MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 73801526437b53c9b5df8e7b59c70ab10e8e86fe44fb21e7ba017b4a6acbd4de. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 73801526437b53c9b5df8e7b59c70ab10e8e86fe44fb21e7ba017b4a6acbd4de
SHA3-384 hash: 3b0dc2b1707697dceebf8708aaddc539746527ac866d4811bdbca15e4471eeb070c54399fcdcf2b997910a70df1e1fc6
SHA1 hash: 3fc03952ce9b4e0f0e643500d7658dfb953082e4
MD5 hash: 710901b0b8a2894f9ff7a6f8754a2342
humanhash: illinois-robert-maine-carolina
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-11 21:16:17 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:JFcuQpWx+BL0SWL0gFzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:JF8i+BL0SI0+zsP4cbddr7zsP4cbddrk
TLSH T10F925CB512896C79FBD0CE39AF3C6F4DADE8C2C42124A3ACBA4F39215A1166DC705359
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=9a3ea979-1600-0000-eaef-49e636100000 pid=4150 /usr/bin/sudo guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154 /tmp/sample.bin guuid=9a3ea979-1600-0000-eaef-49e636100000 pid=4150->guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154 execve guuid=79cd297c-1600-0000-eaef-49e63c100000 pid=4156 /usr/bin/bash guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=79cd297c-1600-0000-eaef-49e63c100000 pid=4156 clone guuid=0705327c-1600-0000-eaef-49e63e100000 pid=4158 /usr/bin/bash guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=0705327c-1600-0000-eaef-49e63e100000 pid=4158 clone guuid=777d647c-1600-0000-eaef-49e640100000 pid=4160 /usr/bin/mkdir guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=777d647c-1600-0000-eaef-49e640100000 pid=4160 execve guuid=73b1c37c-1600-0000-eaef-49e643100000 pid=4163 /usr/bin/mkdir guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=73b1c37c-1600-0000-eaef-49e643100000 pid=4163 execve guuid=f8fe157d-1600-0000-eaef-49e645100000 pid=4165 /usr/bin/mkdir guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=f8fe157d-1600-0000-eaef-49e645100000 pid=4165 execve guuid=dc596d7d-1600-0000-eaef-49e646100000 pid=4166 /usr/bin/mkdir guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=dc596d7d-1600-0000-eaef-49e646100000 pid=4166 execve guuid=b62eb77d-1600-0000-eaef-49e64a100000 pid=4170 /usr/bin/mkdir guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=b62eb77d-1600-0000-eaef-49e64a100000 pid=4170 execve guuid=7888047e-1600-0000-eaef-49e64b100000 pid=4171 /usr/bin/mkdir guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=7888047e-1600-0000-eaef-49e64b100000 pid=4171 execve guuid=603f4c7e-1600-0000-eaef-49e64f100000 pid=4175 /usr/bin/mkdir guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=603f4c7e-1600-0000-eaef-49e64f100000 pid=4175 execve guuid=def4947e-1600-0000-eaef-49e651100000 pid=4177 /usr/bin/cp guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=def4947e-1600-0000-eaef-49e651100000 pid=4177 execve guuid=9027ea7e-1600-0000-eaef-49e654100000 pid=4180 /usr/bin/cp guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=9027ea7e-1600-0000-eaef-49e654100000 pid=4180 execve guuid=340c3c7f-1600-0000-eaef-49e656100000 pid=4182 /usr/bin/cp guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=340c3c7f-1600-0000-eaef-49e656100000 pid=4182 execve guuid=8f4b927f-1600-0000-eaef-49e658100000 pid=4184 /usr/bin/cp guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=8f4b927f-1600-0000-eaef-49e658100000 pid=4184 execve guuid=c363e87f-1600-0000-eaef-49e65b100000 pid=4187 /usr/bin/cp guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=c363e87f-1600-0000-eaef-49e65b100000 pid=4187 execve guuid=8df44380-1600-0000-eaef-49e65d100000 pid=4189 /usr/bin/cp guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=8df44380-1600-0000-eaef-49e65d100000 pid=4189 execve guuid=a37fa980-1600-0000-eaef-49e661100000 pid=4193 /usr/bin/cp guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=a37fa980-1600-0000-eaef-49e661100000 pid=4193 execve guuid=c34c1381-1600-0000-eaef-49e665100000 pid=4197 /usr/bin/cp guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=c34c1381-1600-0000-eaef-49e665100000 pid=4197 execve guuid=82449881-1600-0000-eaef-49e666100000 pid=4198 /usr/bin/cp guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=82449881-1600-0000-eaef-49e666100000 pid=4198 execve guuid=f3ccff81-1600-0000-eaef-49e668100000 pid=4200 /usr/bin/cp guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=f3ccff81-1600-0000-eaef-49e668100000 pid=4200 execve guuid=c83f6382-1600-0000-eaef-49e66b100000 pid=4203 /usr/bin/cp guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=c83f6382-1600-0000-eaef-49e66b100000 pid=4203 execve guuid=6f78d082-1600-0000-eaef-49e66d100000 pid=4205 /usr/bin/cp guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=6f78d082-1600-0000-eaef-49e66d100000 pid=4205 execve guuid=03c83883-1600-0000-eaef-49e670100000 pid=4208 /usr/bin/cp guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=03c83883-1600-0000-eaef-49e670100000 pid=4208 execve guuid=23079083-1600-0000-eaef-49e672100000 pid=4210 /usr/bin/cp guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=23079083-1600-0000-eaef-49e672100000 pid=4210 execve guuid=7b52fa83-1600-0000-eaef-49e675100000 pid=4213 /usr/bin/cp guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=7b52fa83-1600-0000-eaef-49e675100000 pid=4213 execve guuid=8a3b6684-1600-0000-eaef-49e679100000 pid=4217 /usr/bin/touch guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=8a3b6684-1600-0000-eaef-49e679100000 pid=4217 execve guuid=c223aa84-1600-0000-eaef-49e67c100000 pid=4220 /usr/bin/bash guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=c223aa84-1600-0000-eaef-49e67c100000 pid=4220 clone guuid=80c4af84-1600-0000-eaef-49e67d100000 pid=4221 /usr/bin/bash guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=80c4af84-1600-0000-eaef-49e67d100000 pid=4221 clone guuid=a0a3cb84-1600-0000-eaef-49e67e100000 pid=4222 /usr/bin/bash guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=a0a3cb84-1600-0000-eaef-49e67e100000 pid=4222 clone guuid=4a1ad484-1600-0000-eaef-49e67f100000 pid=4223 /usr/bin/base64 write-file guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=4a1ad484-1600-0000-eaef-49e67f100000 pid=4223 execve guuid=118a5985-1600-0000-eaef-49e683100000 pid=4227 /usr/bin/bash guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=118a5985-1600-0000-eaef-49e683100000 pid=4227 execve guuid=0374208a-1600-0000-eaef-49e6a8100000 pid=4264 /usr/bin/rm delete-file guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=0374208a-1600-0000-eaef-49e6a8100000 pid=4264 execve guuid=f1ba658a-1600-0000-eaef-49e6aa100000 pid=4266 /usr/bin/bash guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=f1ba658a-1600-0000-eaef-49e6aa100000 pid=4266 clone guuid=f92f6c8a-1600-0000-eaef-49e6ab100000 pid=4267 /usr/bin/bash guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=f92f6c8a-1600-0000-eaef-49e6ab100000 pid=4267 clone guuid=1e43938a-1600-0000-eaef-49e6af100000 pid=4271 /usr/bin/bash guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=1e43938a-1600-0000-eaef-49e6af100000 pid=4271 execve guuid=4410eb8a-1600-0000-eaef-49e6b2100000 pid=4274 /usr/bin/rm guuid=9b0ebc7b-1600-0000-eaef-49e63a100000 pid=4154->guuid=4410eb8a-1600-0000-eaef-49e6b2100000 pid=4274 execve guuid=84f1a485-1600-0000-eaef-49e686100000 pid=4230 /usr/bin/bash guuid=118a5985-1600-0000-eaef-49e683100000 pid=4227->guuid=84f1a485-1600-0000-eaef-49e686100000 pid=4230 clone guuid=0b24b085-1600-0000-eaef-49e687100000 pid=4231 /usr/bin/bash guuid=118a5985-1600-0000-eaef-49e683100000 pid=4227->guuid=0b24b085-1600-0000-eaef-49e687100000 pid=4231 clone guuid=56d3d285-1600-0000-eaef-49e688100000 pid=4232 /usr/bin/ls guuid=118a5985-1600-0000-eaef-49e683100000 pid=4227->guuid=56d3d285-1600-0000-eaef-49e688100000 pid=4232 execve guuid=589f4686-1600-0000-eaef-49e68c100000 pid=4236 /usr/bin/cat guuid=118a5985-1600-0000-eaef-49e683100000 pid=4227->guuid=589f4686-1600-0000-eaef-49e68c100000 pid=4236 execve guuid=30149186-1600-0000-eaef-49e68e100000 pid=4238 /usr/bin/ls guuid=118a5985-1600-0000-eaef-49e683100000 pid=4227->guuid=30149186-1600-0000-eaef-49e68e100000 pid=4238 execve guuid=b218fd86-1600-0000-eaef-49e690100000 pid=4240 /usr/bin/mkdir guuid=118a5985-1600-0000-eaef-49e683100000 pid=4227->guuid=b218fd86-1600-0000-eaef-49e690100000 pid=4240 execve guuid=6f794e87-1600-0000-eaef-49e693100000 pid=4243 /usr/bin/mv guuid=118a5985-1600-0000-eaef-49e683100000 pid=4227->guuid=6f794e87-1600-0000-eaef-49e693100000 pid=4243 execve guuid=960ea987-1600-0000-eaef-49e695100000 pid=4245 /usr/bin/bash guuid=118a5985-1600-0000-eaef-49e683100000 pid=4227->guuid=960ea987-1600-0000-eaef-49e695100000 pid=4245 clone guuid=0849ae87-1600-0000-eaef-49e696100000 pid=4246 /usr/bin/base64 write-file guuid=118a5985-1600-0000-eaef-49e683100000 pid=4227->guuid=0849ae87-1600-0000-eaef-49e696100000 pid=4246 execve guuid=b673f587-1600-0000-eaef-49e698100000 pid=4248 /usr/bin/rm delete-file guuid=118a5985-1600-0000-eaef-49e683100000 pid=4227->guuid=b673f587-1600-0000-eaef-49e698100000 pid=4248 execve guuid=e0893388-1600-0000-eaef-49e69a100000 pid=4250 /usr/bin/ls guuid=118a5985-1600-0000-eaef-49e683100000 pid=4227->guuid=e0893388-1600-0000-eaef-49e69a100000 pid=4250 execve guuid=aeb49088-1600-0000-eaef-49e69c100000 pid=4252 /usr/bin/bash guuid=118a5985-1600-0000-eaef-49e683100000 pid=4227->guuid=aeb49088-1600-0000-eaef-49e69c100000 pid=4252 clone guuid=e1db9888-1600-0000-eaef-49e69d100000 pid=4253 /usr/bin/base64 write-file guuid=118a5985-1600-0000-eaef-49e683100000 pid=4227->guuid=e1db9888-1600-0000-eaef-49e69d100000 pid=4253 execve guuid=a819ec88-1600-0000-eaef-49e6a1100000 pid=4257 /usr/bin/ls guuid=118a5985-1600-0000-eaef-49e683100000 pid=4227->guuid=a819ec88-1600-0000-eaef-49e6a1100000 pid=4257 execve guuid=51dd6889-1600-0000-eaef-49e6a2100000 pid=4258 /usr/bin/cat guuid=118a5985-1600-0000-eaef-49e683100000 pid=4227->guuid=51dd6889-1600-0000-eaef-49e6a2100000 pid=4258 execve guuid=e94fa989-1600-0000-eaef-49e6a6100000 pid=4262 /usr/bin/ls guuid=118a5985-1600-0000-eaef-49e683100000 pid=4227->guuid=e94fa989-1600-0000-eaef-49e6a6100000 pid=4262 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-11 21:17:50 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 73801526437b53c9b5df8e7b59c70ab10e8e86fe44fb21e7ba017b4a6acbd4de

(this sample)

  
Delivery method
Distributed via web download

Comments