid=5e71ef46-1700-0000-964a-9993be0f0000 pid=4030 execve guuid=dfee5347-1700-0000-964a-9993c00f0000 pid=4032 /usr/bin/ls guuid=ad57a841-1700-0000-964a-99939a0f0000 pid=3994->guuid=dfee5347-1700-0000-964a-9993c00f0000 pid=4032 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-17 09:32:18 UTC
File Type:
Text (Shell)
AV detection:
10 of 22 (45.45%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 6b7497aa426d9d0f44f3d505965080d9315ab9dd5fbfc208cfa346c6b5879505

(this sample)

  
Delivery method
Distributed via web download

Comments