MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 73da98e3602154feaa51f689ad8edc031c95a8f14e24e71e934d726f2008acde. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 73da98e3602154feaa51f689ad8edc031c95a8f14e24e71e934d726f2008acde
SHA3-384 hash: d43c37e6c064844510a47cb71695b77ad5cc0002d16fb7bfeb4e1ec2fb0a3838809b252b7b99dcca69bfe1b214b59b68
SHA1 hash: fa29033df267e50dd8faecc4d1cd75618de38599
MD5 hash: b6fa63544e8d759691ec7bdb9ff803a6
humanhash: echo-leopard-fifteen-network
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-02-24 17:14:51 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:9vcuQpWx+BL0SWL0gszzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:9v8i+BL0SI0HzzsP4cbddr7zsP4cbddo
TLSH T16B925CB412896C79FBD1CE79AF3C7F4CADE8C2C42124A3ACBA4F39215A1166DC705359
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=86bb73dd-1600-0000-a676-c10f530f0000 pid=3923 /usr/bin/sudo guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931 /tmp/sample.bin guuid=86bb73dd-1600-0000-a676-c10f530f0000 pid=3923->guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931 execve guuid=4da838e0-1600-0000-a676-c10f610f0000 pid=3937 /usr/bin/bash guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=4da838e0-1600-0000-a676-c10f610f0000 pid=3937 clone guuid=925c44e0-1600-0000-a676-c10f620f0000 pid=3938 /usr/bin/bash guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=925c44e0-1600-0000-a676-c10f620f0000 pid=3938 clone guuid=4063e0e0-1600-0000-a676-c10f650f0000 pid=3941 /usr/bin/mkdir guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=4063e0e0-1600-0000-a676-c10f650f0000 pid=3941 execve guuid=7bbf33e1-1600-0000-a676-c10f670f0000 pid=3943 /usr/bin/mkdir guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=7bbf33e1-1600-0000-a676-c10f670f0000 pid=3943 execve guuid=e1e787e1-1600-0000-a676-c10f690f0000 pid=3945 /usr/bin/mkdir guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=e1e787e1-1600-0000-a676-c10f690f0000 pid=3945 execve guuid=ceb1d4e1-1600-0000-a676-c10f6a0f0000 pid=3946 /usr/bin/mkdir guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=ceb1d4e1-1600-0000-a676-c10f6a0f0000 pid=3946 execve guuid=8df91ae2-1600-0000-a676-c10f6c0f0000 pid=3948 /usr/bin/mkdir guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=8df91ae2-1600-0000-a676-c10f6c0f0000 pid=3948 execve guuid=92ab67e2-1600-0000-a676-c10f6d0f0000 pid=3949 /usr/bin/mkdir guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=92ab67e2-1600-0000-a676-c10f6d0f0000 pid=3949 execve guuid=8108b4e2-1600-0000-a676-c10f710f0000 pid=3953 /usr/bin/mkdir guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=8108b4e2-1600-0000-a676-c10f710f0000 pid=3953 execve guuid=874302e3-1600-0000-a676-c10f720f0000 pid=3954 /usr/bin/cp guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=874302e3-1600-0000-a676-c10f720f0000 pid=3954 execve guuid=1ce18fe3-1600-0000-a676-c10f750f0000 pid=3957 /usr/bin/cp guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=1ce18fe3-1600-0000-a676-c10f750f0000 pid=3957 execve guuid=2c4701e4-1600-0000-a676-c10f790f0000 pid=3961 /usr/bin/cp guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=2c4701e4-1600-0000-a676-c10f790f0000 pid=3961 execve guuid=ddbb88e4-1600-0000-a676-c10f7b0f0000 pid=3963 /usr/bin/cp guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=ddbb88e4-1600-0000-a676-c10f7b0f0000 pid=3963 execve guuid=816ae0e4-1600-0000-a676-c10f7f0f0000 pid=3967 /usr/bin/cp guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=816ae0e4-1600-0000-a676-c10f7f0f0000 pid=3967 execve guuid=66cc34e5-1600-0000-a676-c10f830f0000 pid=3971 /usr/bin/cp guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=66cc34e5-1600-0000-a676-c10f830f0000 pid=3971 execve guuid=e94b85e5-1600-0000-a676-c10f840f0000 pid=3972 /usr/bin/cp guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=e94b85e5-1600-0000-a676-c10f840f0000 pid=3972 execve guuid=0b23d5e5-1600-0000-a676-c10f870f0000 pid=3975 /usr/bin/cp guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=0b23d5e5-1600-0000-a676-c10f870f0000 pid=3975 execve guuid=556c2ae6-1600-0000-a676-c10f890f0000 pid=3977 /usr/bin/cp guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=556c2ae6-1600-0000-a676-c10f890f0000 pid=3977 execve guuid=22919fe6-1600-0000-a676-c10f8c0f0000 pid=3980 /usr/bin/cp guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=22919fe6-1600-0000-a676-c10f8c0f0000 pid=3980 execve guuid=eb4cf9e6-1600-0000-a676-c10f8f0f0000 pid=3983 /usr/bin/cp guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=eb4cf9e6-1600-0000-a676-c10f8f0f0000 pid=3983 execve guuid=1b5851e7-1600-0000-a676-c10f910f0000 pid=3985 /usr/bin/cp guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=1b5851e7-1600-0000-a676-c10f910f0000 pid=3985 execve guuid=8ae3b7e7-1600-0000-a676-c10f930f0000 pid=3987 /usr/bin/cp guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=8ae3b7e7-1600-0000-a676-c10f930f0000 pid=3987 execve guuid=8c8613e8-1600-0000-a676-c10f960f0000 pid=3990 /usr/bin/cp guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=8c8613e8-1600-0000-a676-c10f960f0000 pid=3990 execve guuid=e6d58ee8-1600-0000-a676-c10f9a0f0000 pid=3994 /usr/bin/cp guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=e6d58ee8-1600-0000-a676-c10f9a0f0000 pid=3994 execve guuid=29aaede8-1600-0000-a676-c10f9c0f0000 pid=3996 /usr/bin/touch guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=29aaede8-1600-0000-a676-c10f9c0f0000 pid=3996 execve guuid=083f2de9-1600-0000-a676-c10f9e0f0000 pid=3998 /usr/bin/bash guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=083f2de9-1600-0000-a676-c10f9e0f0000 pid=3998 clone guuid=13cc32e9-1600-0000-a676-c10f9f0f0000 pid=3999 /usr/bin/bash guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=13cc32e9-1600-0000-a676-c10f9f0f0000 pid=3999 clone guuid=0c304ae9-1600-0000-a676-c10fa10f0000 pid=4001 /usr/bin/bash guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=0c304ae9-1600-0000-a676-c10fa10f0000 pid=4001 clone guuid=e40c4fe9-1600-0000-a676-c10fa20f0000 pid=4002 /usr/bin/base64 write-file guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=e40c4fe9-1600-0000-a676-c10fa20f0000 pid=4002 execve guuid=05dfeee9-1600-0000-a676-c10fa50f0000 pid=4005 /usr/bin/bash guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=05dfeee9-1600-0000-a676-c10fa50f0000 pid=4005 execve guuid=b4b284ef-1600-0000-a676-c10fcf0f0000 pid=4047 /usr/bin/rm delete-file guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=b4b284ef-1600-0000-a676-c10fcf0f0000 pid=4047 execve guuid=11e0cbef-1600-0000-a676-c10fd30f0000 pid=4051 /usr/bin/bash guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=11e0cbef-1600-0000-a676-c10fd30f0000 pid=4051 clone guuid=6162d3ef-1600-0000-a676-c10fd40f0000 pid=4052 /usr/bin/bash guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=6162d3ef-1600-0000-a676-c10fd40f0000 pid=4052 clone guuid=4f992ff0-1600-0000-a676-c10fd80f0000 pid=4056 /usr/bin/bash guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=4f992ff0-1600-0000-a676-c10fd80f0000 pid=4056 execve guuid=efba82f0-1600-0000-a676-c10fd90f0000 pid=4057 /usr/bin/rm guuid=956420df-1600-0000-a676-c10f5b0f0000 pid=3931->guuid=efba82f0-1600-0000-a676-c10fd90f0000 pid=4057 execve guuid=07d33dea-1600-0000-a676-c10fa70f0000 pid=4007 /usr/bin/bash guuid=05dfeee9-1600-0000-a676-c10fa50f0000 pid=4005->guuid=07d33dea-1600-0000-a676-c10fa70f0000 pid=4007 clone guuid=cabd44ea-1600-0000-a676-c10fa80f0000 pid=4008 /usr/bin/bash guuid=05dfeee9-1600-0000-a676-c10fa50f0000 pid=4005->guuid=cabd44ea-1600-0000-a676-c10fa80f0000 pid=4008 clone guuid=b22377ea-1600-0000-a676-c10faa0f0000 pid=4010 /usr/bin/ls guuid=05dfeee9-1600-0000-a676-c10fa50f0000 pid=4005->guuid=b22377ea-1600-0000-a676-c10faa0f0000 pid=4010 execve guuid=456613eb-1600-0000-a676-c10fae0f0000 pid=4014 /usr/bin/cat guuid=05dfeee9-1600-0000-a676-c10fa50f0000 pid=4005->guuid=456613eb-1600-0000-a676-c10fae0f0000 pid=4014 execve guuid=d8755eeb-1600-0000-a676-c10fb00f0000 pid=4016 /usr/bin/ls guuid=05dfeee9-1600-0000-a676-c10fa50f0000 pid=4005->guuid=d8755eeb-1600-0000-a676-c10fb00f0000 pid=4016 execve guuid=638cd4eb-1600-0000-a676-c10fb40f0000 pid=4020 /usr/bin/mkdir guuid=05dfeee9-1600-0000-a676-c10fa50f0000 pid=4005->guuid=638cd4eb-1600-0000-a676-c10fb40f0000 pid=4020 execve guuid=772229ec-1600-0000-a676-c10fb60f0000 pid=4022 /usr/bin/mv guuid=05dfeee9-1600-0000-a676-c10fa50f0000 pid=4005->guuid=772229ec-1600-0000-a676-c10fb60f0000 pid=4022 execve guuid=eab8a2ec-1600-0000-a676-c10fbb0f0000 pid=4027 /usr/bin/bash guuid=05dfeee9-1600-0000-a676-c10fa50f0000 pid=4005->guuid=eab8a2ec-1600-0000-a676-c10fbb0f0000 pid=4027 clone guuid=ea3aaaec-1600-0000-a676-c10fbc0f0000 pid=4028 /usr/bin/base64 write-file guuid=05dfeee9-1600-0000-a676-c10fa50f0000 pid=4005->guuid=ea3aaaec-1600-0000-a676-c10fbc0f0000 pid=4028 execve guuid=138007ed-1600-0000-a676-c10fbf0f0000 pid=4031 /usr/bin/rm delete-file guuid=05dfeee9-1600-0000-a676-c10fa50f0000 pid=4005->guuid=138007ed-1600-0000-a676-c10fbf0f0000 pid=4031 execve guuid=523250ed-1600-0000-a676-c10fc10f0000 pid=4033 /usr/bin/ls guuid=05dfeee9-1600-0000-a676-c10fa50f0000 pid=4005->guuid=523250ed-1600-0000-a676-c10fc10f0000 pid=4033 execve guuid=93b7baed-1600-0000-a676-c10fc40f0000 pid=4036 /usr/bin/bash guuid=05dfeee9-1600-0000-a676-c10fa50f0000 pid=4005->guuid=93b7baed-1600-0000-a676-c10fc40f0000 pid=4036 clone guuid=e709c9ed-1600-0000-a676-c10fc50f0000 pid=4037 /usr/bin/base64 write-file guuid=05dfeee9-1600-0000-a676-c10fa50f0000 pid=4005->guuid=e709c9ed-1600-0000-a676-c10fc50f0000 pid=4037 execve guuid=cbdf7aee-1600-0000-a676-c10fc80f0000 pid=4040 /usr/bin/ls guuid=05dfeee9-1600-0000-a676-c10fa50f0000 pid=4005->guuid=cbdf7aee-1600-0000-a676-c10fc80f0000 pid=4040 execve guuid=e1ade2ee-1600-0000-a676-c10fcb0f0000 pid=4043 /usr/bin/cat guuid=05dfeee9-1600-0000-a676-c10fa50f0000 pid=4005->guuid=e1ade2ee-1600-0000-a676-c10fcb0f0000 pid=4043 execve guuid=b3c61fef-1600-0000-a676-c10fcd0f0000 pid=4045 /usr/bin/ls guuid=05dfeee9-1600-0000-a676-c10fa50f0000 pid=4005->guuid=b3c61fef-1600-0000-a676-c10fcd0f0000 pid=4045 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Heuristic
Status:
Malicious
First seen:
2026-02-24 17:15:25 UTC
File Type:
Text (Shell)
AV detection:
8 of 24 (33.33%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 73da98e3602154feaa51f689ad8edc031c95a8f14e24e71e934d726f2008acde

(this sample)

  
Delivery method
Distributed via web download

Comments