MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 80e25df31d75f883618cd77ef0881406dce057d35620f1c84470a5fcde3cdf49. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 80e25df31d75f883618cd77ef0881406dce057d35620f1c84470a5fcde3cdf49
SHA3-384 hash: d5df7ce704b3a44ca628ea88737b8975fc96e0fe9ad2ac3bab9c42e67961fd0356cb7fbc12f7ca7c4ed857851e315b14
SHA1 hash: 6545b3c4366d480701b8278e47a04f85933da24b
MD5 hash: 3243f7bf3ad3c1dc708f4c06c1b36f1c
humanhash: three-cup-winter-bluebird
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-11 15:31:30 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:KFcuQpWx+BL0SWL0gLzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:KF8i+BL0SI0MzsP4cbddr7zsP4cbddrk
TLSH T1EB925DB512896C79FBD0CE39AF3C6F4CADE8C2C42124A3ACBA4F39205A1166DC705359
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=79339e01-1700-0000-fcb3-b349bd0d0000 pid=3517 /usr/bin/sudo guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522 /tmp/sample.bin guuid=79339e01-1700-0000-fcb3-b349bd0d0000 pid=3517->guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522 execve guuid=6ac31b05-1700-0000-fcb3-b349c30d0000 pid=3523 /usr/bin/bash guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=6ac31b05-1700-0000-fcb3-b349c30d0000 pid=3523 clone guuid=21205305-1700-0000-fcb3-b349c40d0000 pid=3524 /usr/bin/bash guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=21205305-1700-0000-fcb3-b349c40d0000 pid=3524 clone guuid=4a2aed05-1700-0000-fcb3-b349c50d0000 pid=3525 /usr/bin/mkdir guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=4a2aed05-1700-0000-fcb3-b349c50d0000 pid=3525 execve guuid=54d78906-1700-0000-fcb3-b349c60d0000 pid=3526 /usr/bin/mkdir guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=54d78906-1700-0000-fcb3-b349c60d0000 pid=3526 execve guuid=eb7d1507-1700-0000-fcb3-b349c70d0000 pid=3527 /usr/bin/mkdir guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=eb7d1507-1700-0000-fcb3-b349c70d0000 pid=3527 execve guuid=f0a59807-1700-0000-fcb3-b349c90d0000 pid=3529 /usr/bin/mkdir guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=f0a59807-1700-0000-fcb3-b349c90d0000 pid=3529 execve guuid=c4b43108-1700-0000-fcb3-b349ca0d0000 pid=3530 /usr/bin/mkdir guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=c4b43108-1700-0000-fcb3-b349ca0d0000 pid=3530 execve guuid=f066e008-1700-0000-fcb3-b349cb0d0000 pid=3531 /usr/bin/mkdir guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=f066e008-1700-0000-fcb3-b349cb0d0000 pid=3531 execve guuid=fb245509-1700-0000-fcb3-b349cc0d0000 pid=3532 /usr/bin/mkdir guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=fb245509-1700-0000-fcb3-b349cc0d0000 pid=3532 execve guuid=fed5ef09-1700-0000-fcb3-b349ce0d0000 pid=3534 /usr/bin/cp guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=fed5ef09-1700-0000-fcb3-b349ce0d0000 pid=3534 execve guuid=4c868b0a-1700-0000-fcb3-b349d10d0000 pid=3537 /usr/bin/cp guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=4c868b0a-1700-0000-fcb3-b349d10d0000 pid=3537 execve guuid=1fe6170b-1700-0000-fcb3-b349d30d0000 pid=3539 /usr/bin/cp guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=1fe6170b-1700-0000-fcb3-b349d30d0000 pid=3539 execve guuid=cdf7a40b-1700-0000-fcb3-b349d60d0000 pid=3542 /usr/bin/cp guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=cdf7a40b-1700-0000-fcb3-b349d60d0000 pid=3542 execve guuid=9deb400c-1700-0000-fcb3-b349d70d0000 pid=3543 /usr/bin/cp guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=9deb400c-1700-0000-fcb3-b349d70d0000 pid=3543 execve guuid=481cca0c-1700-0000-fcb3-b349d90d0000 pid=3545 /usr/bin/cp guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=481cca0c-1700-0000-fcb3-b349d90d0000 pid=3545 execve guuid=66734e0d-1700-0000-fcb3-b349db0d0000 pid=3547 /usr/bin/cp guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=66734e0d-1700-0000-fcb3-b349db0d0000 pid=3547 execve guuid=ba7cf70d-1700-0000-fcb3-b349dd0d0000 pid=3549 /usr/bin/cp guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=ba7cf70d-1700-0000-fcb3-b349dd0d0000 pid=3549 execve guuid=ab2eba0e-1700-0000-fcb3-b349e00d0000 pid=3552 /usr/bin/cp guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=ab2eba0e-1700-0000-fcb3-b349e00d0000 pid=3552 execve guuid=1330410f-1700-0000-fcb3-b349e20d0000 pid=3554 /usr/bin/cp guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=1330410f-1700-0000-fcb3-b349e20d0000 pid=3554 execve guuid=ea8ce00f-1700-0000-fcb3-b349e50d0000 pid=3557 /usr/bin/cp guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=ea8ce00f-1700-0000-fcb3-b349e50d0000 pid=3557 execve guuid=a0247610-1700-0000-fcb3-b349e80d0000 pid=3560 /usr/bin/cp guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=a0247610-1700-0000-fcb3-b349e80d0000 pid=3560 execve guuid=2e321011-1700-0000-fcb3-b349ea0d0000 pid=3562 /usr/bin/cp guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=2e321011-1700-0000-fcb3-b349ea0d0000 pid=3562 execve guuid=1029a511-1700-0000-fcb3-b349ed0d0000 pid=3565 /usr/bin/cp guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=1029a511-1700-0000-fcb3-b349ed0d0000 pid=3565 execve guuid=130e4312-1700-0000-fcb3-b349ef0d0000 pid=3567 /usr/bin/cp guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=130e4312-1700-0000-fcb3-b349ef0d0000 pid=3567 execve guuid=1038e512-1700-0000-fcb3-b349f20d0000 pid=3570 /usr/bin/touch guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=1038e512-1700-0000-fcb3-b349f20d0000 pid=3570 execve guuid=15364c13-1700-0000-fcb3-b349f40d0000 pid=3572 /usr/bin/bash guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=15364c13-1700-0000-fcb3-b349f40d0000 pid=3572 clone guuid=73035613-1700-0000-fcb3-b349f50d0000 pid=3573 /usr/bin/bash guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=73035613-1700-0000-fcb3-b349f50d0000 pid=3573 clone guuid=6f719013-1700-0000-fcb3-b349f70d0000 pid=3575 /usr/bin/bash guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=6f719013-1700-0000-fcb3-b349f70d0000 pid=3575 clone guuid=67bd9913-1700-0000-fcb3-b349f80d0000 pid=3576 /usr/bin/base64 write-file guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=67bd9913-1700-0000-fcb3-b349f80d0000 pid=3576 execve guuid=24898514-1700-0000-fcb3-b349fb0d0000 pid=3579 /usr/bin/bash guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=24898514-1700-0000-fcb3-b349fb0d0000 pid=3579 execve guuid=d221ea1a-1700-0000-fcb3-b3491f0e0000 pid=3615 /usr/bin/rm delete-file guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=d221ea1a-1700-0000-fcb3-b3491f0e0000 pid=3615 execve guuid=1d84361b-1700-0000-fcb3-b349210e0000 pid=3617 /usr/bin/bash guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=1d84361b-1700-0000-fcb3-b349210e0000 pid=3617 clone guuid=bd423c1b-1700-0000-fcb3-b349220e0000 pid=3618 /usr/bin/bash guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=bd423c1b-1700-0000-fcb3-b349220e0000 pid=3618 clone guuid=59859e1b-1700-0000-fcb3-b349240e0000 pid=3620 /usr/bin/bash guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=59859e1b-1700-0000-fcb3-b349240e0000 pid=3620 execve guuid=43b0551c-1700-0000-fcb3-b349270e0000 pid=3623 /usr/bin/rm guuid=e1f73f04-1700-0000-fcb3-b349c20d0000 pid=3522->guuid=43b0551c-1700-0000-fcb3-b349270e0000 pid=3623 execve guuid=04840315-1700-0000-fcb3-b349fd0d0000 pid=3581 /usr/bin/bash guuid=24898514-1700-0000-fcb3-b349fb0d0000 pid=3579->guuid=04840315-1700-0000-fcb3-b349fd0d0000 pid=3581 clone guuid=1bc00d15-1700-0000-fcb3-b349ff0d0000 pid=3583 /usr/bin/bash guuid=24898514-1700-0000-fcb3-b349fb0d0000 pid=3579->guuid=1bc00d15-1700-0000-fcb3-b349ff0d0000 pid=3583 clone guuid=09cd4415-1700-0000-fcb3-b349000e0000 pid=3584 /usr/bin/ls guuid=24898514-1700-0000-fcb3-b349fb0d0000 pid=3579->guuid=09cd4415-1700-0000-fcb3-b349000e0000 pid=3584 execve guuid=3b82f515-1700-0000-fcb3-b349050e0000 pid=3589 /usr/bin/cat guuid=24898514-1700-0000-fcb3-b349fb0d0000 pid=3579->guuid=3b82f515-1700-0000-fcb3-b349050e0000 pid=3589 execve guuid=99026516-1700-0000-fcb3-b349060e0000 pid=3590 /usr/bin/ls guuid=24898514-1700-0000-fcb3-b349fb0d0000 pid=3579->guuid=99026516-1700-0000-fcb3-b349060e0000 pid=3590 execve guuid=5f2b0317-1700-0000-fcb3-b349080e0000 pid=3592 /usr/bin/mkdir guuid=24898514-1700-0000-fcb3-b349fb0d0000 pid=3579->guuid=5f2b0317-1700-0000-fcb3-b349080e0000 pid=3592 execve guuid=1aaa7117-1700-0000-fcb3-b3490a0e0000 pid=3594 /usr/bin/mv guuid=24898514-1700-0000-fcb3-b349fb0d0000 pid=3579->guuid=1aaa7117-1700-0000-fcb3-b3490a0e0000 pid=3594 execve guuid=b69ddc17-1700-0000-fcb3-b3490b0e0000 pid=3595 /usr/bin/bash guuid=24898514-1700-0000-fcb3-b349fb0d0000 pid=3579->guuid=b69ddc17-1700-0000-fcb3-b3490b0e0000 pid=3595 clone guuid=6094e417-1700-0000-fcb3-b3490c0e0000 pid=3596 /usr/bin/base64 write-file guuid=24898514-1700-0000-fcb3-b349fb0d0000 pid=3579->guuid=6094e417-1700-0000-fcb3-b3490c0e0000 pid=3596 execve guuid=27ad3418-1700-0000-fcb3-b3490e0e0000 pid=3598 /usr/bin/rm delete-file guuid=24898514-1700-0000-fcb3-b349fb0d0000 pid=3579->guuid=27ad3418-1700-0000-fcb3-b3490e0e0000 pid=3598 execve guuid=8ee77718-1700-0000-fcb3-b349110e0000 pid=3601 /usr/bin/ls guuid=24898514-1700-0000-fcb3-b349fb0d0000 pid=3579->guuid=8ee77718-1700-0000-fcb3-b349110e0000 pid=3601 execve guuid=d6dee318-1700-0000-fcb3-b349130e0000 pid=3603 /usr/bin/bash guuid=24898514-1700-0000-fcb3-b349fb0d0000 pid=3579->guuid=d6dee318-1700-0000-fcb3-b349130e0000 pid=3603 clone guuid=7831eb18-1700-0000-fcb3-b349140e0000 pid=3604 /usr/bin/base64 write-file guuid=24898514-1700-0000-fcb3-b349fb0d0000 pid=3579->guuid=7831eb18-1700-0000-fcb3-b349140e0000 pid=3604 execve guuid=f00c3019-1700-0000-fcb3-b349160e0000 pid=3606 /usr/bin/ls guuid=24898514-1700-0000-fcb3-b349fb0d0000 pid=3579->guuid=f00c3019-1700-0000-fcb3-b349160e0000 pid=3606 execve guuid=0bddf719-1700-0000-fcb3-b3491a0e0000 pid=3610 /usr/bin/cat guuid=24898514-1700-0000-fcb3-b349fb0d0000 pid=3579->guuid=0bddf719-1700-0000-fcb3-b3491a0e0000 pid=3610 execve guuid=4bc3801a-1700-0000-fcb3-b3491c0e0000 pid=3612 /usr/bin/ls guuid=24898514-1700-0000-fcb3-b349fb0d0000 pid=3579->guuid=4bc3801a-1700-0000-fcb3-b3491c0e0000 pid=3612 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-11 15:32:28 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 80e25df31d75f883618cd77ef0881406dce057d35620f1c84470a5fcde3cdf49

(this sample)

  
Delivery method
Distributed via web download

Comments