MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8558676255b31a3cab152fcbf4bb07e799f61ebfcd1323dd1a14cd95a33281e8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 8558676255b31a3cab152fcbf4bb07e799f61ebfcd1323dd1a14cd95a33281e8
SHA3-384 hash: fc65bccaa845862d00387f7d2f9026c724636a79fcaa2429da0f8bd09c730d0bde18bc259d47e3d1194d420d5aed5ea0
SHA1 hash: cf2b496e0e0bbff4313f266f2cfa5d1385eb6e24
MD5 hash: ae89ec5929991a4a9cfc06208e6c985a
humanhash: blue-william-video-pennsylvania
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-23 11:30:41 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:hFcuQpWx+BL0SWL0gvzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:hF8i+BL0SI0QzsP4cbddr7zsP4cbddrk
TLSH T129925CB512896C79FBD1CE39AF3C6F4CADE882C42124E3ACBA0F39215A1166DC705359
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
54
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=5096ed11-1700-0000-d60a-354def0d0000 pid=3567 /usr/bin/sudo guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575 /tmp/sample.bin guuid=5096ed11-1700-0000-d60a-354def0d0000 pid=3567->guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575 execve guuid=1c6aac14-1700-0000-d60a-354df90d0000 pid=3577 /usr/bin/bash guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=1c6aac14-1700-0000-d60a-354df90d0000 pid=3577 clone guuid=f826b414-1700-0000-d60a-354dfa0d0000 pid=3578 /usr/bin/bash guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=f826b414-1700-0000-d60a-354dfa0d0000 pid=3578 clone guuid=4fe0ed14-1700-0000-d60a-354dfb0d0000 pid=3579 /usr/bin/mkdir guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=4fe0ed14-1700-0000-d60a-354dfb0d0000 pid=3579 execve guuid=4bb35c15-1700-0000-d60a-354dfd0d0000 pid=3581 /usr/bin/mkdir guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=4bb35c15-1700-0000-d60a-354dfd0d0000 pid=3581 execve guuid=21e9dd15-1700-0000-d60a-354d000e0000 pid=3584 /usr/bin/mkdir guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=21e9dd15-1700-0000-d60a-354d000e0000 pid=3584 execve guuid=7deb4e16-1700-0000-d60a-354d020e0000 pid=3586 /usr/bin/mkdir guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=7deb4e16-1700-0000-d60a-354d020e0000 pid=3586 execve guuid=637bc816-1700-0000-d60a-354d040e0000 pid=3588 /usr/bin/mkdir guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=637bc816-1700-0000-d60a-354d040e0000 pid=3588 execve guuid=5f124017-1700-0000-d60a-354d060e0000 pid=3590 /usr/bin/mkdir guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=5f124017-1700-0000-d60a-354d060e0000 pid=3590 execve guuid=789f9d17-1700-0000-d60a-354d090e0000 pid=3593 /usr/bin/mkdir guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=789f9d17-1700-0000-d60a-354d090e0000 pid=3593 execve guuid=d782e717-1700-0000-d60a-354d0b0e0000 pid=3595 /usr/bin/cp guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=d782e717-1700-0000-d60a-354d0b0e0000 pid=3595 execve guuid=634f3b18-1700-0000-d60a-354d0d0e0000 pid=3597 /usr/bin/cp guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=634f3b18-1700-0000-d60a-354d0d0e0000 pid=3597 execve guuid=402e9218-1700-0000-d60a-354d0f0e0000 pid=3599 /usr/bin/cp guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=402e9218-1700-0000-d60a-354d0f0e0000 pid=3599 execve guuid=daace218-1700-0000-d60a-354d110e0000 pid=3601 /usr/bin/cp guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=daace218-1700-0000-d60a-354d110e0000 pid=3601 execve guuid=658c3419-1700-0000-d60a-354d130e0000 pid=3603 /usr/bin/cp guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=658c3419-1700-0000-d60a-354d130e0000 pid=3603 execve guuid=8d6d8619-1700-0000-d60a-354d150e0000 pid=3605 /usr/bin/cp guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=8d6d8619-1700-0000-d60a-354d150e0000 pid=3605 execve guuid=162ee019-1700-0000-d60a-354d180e0000 pid=3608 /usr/bin/cp guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=162ee019-1700-0000-d60a-354d180e0000 pid=3608 execve guuid=04c03c1a-1700-0000-d60a-354d190e0000 pid=3609 /usr/bin/cp guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=04c03c1a-1700-0000-d60a-354d190e0000 pid=3609 execve guuid=138b961a-1700-0000-d60a-354d1c0e0000 pid=3612 /usr/bin/cp guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=138b961a-1700-0000-d60a-354d1c0e0000 pid=3612 execve guuid=abcef01a-1700-0000-d60a-354d1e0e0000 pid=3614 /usr/bin/cp guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=abcef01a-1700-0000-d60a-354d1e0e0000 pid=3614 execve guuid=b85d4a1b-1700-0000-d60a-354d200e0000 pid=3616 /usr/bin/cp guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=b85d4a1b-1700-0000-d60a-354d200e0000 pid=3616 execve guuid=ecb6aa1b-1700-0000-d60a-354d210e0000 pid=3617 /usr/bin/cp guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=ecb6aa1b-1700-0000-d60a-354d210e0000 pid=3617 execve guuid=6fd1051c-1700-0000-d60a-354d220e0000 pid=3618 /usr/bin/cp guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=6fd1051c-1700-0000-d60a-354d220e0000 pid=3618 execve guuid=fd34651c-1700-0000-d60a-354d240e0000 pid=3620 /usr/bin/cp guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=fd34651c-1700-0000-d60a-354d240e0000 pid=3620 execve guuid=7316c21c-1700-0000-d60a-354d270e0000 pid=3623 /usr/bin/cp guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=7316c21c-1700-0000-d60a-354d270e0000 pid=3623 execve guuid=2a0d191d-1700-0000-d60a-354d290e0000 pid=3625 /usr/bin/touch guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=2a0d191d-1700-0000-d60a-354d290e0000 pid=3625 execve guuid=28fc5c1d-1700-0000-d60a-354d2c0e0000 pid=3628 /usr/bin/bash guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=28fc5c1d-1700-0000-d60a-354d2c0e0000 pid=3628 clone guuid=da5a641d-1700-0000-d60a-354d2d0e0000 pid=3629 /usr/bin/bash guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=da5a641d-1700-0000-d60a-354d2d0e0000 pid=3629 clone guuid=14537e1d-1700-0000-d60a-354d2e0e0000 pid=3630 /usr/bin/bash guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=14537e1d-1700-0000-d60a-354d2e0e0000 pid=3630 clone guuid=aa51841d-1700-0000-d60a-354d2f0e0000 pid=3631 /usr/bin/base64 write-file guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=aa51841d-1700-0000-d60a-354d2f0e0000 pid=3631 execve guuid=e7e7fe1d-1700-0000-d60a-354d320e0000 pid=3634 /usr/bin/bash guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=e7e7fe1d-1700-0000-d60a-354d320e0000 pid=3634 execve guuid=60363e22-1700-0000-d60a-354d5a0e0000 pid=3674 /usr/bin/rm delete-file guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=60363e22-1700-0000-d60a-354d5a0e0000 pid=3674 execve guuid=f4708122-1700-0000-d60a-354d5c0e0000 pid=3676 /usr/bin/bash guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=f4708122-1700-0000-d60a-354d5c0e0000 pid=3676 clone guuid=8bed8622-1700-0000-d60a-354d5d0e0000 pid=3677 /usr/bin/bash guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=8bed8622-1700-0000-d60a-354d5d0e0000 pid=3677 clone guuid=2179d022-1700-0000-d60a-354d5f0e0000 pid=3679 /usr/bin/bash guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=2179d022-1700-0000-d60a-354d5f0e0000 pid=3679 execve guuid=55c52223-1700-0000-d60a-354d610e0000 pid=3681 /usr/bin/rm guuid=611d3814-1700-0000-d60a-354df70d0000 pid=3575->guuid=55c52223-1700-0000-d60a-354d610e0000 pid=3681 execve guuid=d3d94d1e-1700-0000-d60a-354d340e0000 pid=3636 /usr/bin/bash guuid=e7e7fe1d-1700-0000-d60a-354d320e0000 pid=3634->guuid=d3d94d1e-1700-0000-d60a-354d340e0000 pid=3636 clone guuid=0dbb541e-1700-0000-d60a-354d350e0000 pid=3637 /usr/bin/bash guuid=e7e7fe1d-1700-0000-d60a-354d320e0000 pid=3634->guuid=0dbb541e-1700-0000-d60a-354d350e0000 pid=3637 clone guuid=0703731e-1700-0000-d60a-354d370e0000 pid=3639 /usr/bin/ls guuid=e7e7fe1d-1700-0000-d60a-354d320e0000 pid=3634->guuid=0703731e-1700-0000-d60a-354d370e0000 pid=3639 execve guuid=663ed41e-1700-0000-d60a-354d390e0000 pid=3641 /usr/bin/cat guuid=e7e7fe1d-1700-0000-d60a-354d320e0000 pid=3634->guuid=663ed41e-1700-0000-d60a-354d390e0000 pid=3641 execve guuid=b172161f-1700-0000-d60a-354d3d0e0000 pid=3645 /usr/bin/ls guuid=e7e7fe1d-1700-0000-d60a-354d320e0000 pid=3634->guuid=b172161f-1700-0000-d60a-354d3d0e0000 pid=3645 execve guuid=0c03701f-1700-0000-d60a-354d3e0e0000 pid=3646 /usr/bin/mkdir guuid=e7e7fe1d-1700-0000-d60a-354d320e0000 pid=3634->guuid=0c03701f-1700-0000-d60a-354d3e0e0000 pid=3646 execve guuid=4895b91f-1700-0000-d60a-354d410e0000 pid=3649 /usr/bin/mv guuid=e7e7fe1d-1700-0000-d60a-354d320e0000 pid=3634->guuid=4895b91f-1700-0000-d60a-354d410e0000 pid=3649 execve guuid=098c0e20-1700-0000-d60a-354d450e0000 pid=3653 /usr/bin/bash guuid=e7e7fe1d-1700-0000-d60a-354d320e0000 pid=3634->guuid=098c0e20-1700-0000-d60a-354d450e0000 pid=3653 clone guuid=9c091620-1700-0000-d60a-354d470e0000 pid=3655 /usr/bin/base64 write-file guuid=e7e7fe1d-1700-0000-d60a-354d320e0000 pid=3634->guuid=9c091620-1700-0000-d60a-354d470e0000 pid=3655 execve guuid=e38c5a20-1700-0000-d60a-354d480e0000 pid=3656 /usr/bin/rm delete-file guuid=e7e7fe1d-1700-0000-d60a-354d320e0000 pid=3634->guuid=e38c5a20-1700-0000-d60a-354d480e0000 pid=3656 execve guuid=a3d59c20-1700-0000-d60a-354d4c0e0000 pid=3660 /usr/bin/ls guuid=e7e7fe1d-1700-0000-d60a-354d320e0000 pid=3634->guuid=a3d59c20-1700-0000-d60a-354d4c0e0000 pid=3660 execve guuid=a69bfa20-1700-0000-d60a-354d500e0000 pid=3664 /usr/bin/bash guuid=e7e7fe1d-1700-0000-d60a-354d320e0000 pid=3634->guuid=a69bfa20-1700-0000-d60a-354d500e0000 pid=3664 clone guuid=52280021-1700-0000-d60a-354d510e0000 pid=3665 /usr/bin/base64 write-file guuid=e7e7fe1d-1700-0000-d60a-354d320e0000 pid=3634->guuid=52280021-1700-0000-d60a-354d510e0000 pid=3665 execve guuid=61244421-1700-0000-d60a-354d520e0000 pid=3666 /usr/bin/ls guuid=e7e7fe1d-1700-0000-d60a-354d320e0000 pid=3634->guuid=61244421-1700-0000-d60a-354d520e0000 pid=3666 execve guuid=43719c21-1700-0000-d60a-354d550e0000 pid=3669 /usr/bin/cat guuid=e7e7fe1d-1700-0000-d60a-354d320e0000 pid=3634->guuid=43719c21-1700-0000-d60a-354d550e0000 pid=3669 execve guuid=1c1cd321-1700-0000-d60a-354d570e0000 pid=3671 /usr/bin/ls guuid=e7e7fe1d-1700-0000-d60a-354d320e0000 pid=3634->guuid=1c1cd321-1700-0000-d60a-354d570e0000 pid=3671 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Heuristic
Status:
Malicious
First seen:
2026-03-23 11:31:27 UTC
File Type:
Text (Shell)
AV detection:
14 of 36 (38.89%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 8558676255b31a3cab152fcbf4bb07e799f61ebfcd1323dd1a14cd95a33281e8

(this sample)

  
Delivery method
Distributed via web download

Comments