MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 82aaa56441fcb4ca4495c0f2e03eb8fe44df801abeb0aa0d4341d176fbd799ec. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 82aaa56441fcb4ca4495c0f2e03eb8fe44df801abeb0aa0d4341d176fbd799ec
SHA3-384 hash: 5e04c58d59c9c217509939a7a9f5b24300b625d3d25dada967b238d2f637006e38cf144de9012ed68806cf398d1a3a2f
SHA1 hash: 01efc33d189f9ff6e8e4dcc6eac41dc47baaebdb
MD5 hash: e8b718d265aae790dfc6b8e0c3ac0209
humanhash: colorado-lithium-oscar-yankee
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-14 20:32:46 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:fkFcuQpWx+BL0SWL0gizsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:fkF8i+BL0SI0xzsP4cbddr7zsP4cbddo
TLSH T117925DB512896C79FBD0CE39AF3C7F4DADE8C2C42124A3ACBA4F39205A1166DC705359
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Gathering data
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=a047dc33-1700-0000-b98a-c560970d0000 pid=3479 /usr/bin/sudo guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485 /tmp/sample.bin guuid=a047dc33-1700-0000-b98a-c560970d0000 pid=3479->guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485 execve guuid=69341536-1700-0000-b98a-c5609e0d0000 pid=3486 /usr/bin/bash guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=69341536-1700-0000-b98a-c5609e0d0000 pid=3486 clone guuid=5a301f36-1700-0000-b98a-c5609f0d0000 pid=3487 /usr/bin/bash guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=5a301f36-1700-0000-b98a-c5609f0d0000 pid=3487 clone guuid=f18c3f36-1700-0000-b98a-c560a00d0000 pid=3488 /usr/bin/mkdir guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=f18c3f36-1700-0000-b98a-c560a00d0000 pid=3488 execve guuid=a3eca736-1700-0000-b98a-c560a10d0000 pid=3489 /usr/bin/mkdir guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=a3eca736-1700-0000-b98a-c560a10d0000 pid=3489 execve guuid=4e8b0537-1700-0000-b98a-c560a20d0000 pid=3490 /usr/bin/mkdir guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=4e8b0537-1700-0000-b98a-c560a20d0000 pid=3490 execve guuid=48bd6137-1700-0000-b98a-c560a30d0000 pid=3491 /usr/bin/mkdir guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=48bd6137-1700-0000-b98a-c560a30d0000 pid=3491 execve guuid=2694bd37-1700-0000-b98a-c560a40d0000 pid=3492 /usr/bin/mkdir guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=2694bd37-1700-0000-b98a-c560a40d0000 pid=3492 execve guuid=98e01438-1700-0000-b98a-c560a50d0000 pid=3493 /usr/bin/mkdir guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=98e01438-1700-0000-b98a-c560a50d0000 pid=3493 execve guuid=18026b38-1700-0000-b98a-c560a60d0000 pid=3494 /usr/bin/mkdir guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=18026b38-1700-0000-b98a-c560a60d0000 pid=3494 execve guuid=69c3bd38-1700-0000-b98a-c560a70d0000 pid=3495 /usr/bin/cp guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=69c3bd38-1700-0000-b98a-c560a70d0000 pid=3495 execve guuid=f8691939-1700-0000-b98a-c560a80d0000 pid=3496 /usr/bin/cp guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=f8691939-1700-0000-b98a-c560a80d0000 pid=3496 execve guuid=acfc7539-1700-0000-b98a-c560a90d0000 pid=3497 /usr/bin/cp guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=acfc7539-1700-0000-b98a-c560a90d0000 pid=3497 execve guuid=9f5bca39-1700-0000-b98a-c560ad0d0000 pid=3501 /usr/bin/cp guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=9f5bca39-1700-0000-b98a-c560ad0d0000 pid=3501 execve guuid=e651623a-1700-0000-b98a-c560af0d0000 pid=3503 /usr/bin/cp guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=e651623a-1700-0000-b98a-c560af0d0000 pid=3503 execve guuid=493fbc3a-1700-0000-b98a-c560b20d0000 pid=3506 /usr/bin/cp guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=493fbc3a-1700-0000-b98a-c560b20d0000 pid=3506 execve guuid=2c8f163b-1700-0000-b98a-c560b40d0000 pid=3508 /usr/bin/cp guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=2c8f163b-1700-0000-b98a-c560b40d0000 pid=3508 execve guuid=548a863b-1700-0000-b98a-c560b60d0000 pid=3510 /usr/bin/cp guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=548a863b-1700-0000-b98a-c560b60d0000 pid=3510 execve guuid=5edc133c-1700-0000-b98a-c560ba0d0000 pid=3514 /usr/bin/cp guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=5edc133c-1700-0000-b98a-c560ba0d0000 pid=3514 execve guuid=c964613c-1700-0000-b98a-c560bc0d0000 pid=3516 /usr/bin/cp guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=c964613c-1700-0000-b98a-c560bc0d0000 pid=3516 execve guuid=12f3b03c-1700-0000-b98a-c560be0d0000 pid=3518 /usr/bin/cp guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=12f3b03c-1700-0000-b98a-c560be0d0000 pid=3518 execve guuid=fac40e3d-1700-0000-b98a-c560bf0d0000 pid=3519 /usr/bin/cp guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=fac40e3d-1700-0000-b98a-c560bf0d0000 pid=3519 execve guuid=6b81863d-1700-0000-b98a-c560c10d0000 pid=3521 /usr/bin/cp guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=6b81863d-1700-0000-b98a-c560c10d0000 pid=3521 execve guuid=b2fde23d-1700-0000-b98a-c560c30d0000 pid=3523 /usr/bin/cp guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=b2fde23d-1700-0000-b98a-c560c30d0000 pid=3523 execve guuid=32e33c3e-1700-0000-b98a-c560c50d0000 pid=3525 /usr/bin/cp guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=32e33c3e-1700-0000-b98a-c560c50d0000 pid=3525 execve guuid=1df6953e-1700-0000-b98a-c560c80d0000 pid=3528 /usr/bin/touch guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=1df6953e-1700-0000-b98a-c560c80d0000 pid=3528 execve guuid=f31cdd3e-1700-0000-b98a-c560ca0d0000 pid=3530 /usr/bin/bash guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=f31cdd3e-1700-0000-b98a-c560ca0d0000 pid=3530 clone guuid=63a2e33e-1700-0000-b98a-c560cb0d0000 pid=3531 /usr/bin/bash guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=63a2e33e-1700-0000-b98a-c560cb0d0000 pid=3531 clone guuid=6b43003f-1700-0000-b98a-c560cc0d0000 pid=3532 /usr/bin/bash guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=6b43003f-1700-0000-b98a-c560cc0d0000 pid=3532 clone guuid=0b74053f-1700-0000-b98a-c560ce0d0000 pid=3534 /usr/bin/base64 write-file guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=0b74053f-1700-0000-b98a-c560ce0d0000 pid=3534 execve guuid=7b8c8c3f-1700-0000-b98a-c560cf0d0000 pid=3535 /usr/bin/bash guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=7b8c8c3f-1700-0000-b98a-c560cf0d0000 pid=3535 execve guuid=4de5e144-1700-0000-b98a-c560f10d0000 pid=3569 /usr/bin/rm delete-file guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=4de5e144-1700-0000-b98a-c560f10d0000 pid=3569 execve guuid=70e92a45-1700-0000-b98a-c560f20d0000 pid=3570 /usr/bin/bash guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=70e92a45-1700-0000-b98a-c560f20d0000 pid=3570 clone guuid=c7023345-1700-0000-b98a-c560f30d0000 pid=3571 /usr/bin/bash guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=c7023345-1700-0000-b98a-c560f30d0000 pid=3571 clone guuid=64d05345-1700-0000-b98a-c560f40d0000 pid=3572 /usr/bin/bash guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=64d05345-1700-0000-b98a-c560f40d0000 pid=3572 execve guuid=faadcc45-1700-0000-b98a-c560f50d0000 pid=3573 /usr/bin/rm guuid=a406b135-1700-0000-b98a-c5609d0d0000 pid=3485->guuid=faadcc45-1700-0000-b98a-c560f50d0000 pid=3573 execve guuid=ead3dc3f-1700-0000-b98a-c560d10d0000 pid=3537 /usr/bin/bash guuid=7b8c8c3f-1700-0000-b98a-c560cf0d0000 pid=3535->guuid=ead3dc3f-1700-0000-b98a-c560d10d0000 pid=3537 clone guuid=bd3fe63f-1700-0000-b98a-c560d20d0000 pid=3538 /usr/bin/bash guuid=7b8c8c3f-1700-0000-b98a-c560cf0d0000 pid=3535->guuid=bd3fe63f-1700-0000-b98a-c560d20d0000 pid=3538 clone guuid=d3950340-1700-0000-b98a-c560d30d0000 pid=3539 /usr/bin/ls guuid=7b8c8c3f-1700-0000-b98a-c560cf0d0000 pid=3535->guuid=d3950340-1700-0000-b98a-c560d30d0000 pid=3539 execve guuid=8fd87140-1700-0000-b98a-c560d60d0000 pid=3542 /usr/bin/cat guuid=7b8c8c3f-1700-0000-b98a-c560cf0d0000 pid=3535->guuid=8fd87140-1700-0000-b98a-c560d60d0000 pid=3542 execve guuid=e05bb940-1700-0000-b98a-c560d80d0000 pid=3544 /usr/bin/ls guuid=7b8c8c3f-1700-0000-b98a-c560cf0d0000 pid=3535->guuid=e05bb940-1700-0000-b98a-c560d80d0000 pid=3544 execve guuid=d7fe2641-1700-0000-b98a-c560da0d0000 pid=3546 /usr/bin/mkdir guuid=7b8c8c3f-1700-0000-b98a-c560cf0d0000 pid=3535->guuid=d7fe2641-1700-0000-b98a-c560da0d0000 pid=3546 execve guuid=f777aa41-1700-0000-b98a-c560dd0d0000 pid=3549 /usr/bin/mv guuid=7b8c8c3f-1700-0000-b98a-c560cf0d0000 pid=3535->guuid=f777aa41-1700-0000-b98a-c560dd0d0000 pid=3549 execve guuid=ffc72e42-1700-0000-b98a-c560e00d0000 pid=3552 /usr/bin/bash guuid=7b8c8c3f-1700-0000-b98a-c560cf0d0000 pid=3535->guuid=ffc72e42-1700-0000-b98a-c560e00d0000 pid=3552 clone guuid=e0f73542-1700-0000-b98a-c560e10d0000 pid=3553 /usr/bin/base64 write-file guuid=7b8c8c3f-1700-0000-b98a-c560cf0d0000 pid=3535->guuid=e0f73542-1700-0000-b98a-c560e10d0000 pid=3553 execve guuid=ddc59342-1700-0000-b98a-c560e30d0000 pid=3555 /usr/bin/rm delete-file guuid=7b8c8c3f-1700-0000-b98a-c560cf0d0000 pid=3535->guuid=ddc59342-1700-0000-b98a-c560e30d0000 pid=3555 execve guuid=2f63e542-1700-0000-b98a-c560e50d0000 pid=3557 /usr/bin/ls guuid=7b8c8c3f-1700-0000-b98a-c560cf0d0000 pid=3535->guuid=2f63e542-1700-0000-b98a-c560e50d0000 pid=3557 execve guuid=a2ca6843-1700-0000-b98a-c560e70d0000 pid=3559 /usr/bin/bash guuid=7b8c8c3f-1700-0000-b98a-c560cf0d0000 pid=3535->guuid=a2ca6843-1700-0000-b98a-c560e70d0000 pid=3559 clone guuid=524c6f43-1700-0000-b98a-c560e80d0000 pid=3560 /usr/bin/base64 write-file guuid=7b8c8c3f-1700-0000-b98a-c560cf0d0000 pid=3535->guuid=524c6f43-1700-0000-b98a-c560e80d0000 pid=3560 execve guuid=4c97c443-1700-0000-b98a-c560ea0d0000 pid=3562 /usr/bin/ls guuid=7b8c8c3f-1700-0000-b98a-c560cf0d0000 pid=3535->guuid=4c97c443-1700-0000-b98a-c560ea0d0000 pid=3562 execve guuid=20862744-1700-0000-b98a-c560ec0d0000 pid=3564 /usr/bin/cat guuid=7b8c8c3f-1700-0000-b98a-c560cf0d0000 pid=3535->guuid=20862744-1700-0000-b98a-c560ec0d0000 pid=3564 execve guuid=458c6844-1700-0000-b98a-c560ee0d0000 pid=3566 /usr/bin/ls guuid=7b8c8c3f-1700-0000-b98a-c560cf0d0000 pid=3535->guuid=458c6844-1700-0000-b98a-c560ee0d0000 pid=3566 execve
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-14 20:33:44 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 82aaa56441fcb4ca4495c0f2e03eb8fe44df801abeb0aa0d4341d176fbd799ec

(this sample)

  
Delivery method
Distributed via web download

Comments