MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6d55a4ac37e4ee13b06c5b84f81b1958f72c9056c4562b6c92b4cf757c9715d7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 6d55a4ac37e4ee13b06c5b84f81b1958f72c9056c4562b6c92b4cf757c9715d7
SHA3-384 hash: b314142f69b4e1ccc9c39ade3d2a8c4ba2e8f157e2794b88fea367045353c208daab82dbf703813b4130114f2133cd22
SHA1 hash: 07ef968b902e0ac6d986d08aa962f890eb24bbde
MD5 hash: b6ae3d23c96fd62591ce359f2cfe2f0d
humanhash: california-october-six-quebec
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-09 15:50:30 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:SYcuQpWx+BL0SWL0gmzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:SY8i+BL0SI0VzsP4cbddr7zsP4cbddrk
TLSH T118924CB412496C79FBD1CE39AF3C7F4CADE882C42124A3ADBA0F39215A1166DC705349
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
47
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=68356ea5-1600-0000-8c4b-83d6800f0000 pid=3968 /usr/bin/sudo guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975 /tmp/sample.bin guuid=68356ea5-1600-0000-8c4b-83d6800f0000 pid=3968->guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975 execve guuid=9ca98ea8-1600-0000-8c4b-83d6890f0000 pid=3977 /usr/bin/bash guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=9ca98ea8-1600-0000-8c4b-83d6890f0000 pid=3977 clone guuid=5d2a97a8-1600-0000-8c4b-83d68a0f0000 pid=3978 /usr/bin/bash guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=5d2a97a8-1600-0000-8c4b-83d68a0f0000 pid=3978 clone guuid=e078c2a8-1600-0000-8c4b-83d68c0f0000 pid=3980 /usr/bin/mkdir guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=e078c2a8-1600-0000-8c4b-83d68c0f0000 pid=3980 execve guuid=4e363aa9-1600-0000-8c4b-83d6900f0000 pid=3984 /usr/bin/mkdir guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=4e363aa9-1600-0000-8c4b-83d6900f0000 pid=3984 execve guuid=ffe3cca9-1600-0000-8c4b-83d6920f0000 pid=3986 /usr/bin/mkdir guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=ffe3cca9-1600-0000-8c4b-83d6920f0000 pid=3986 execve guuid=19d42daa-1600-0000-8c4b-83d6950f0000 pid=3989 /usr/bin/mkdir guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=19d42daa-1600-0000-8c4b-83d6950f0000 pid=3989 execve guuid=8d8abdaa-1600-0000-8c4b-83d6970f0000 pid=3991 /usr/bin/mkdir guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=8d8abdaa-1600-0000-8c4b-83d6970f0000 pid=3991 execve guuid=0b733eab-1600-0000-8c4b-83d6990f0000 pid=3993 /usr/bin/mkdir guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=0b733eab-1600-0000-8c4b-83d6990f0000 pid=3993 execve guuid=11e2bdab-1600-0000-8c4b-83d69d0f0000 pid=3997 /usr/bin/mkdir guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=11e2bdab-1600-0000-8c4b-83d69d0f0000 pid=3997 execve guuid=df031bac-1600-0000-8c4b-83d6a10f0000 pid=4001 /usr/bin/cp guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=df031bac-1600-0000-8c4b-83d6a10f0000 pid=4001 execve guuid=221080ac-1600-0000-8c4b-83d6a20f0000 pid=4002 /usr/bin/cp guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=221080ac-1600-0000-8c4b-83d6a20f0000 pid=4002 execve guuid=e4581dad-1600-0000-8c4b-83d6a60f0000 pid=4006 /usr/bin/cp guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=e4581dad-1600-0000-8c4b-83d6a60f0000 pid=4006 execve guuid=94d4a7ad-1600-0000-8c4b-83d6a80f0000 pid=4008 /usr/bin/cp guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=94d4a7ad-1600-0000-8c4b-83d6a80f0000 pid=4008 execve guuid=422d09ae-1600-0000-8c4b-83d6ab0f0000 pid=4011 /usr/bin/cp guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=422d09ae-1600-0000-8c4b-83d6ab0f0000 pid=4011 execve guuid=d183c5ae-1600-0000-8c4b-83d6ae0f0000 pid=4014 /usr/bin/cp guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=d183c5ae-1600-0000-8c4b-83d6ae0f0000 pid=4014 execve guuid=f4525eaf-1600-0000-8c4b-83d6b50f0000 pid=4021 /usr/bin/cp guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=f4525eaf-1600-0000-8c4b-83d6b50f0000 pid=4021 execve guuid=b93f42b0-1600-0000-8c4b-83d6b70f0000 pid=4023 /usr/bin/cp guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=b93f42b0-1600-0000-8c4b-83d6b70f0000 pid=4023 execve guuid=24b9f4b0-1600-0000-8c4b-83d6bb0f0000 pid=4027 /usr/bin/cp guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=24b9f4b0-1600-0000-8c4b-83d6bb0f0000 pid=4027 execve guuid=0b434cb1-1600-0000-8c4b-83d6bd0f0000 pid=4029 /usr/bin/cp guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=0b434cb1-1600-0000-8c4b-83d6bd0f0000 pid=4029 execve guuid=86d7e2b1-1600-0000-8c4b-83d6c00f0000 pid=4032 /usr/bin/cp guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=86d7e2b1-1600-0000-8c4b-83d6c00f0000 pid=4032 execve guuid=9be33ab2-1600-0000-8c4b-83d6c20f0000 pid=4034 /usr/bin/cp guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=9be33ab2-1600-0000-8c4b-83d6c20f0000 pid=4034 execve guuid=976ab1b2-1600-0000-8c4b-83d6c60f0000 pid=4038 /usr/bin/cp guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=976ab1b2-1600-0000-8c4b-83d6c60f0000 pid=4038 execve guuid=476b31b3-1600-0000-8c4b-83d6ca0f0000 pid=4042 /usr/bin/cp guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=476b31b3-1600-0000-8c4b-83d6ca0f0000 pid=4042 execve guuid=684eaeb3-1600-0000-8c4b-83d6cd0f0000 pid=4045 /usr/bin/cp guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=684eaeb3-1600-0000-8c4b-83d6cd0f0000 pid=4045 execve guuid=0f983ab4-1600-0000-8c4b-83d6ce0f0000 pid=4046 /usr/bin/touch guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=0f983ab4-1600-0000-8c4b-83d6ce0f0000 pid=4046 execve guuid=ee69b0b4-1600-0000-8c4b-83d6d20f0000 pid=4050 /usr/bin/bash guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=ee69b0b4-1600-0000-8c4b-83d6d20f0000 pid=4050 clone guuid=c75eb6b4-1600-0000-8c4b-83d6d30f0000 pid=4051 /usr/bin/bash guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=c75eb6b4-1600-0000-8c4b-83d6d30f0000 pid=4051 clone guuid=d902deb4-1600-0000-8c4b-83d6d40f0000 pid=4052 /usr/bin/bash guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=d902deb4-1600-0000-8c4b-83d6d40f0000 pid=4052 clone guuid=c794eab4-1600-0000-8c4b-83d6d50f0000 pid=4053 /usr/bin/base64 write-file guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=c794eab4-1600-0000-8c4b-83d6d50f0000 pid=4053 execve guuid=1f6d6db5-1600-0000-8c4b-83d6d90f0000 pid=4057 /usr/bin/bash guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=1f6d6db5-1600-0000-8c4b-83d6d90f0000 pid=4057 execve guuid=77f142bb-1600-0000-8c4b-83d6f80f0000 pid=4088 /usr/bin/rm delete-file guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=77f142bb-1600-0000-8c4b-83d6f80f0000 pid=4088 execve guuid=54309ebb-1600-0000-8c4b-83d6fc0f0000 pid=4092 /usr/bin/bash guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=54309ebb-1600-0000-8c4b-83d6fc0f0000 pid=4092 clone guuid=f338a5bb-1600-0000-8c4b-83d6fd0f0000 pid=4093 /usr/bin/bash guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=f338a5bb-1600-0000-8c4b-83d6fd0f0000 pid=4093 clone guuid=9c071ebc-1600-0000-8c4b-83d6ff0f0000 pid=4095 /usr/bin/bash guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=9c071ebc-1600-0000-8c4b-83d6ff0f0000 pid=4095 execve guuid=6b5799bc-1600-0000-8c4b-83d603100000 pid=4099 /usr/bin/rm guuid=b0b6ffa7-1600-0000-8c4b-83d6870f0000 pid=3975->guuid=6b5799bc-1600-0000-8c4b-83d603100000 pid=4099 execve guuid=aa2d08b6-1600-0000-8c4b-83d6da0f0000 pid=4058 /usr/bin/bash guuid=1f6d6db5-1600-0000-8c4b-83d6d90f0000 pid=4057->guuid=aa2d08b6-1600-0000-8c4b-83d6da0f0000 pid=4058 clone guuid=c36f1eb6-1600-0000-8c4b-83d6db0f0000 pid=4059 /usr/bin/bash guuid=1f6d6db5-1600-0000-8c4b-83d6d90f0000 pid=4057->guuid=c36f1eb6-1600-0000-8c4b-83d6db0f0000 pid=4059 clone guuid=5d354ab6-1600-0000-8c4b-83d6dc0f0000 pid=4060 /usr/bin/ls guuid=1f6d6db5-1600-0000-8c4b-83d6d90f0000 pid=4057->guuid=5d354ab6-1600-0000-8c4b-83d6dc0f0000 pid=4060 execve guuid=2086d4b6-1600-0000-8c4b-83d6dd0f0000 pid=4061 /usr/bin/cat guuid=1f6d6db5-1600-0000-8c4b-83d6d90f0000 pid=4057->guuid=2086d4b6-1600-0000-8c4b-83d6dd0f0000 pid=4061 execve guuid=7d7125b7-1600-0000-8c4b-83d6df0f0000 pid=4063 /usr/bin/ls guuid=1f6d6db5-1600-0000-8c4b-83d6d90f0000 pid=4057->guuid=7d7125b7-1600-0000-8c4b-83d6df0f0000 pid=4063 execve guuid=5fa09db7-1600-0000-8c4b-83d6e10f0000 pid=4065 /usr/bin/mkdir guuid=1f6d6db5-1600-0000-8c4b-83d6d90f0000 pid=4057->guuid=5fa09db7-1600-0000-8c4b-83d6e10f0000 pid=4065 execve guuid=3254f7b7-1600-0000-8c4b-83d6e30f0000 pid=4067 /usr/bin/mv guuid=1f6d6db5-1600-0000-8c4b-83d6d90f0000 pid=4057->guuid=3254f7b7-1600-0000-8c4b-83d6e30f0000 pid=4067 execve guuid=da6f5db8-1600-0000-8c4b-83d6e50f0000 pid=4069 /usr/bin/bash guuid=1f6d6db5-1600-0000-8c4b-83d6d90f0000 pid=4057->guuid=da6f5db8-1600-0000-8c4b-83d6e50f0000 pid=4069 clone guuid=400763b8-1600-0000-8c4b-83d6e60f0000 pid=4070 /usr/bin/base64 write-file guuid=1f6d6db5-1600-0000-8c4b-83d6d90f0000 pid=4057->guuid=400763b8-1600-0000-8c4b-83d6e60f0000 pid=4070 execve guuid=70eab4b8-1600-0000-8c4b-83d6e80f0000 pid=4072 /usr/bin/rm delete-file guuid=1f6d6db5-1600-0000-8c4b-83d6d90f0000 pid=4057->guuid=70eab4b8-1600-0000-8c4b-83d6e80f0000 pid=4072 execve guuid=e943f4b8-1600-0000-8c4b-83d6eb0f0000 pid=4075 /usr/bin/ls guuid=1f6d6db5-1600-0000-8c4b-83d6d90f0000 pid=4057->guuid=e943f4b8-1600-0000-8c4b-83d6eb0f0000 pid=4075 execve guuid=da9f8cb9-1600-0000-8c4b-83d6ee0f0000 pid=4078 /usr/bin/bash guuid=1f6d6db5-1600-0000-8c4b-83d6d90f0000 pid=4057->guuid=da9f8cb9-1600-0000-8c4b-83d6ee0f0000 pid=4078 clone guuid=160894b9-1600-0000-8c4b-83d6ef0f0000 pid=4079 /usr/bin/base64 write-file guuid=1f6d6db5-1600-0000-8c4b-83d6d90f0000 pid=4057->guuid=160894b9-1600-0000-8c4b-83d6ef0f0000 pid=4079 execve guuid=4cbaecb9-1600-0000-8c4b-83d6f30f0000 pid=4083 /usr/bin/ls guuid=1f6d6db5-1600-0000-8c4b-83d6d90f0000 pid=4057->guuid=4cbaecb9-1600-0000-8c4b-83d6f30f0000 pid=4083 execve guuid=68db4fba-1600-0000-8c4b-83d6f40f0000 pid=4084 /usr/bin/cat guuid=1f6d6db5-1600-0000-8c4b-83d6d90f0000 pid=4057->guuid=68db4fba-1600-0000-8c4b-83d6f40f0000 pid=4084 execve guuid=6317adba-1600-0000-8c4b-83d6f50f0000 pid=4085 /usr/bin/ls guuid=1f6d6db5-1600-0000-8c4b-83d6d90f0000 pid=4057->guuid=6317adba-1600-0000-8c4b-83d6f50f0000 pid=4085 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-09 15:51:23 UTC
File Type:
Text (Shell)
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 6d55a4ac37e4ee13b06c5b84f81b1958f72c9056c4562b6c92b4cf757c9715d7

(this sample)

  
Delivery method
Distributed via web download

Comments