MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7b85a4ab95ac603ecc2a7eee39919012cfb583e20c385ae71397538f17df63c3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 7b85a4ab95ac603ecc2a7eee39919012cfb583e20c385ae71397538f17df63c3
SHA3-384 hash: e6a13c3a41ef08fc7e1a2cf4e0358e425a14c39f75d2dfbc36084a65446ddab668d816aaf15b16e799e83e5410c1d1ee
SHA1 hash: e493bb546cde9bb708e3c93c9f2a96d29c959c94
MD5 hash: 22f423b09ecadea69a18c654033d69b4
humanhash: music-helium-montana-december
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-04 02:31:44 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:N30M3vgRjGlsaq7gzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:NTmjfMzsP4cbddr7zsP4cbddrk
TLSH T13A925CA916496C79BBC0DE7D9F3C7F0CADE4C1C02118A3ACBA4F39714A2069DDA0535D
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=3e8583c8-1600-0000-4f8e-3195be0c0000 pid=3262 /usr/bin/sudo guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270 /tmp/sample.bin guuid=3e8583c8-1600-0000-4f8e-3195be0c0000 pid=3262->guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270 execve guuid=d8b625cb-1600-0000-4f8e-3195c80c0000 pid=3272 /usr/bin/bash guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=d8b625cb-1600-0000-4f8e-3195c80c0000 pid=3272 clone guuid=b49738cb-1600-0000-4f8e-3195ca0c0000 pid=3274 /usr/bin/bash guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=b49738cb-1600-0000-4f8e-3195ca0c0000 pid=3274 clone guuid=6eb1afcb-1600-0000-4f8e-3195cb0c0000 pid=3275 /usr/bin/mkdir guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=6eb1afcb-1600-0000-4f8e-3195cb0c0000 pid=3275 execve guuid=4ce708cc-1600-0000-4f8e-3195cd0c0000 pid=3277 /usr/bin/mkdir guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=4ce708cc-1600-0000-4f8e-3195cd0c0000 pid=3277 execve guuid=cb6572cc-1600-0000-4f8e-3195d00c0000 pid=3280 /usr/bin/mkdir guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=cb6572cc-1600-0000-4f8e-3195d00c0000 pid=3280 execve guuid=d600d3cc-1600-0000-4f8e-3195d30c0000 pid=3283 /usr/bin/mkdir guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=d600d3cc-1600-0000-4f8e-3195d30c0000 pid=3283 execve guuid=a30719cd-1600-0000-4f8e-3195d50c0000 pid=3285 /usr/bin/mkdir guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=a30719cd-1600-0000-4f8e-3195d50c0000 pid=3285 execve guuid=1ac27ecd-1600-0000-4f8e-3195d60c0000 pid=3286 /usr/bin/mkdir guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=1ac27ecd-1600-0000-4f8e-3195d60c0000 pid=3286 execve guuid=4314c7cd-1600-0000-4f8e-3195d90c0000 pid=3289 /usr/bin/mkdir guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=4314c7cd-1600-0000-4f8e-3195d90c0000 pid=3289 execve guuid=c7f11fce-1600-0000-4f8e-3195db0c0000 pid=3291 /usr/bin/cp guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=c7f11fce-1600-0000-4f8e-3195db0c0000 pid=3291 execve guuid=cd23a2ce-1600-0000-4f8e-3195dd0c0000 pid=3293 /usr/bin/cp guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=cd23a2ce-1600-0000-4f8e-3195dd0c0000 pid=3293 execve guuid=d30e22cf-1600-0000-4f8e-3195de0c0000 pid=3294 /usr/bin/cp guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=d30e22cf-1600-0000-4f8e-3195de0c0000 pid=3294 execve guuid=f3659acf-1600-0000-4f8e-3195e00c0000 pid=3296 /usr/bin/cp guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=f3659acf-1600-0000-4f8e-3195e00c0000 pid=3296 execve guuid=6e0ffacf-1600-0000-4f8e-3195e30c0000 pid=3299 /usr/bin/cp guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=6e0ffacf-1600-0000-4f8e-3195e30c0000 pid=3299 execve guuid=979b68d0-1600-0000-4f8e-3195e40c0000 pid=3300 /usr/bin/cp guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=979b68d0-1600-0000-4f8e-3195e40c0000 pid=3300 execve guuid=37b9d1d0-1600-0000-4f8e-3195e70c0000 pid=3303 /usr/bin/cp guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=37b9d1d0-1600-0000-4f8e-3195e70c0000 pid=3303 execve guuid=c55e38d1-1600-0000-4f8e-3195e90c0000 pid=3305 /usr/bin/cp guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=c55e38d1-1600-0000-4f8e-3195e90c0000 pid=3305 execve guuid=04049dd1-1600-0000-4f8e-3195eb0c0000 pid=3307 /usr/bin/cp guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=04049dd1-1600-0000-4f8e-3195eb0c0000 pid=3307 execve guuid=cc9e13d2-1600-0000-4f8e-3195ec0c0000 pid=3308 /usr/bin/cp guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=cc9e13d2-1600-0000-4f8e-3195ec0c0000 pid=3308 execve guuid=ee7b96d2-1600-0000-4f8e-3195ed0c0000 pid=3309 /usr/bin/cp guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=ee7b96d2-1600-0000-4f8e-3195ed0c0000 pid=3309 execve guuid=e25f0cd3-1600-0000-4f8e-3195ee0c0000 pid=3310 /usr/bin/cp guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=e25f0cd3-1600-0000-4f8e-3195ee0c0000 pid=3310 execve guuid=956a6ed3-1600-0000-4f8e-3195f00c0000 pid=3312 /usr/bin/cp guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=956a6ed3-1600-0000-4f8e-3195f00c0000 pid=3312 execve guuid=c09023d4-1600-0000-4f8e-3195f30c0000 pid=3315 /usr/bin/cp guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=c09023d4-1600-0000-4f8e-3195f30c0000 pid=3315 execve guuid=c40393d4-1600-0000-4f8e-3195f50c0000 pid=3317 /usr/bin/cp guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=c40393d4-1600-0000-4f8e-3195f50c0000 pid=3317 execve guuid=616502d5-1600-0000-4f8e-3195f80c0000 pid=3320 /usr/bin/touch guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=616502d5-1600-0000-4f8e-3195f80c0000 pid=3320 execve guuid=169740d5-1600-0000-4f8e-3195fa0c0000 pid=3322 /usr/bin/bash guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=169740d5-1600-0000-4f8e-3195fa0c0000 pid=3322 clone guuid=6c3447d5-1600-0000-4f8e-3195fb0c0000 pid=3323 /usr/bin/bash guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=6c3447d5-1600-0000-4f8e-3195fb0c0000 pid=3323 clone guuid=e13563d5-1600-0000-4f8e-3195fc0c0000 pid=3324 /usr/bin/bash guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=e13563d5-1600-0000-4f8e-3195fc0c0000 pid=3324 clone guuid=b72369d5-1600-0000-4f8e-3195fd0c0000 pid=3325 /usr/bin/base64 write-file guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=b72369d5-1600-0000-4f8e-3195fd0c0000 pid=3325 execve guuid=2dd0dcd5-1600-0000-4f8e-3195000d0000 pid=3328 /usr/bin/bash guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=2dd0dcd5-1600-0000-4f8e-3195000d0000 pid=3328 execve guuid=6c68e9da-1600-0000-4f8e-31951c0d0000 pid=3356 /usr/bin/rm delete-file guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=6c68e9da-1600-0000-4f8e-31951c0d0000 pid=3356 execve guuid=ce7530db-1600-0000-4f8e-31951e0d0000 pid=3358 /usr/bin/bash guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=ce7530db-1600-0000-4f8e-31951e0d0000 pid=3358 clone guuid=d39237db-1600-0000-4f8e-31951f0d0000 pid=3359 /usr/bin/bash guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=d39237db-1600-0000-4f8e-31951f0d0000 pid=3359 clone guuid=e5bc57db-1600-0000-4f8e-3195210d0000 pid=3361 /usr/bin/bash guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=e5bc57db-1600-0000-4f8e-3195210d0000 pid=3361 execve guuid=f667a7db-1600-0000-4f8e-3195230d0000 pid=3363 /usr/bin/rm guuid=93bba9ca-1600-0000-4f8e-3195c60c0000 pid=3270->guuid=f667a7db-1600-0000-4f8e-3195230d0000 pid=3363 execve guuid=c5af25d6-1600-0000-4f8e-3195020d0000 pid=3330 /usr/bin/bash guuid=2dd0dcd5-1600-0000-4f8e-3195000d0000 pid=3328->guuid=c5af25d6-1600-0000-4f8e-3195020d0000 pid=3330 clone guuid=ddde35d6-1600-0000-4f8e-3195030d0000 pid=3331 /usr/bin/bash guuid=2dd0dcd5-1600-0000-4f8e-3195000d0000 pid=3328->guuid=ddde35d6-1600-0000-4f8e-3195030d0000 pid=3331 clone guuid=306d65d6-1600-0000-4f8e-3195050d0000 pid=3333 /usr/bin/ls guuid=2dd0dcd5-1600-0000-4f8e-3195000d0000 pid=3328->guuid=306d65d6-1600-0000-4f8e-3195050d0000 pid=3333 execve guuid=2193dfd6-1600-0000-4f8e-3195080d0000 pid=3336 /usr/bin/cat guuid=2dd0dcd5-1600-0000-4f8e-3195000d0000 pid=3328->guuid=2193dfd6-1600-0000-4f8e-3195080d0000 pid=3336 execve guuid=ba3725d7-1600-0000-4f8e-31950a0d0000 pid=3338 /usr/bin/ls guuid=2dd0dcd5-1600-0000-4f8e-3195000d0000 pid=3328->guuid=ba3725d7-1600-0000-4f8e-31950a0d0000 pid=3338 execve guuid=8d5d82d7-1600-0000-4f8e-31950c0d0000 pid=3340 /usr/bin/mkdir guuid=2dd0dcd5-1600-0000-4f8e-3195000d0000 pid=3328->guuid=8d5d82d7-1600-0000-4f8e-31950c0d0000 pid=3340 execve guuid=47d4ccd7-1600-0000-4f8e-31950e0d0000 pid=3342 /usr/bin/mv guuid=2dd0dcd5-1600-0000-4f8e-3195000d0000 pid=3328->guuid=47d4ccd7-1600-0000-4f8e-31950e0d0000 pid=3342 execve guuid=415b1dd8-1600-0000-4f8e-3195100d0000 pid=3344 /usr/bin/bash guuid=2dd0dcd5-1600-0000-4f8e-3195000d0000 pid=3328->guuid=415b1dd8-1600-0000-4f8e-3195100d0000 pid=3344 clone guuid=f5d223d8-1600-0000-4f8e-3195120d0000 pid=3346 /usr/bin/base64 write-file guuid=2dd0dcd5-1600-0000-4f8e-3195000d0000 pid=3328->guuid=f5d223d8-1600-0000-4f8e-3195120d0000 pid=3346 execve guuid=313c73d8-1600-0000-4f8e-3195130d0000 pid=3347 /usr/bin/rm delete-file guuid=2dd0dcd5-1600-0000-4f8e-3195000d0000 pid=3328->guuid=313c73d8-1600-0000-4f8e-3195130d0000 pid=3347 execve guuid=984ebed8-1600-0000-4f8e-3195140d0000 pid=3348 /usr/bin/ls guuid=2dd0dcd5-1600-0000-4f8e-3195000d0000 pid=3328->guuid=984ebed8-1600-0000-4f8e-3195140d0000 pid=3348 execve guuid=5bc526d9-1600-0000-4f8e-3195160d0000 pid=3350 /usr/bin/bash guuid=2dd0dcd5-1600-0000-4f8e-3195000d0000 pid=3328->guuid=5bc526d9-1600-0000-4f8e-3195160d0000 pid=3350 clone guuid=a1d22ed9-1600-0000-4f8e-3195170d0000 pid=3351 /usr/bin/base64 write-file guuid=2dd0dcd5-1600-0000-4f8e-3195000d0000 pid=3328->guuid=a1d22ed9-1600-0000-4f8e-3195170d0000 pid=3351 execve guuid=0c998bd9-1600-0000-4f8e-3195180d0000 pid=3352 /usr/bin/ls guuid=2dd0dcd5-1600-0000-4f8e-3195000d0000 pid=3328->guuid=0c998bd9-1600-0000-4f8e-3195180d0000 pid=3352 execve guuid=1d7d25da-1600-0000-4f8e-3195190d0000 pid=3353 /usr/bin/cat guuid=2dd0dcd5-1600-0000-4f8e-3195000d0000 pid=3328->guuid=1d7d25da-1600-0000-4f8e-3195190d0000 pid=3353 execve guuid=2f0f75da-1600-0000-4f8e-31951a0d0000 pid=3354 /usr/bin/ls guuid=2dd0dcd5-1600-0000-4f8e-3195000d0000 pid=3328->guuid=2f0f75da-1600-0000-4f8e-31951a0d0000 pid=3354 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Heuristic
Status:
Malicious
First seen:
2026-03-04 02:32:18 UTC
File Type:
Text (Shell)
AV detection:
11 of 36 (30.56%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 7b85a4ab95ac603ecc2a7eee39919012cfb583e20c385ae71397538f17df63c3

(this sample)

  
Delivery method
Distributed via web download

Comments