MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 887b96afc1ca21d53fcb21f6e95396b041ddeb34db4b1682ece4cd5a3abe56d6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 887b96afc1ca21d53fcb21f6e95396b041ddeb34db4b1682ece4cd5a3abe56d6
SHA3-384 hash: 1e2f5d1ebfe0b2aec7341bc1bd9acbf7971fd973736fe59bda017ce089e785436418ac65c41813e04bb262d3498f18ba
SHA1 hash: ec026bd89e53786e4c6a3030a51ee364117c05df
MD5 hash: 5ac9f754f3edc409dfdcf2130db76f83
humanhash: double-salami-five-nine
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-18 09:54:09 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:wFcuQpWx+BL0SWL0gMzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:wF8i+BL0SI0XzsP4cbddr7zsP4cbddrk
TLSH T129925DB512896C79FBD0CE399F3C6F4CADE8C2C42124E3ACBA4F39205A1166DC70534A
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=8a393d40-1700-0000-2d48-f1831a0d0000 pid=3354 /usr/bin/sudo guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360 /tmp/sample.bin guuid=8a393d40-1700-0000-2d48-f1831a0d0000 pid=3354->guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360 execve guuid=bb206042-1700-0000-2d48-f183220d0000 pid=3362 /usr/bin/bash guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=bb206042-1700-0000-2d48-f183220d0000 pid=3362 clone guuid=4b8c6742-1700-0000-2d48-f183230d0000 pid=3363 /usr/bin/bash guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=4b8c6742-1700-0000-2d48-f183230d0000 pid=3363 clone guuid=f0178042-1700-0000-2d48-f183240d0000 pid=3364 /usr/bin/mkdir guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=f0178042-1700-0000-2d48-f183240d0000 pid=3364 execve guuid=81fd0243-1700-0000-2d48-f183260d0000 pid=3366 /usr/bin/mkdir guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=81fd0243-1700-0000-2d48-f183260d0000 pid=3366 execve guuid=f41d6d43-1700-0000-2d48-f183280d0000 pid=3368 /usr/bin/mkdir guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=f41d6d43-1700-0000-2d48-f183280d0000 pid=3368 execve guuid=93cbbb43-1700-0000-2d48-f1832a0d0000 pid=3370 /usr/bin/mkdir guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=93cbbb43-1700-0000-2d48-f1832a0d0000 pid=3370 execve guuid=8aba1344-1700-0000-2d48-f1832c0d0000 pid=3372 /usr/bin/mkdir guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=8aba1344-1700-0000-2d48-f1832c0d0000 pid=3372 execve guuid=51ce6344-1700-0000-2d48-f1832e0d0000 pid=3374 /usr/bin/mkdir guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=51ce6344-1700-0000-2d48-f1832e0d0000 pid=3374 execve guuid=1828b644-1700-0000-2d48-f183300d0000 pid=3376 /usr/bin/mkdir guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=1828b644-1700-0000-2d48-f183300d0000 pid=3376 execve guuid=a3310d45-1700-0000-2d48-f183320d0000 pid=3378 /usr/bin/cp guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=a3310d45-1700-0000-2d48-f183320d0000 pid=3378 execve guuid=90c99945-1700-0000-2d48-f183340d0000 pid=3380 /usr/bin/cp guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=90c99945-1700-0000-2d48-f183340d0000 pid=3380 execve guuid=de9a0f46-1700-0000-2d48-f183360d0000 pid=3382 /usr/bin/cp guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=de9a0f46-1700-0000-2d48-f183360d0000 pid=3382 execve guuid=ace07d46-1700-0000-2d48-f183380d0000 pid=3384 /usr/bin/cp guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=ace07d46-1700-0000-2d48-f183380d0000 pid=3384 execve guuid=573bdb46-1700-0000-2d48-f1833a0d0000 pid=3386 /usr/bin/cp guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=573bdb46-1700-0000-2d48-f1833a0d0000 pid=3386 execve guuid=a2844c47-1700-0000-2d48-f1833d0d0000 pid=3389 /usr/bin/cp guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=a2844c47-1700-0000-2d48-f1833d0d0000 pid=3389 execve guuid=5924bd47-1700-0000-2d48-f1833f0d0000 pid=3391 /usr/bin/cp guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=5924bd47-1700-0000-2d48-f1833f0d0000 pid=3391 execve guuid=bde02d48-1700-0000-2d48-f183420d0000 pid=3394 /usr/bin/cp guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=bde02d48-1700-0000-2d48-f183420d0000 pid=3394 execve guuid=6de29748-1700-0000-2d48-f183440d0000 pid=3396 /usr/bin/cp guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=6de29748-1700-0000-2d48-f183440d0000 pid=3396 execve guuid=837cf448-1700-0000-2d48-f183470d0000 pid=3399 /usr/bin/cp guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=837cf448-1700-0000-2d48-f183470d0000 pid=3399 execve guuid=d0505349-1700-0000-2d48-f183490d0000 pid=3401 /usr/bin/cp guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=d0505349-1700-0000-2d48-f183490d0000 pid=3401 execve guuid=9461a349-1700-0000-2d48-f1834c0d0000 pid=3404 /usr/bin/cp guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=9461a349-1700-0000-2d48-f1834c0d0000 pid=3404 execve guuid=35d7004a-1700-0000-2d48-f1834e0d0000 pid=3406 /usr/bin/cp guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=35d7004a-1700-0000-2d48-f1834e0d0000 pid=3406 execve guuid=6658554a-1700-0000-2d48-f183510d0000 pid=3409 /usr/bin/cp guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=6658554a-1700-0000-2d48-f183510d0000 pid=3409 execve guuid=5680ad4a-1700-0000-2d48-f183520d0000 pid=3410 /usr/bin/cp guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=5680ad4a-1700-0000-2d48-f183520d0000 pid=3410 execve guuid=8208ff4a-1700-0000-2d48-f183540d0000 pid=3412 /usr/bin/touch guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=8208ff4a-1700-0000-2d48-f183540d0000 pid=3412 execve guuid=81b23f4b-1700-0000-2d48-f183560d0000 pid=3414 /usr/bin/bash guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=81b23f4b-1700-0000-2d48-f183560d0000 pid=3414 clone guuid=1ff3444b-1700-0000-2d48-f183570d0000 pid=3415 /usr/bin/bash guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=1ff3444b-1700-0000-2d48-f183570d0000 pid=3415 clone guuid=358c614b-1700-0000-2d48-f183580d0000 pid=3416 /usr/bin/bash guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=358c614b-1700-0000-2d48-f183580d0000 pid=3416 clone guuid=d93b684b-1700-0000-2d48-f183590d0000 pid=3417 /usr/bin/base64 write-file guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=d93b684b-1700-0000-2d48-f183590d0000 pid=3417 execve guuid=26b2d84b-1700-0000-2d48-f1835c0d0000 pid=3420 /usr/bin/bash guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=26b2d84b-1700-0000-2d48-f1835c0d0000 pid=3420 execve guuid=94ff8050-1700-0000-2d48-f183800d0000 pid=3456 /usr/bin/rm delete-file guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=94ff8050-1700-0000-2d48-f183800d0000 pid=3456 execve guuid=c53fd850-1700-0000-2d48-f183810d0000 pid=3457 /usr/bin/bash guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=c53fd850-1700-0000-2d48-f183810d0000 pid=3457 clone guuid=f44adf50-1700-0000-2d48-f183820d0000 pid=3458 /usr/bin/bash guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=f44adf50-1700-0000-2d48-f183820d0000 pid=3458 clone guuid=68511351-1700-0000-2d48-f183840d0000 pid=3460 /usr/bin/bash guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=68511351-1700-0000-2d48-f183840d0000 pid=3460 execve guuid=3ce86151-1700-0000-2d48-f183860d0000 pid=3462 /usr/bin/rm guuid=1b481042-1700-0000-2d48-f183200d0000 pid=3360->guuid=3ce86151-1700-0000-2d48-f183860d0000 pid=3462 execve guuid=18e3254c-1700-0000-2d48-f1835e0d0000 pid=3422 /usr/bin/bash guuid=26b2d84b-1700-0000-2d48-f1835c0d0000 pid=3420->guuid=18e3254c-1700-0000-2d48-f1835e0d0000 pid=3422 clone guuid=5b852b4c-1700-0000-2d48-f1835f0d0000 pid=3423 /usr/bin/bash guuid=26b2d84b-1700-0000-2d48-f1835c0d0000 pid=3420->guuid=5b852b4c-1700-0000-2d48-f1835f0d0000 pid=3423 clone guuid=072f464c-1700-0000-2d48-f183610d0000 pid=3425 /usr/bin/ls guuid=26b2d84b-1700-0000-2d48-f1835c0d0000 pid=3420->guuid=072f464c-1700-0000-2d48-f183610d0000 pid=3425 execve guuid=87c5b94c-1700-0000-2d48-f183640d0000 pid=3428 /usr/bin/cat guuid=26b2d84b-1700-0000-2d48-f1835c0d0000 pid=3420->guuid=87c5b94c-1700-0000-2d48-f183640d0000 pid=3428 execve guuid=e9df064d-1700-0000-2d48-f183660d0000 pid=3430 /usr/bin/ls guuid=26b2d84b-1700-0000-2d48-f1835c0d0000 pid=3420->guuid=e9df064d-1700-0000-2d48-f183660d0000 pid=3430 execve guuid=779b694d-1700-0000-2d48-f183690d0000 pid=3433 /usr/bin/mkdir guuid=26b2d84b-1700-0000-2d48-f1835c0d0000 pid=3420->guuid=779b694d-1700-0000-2d48-f183690d0000 pid=3433 execve guuid=2ae0b34d-1700-0000-2d48-f1836b0d0000 pid=3435 /usr/bin/mv guuid=26b2d84b-1700-0000-2d48-f1835c0d0000 pid=3420->guuid=2ae0b34d-1700-0000-2d48-f1836b0d0000 pid=3435 execve guuid=52870d4e-1700-0000-2d48-f1836d0d0000 pid=3437 /usr/bin/bash guuid=26b2d84b-1700-0000-2d48-f1835c0d0000 pid=3420->guuid=52870d4e-1700-0000-2d48-f1836d0d0000 pid=3437 clone guuid=c02c144e-1700-0000-2d48-f1836e0d0000 pid=3438 /usr/bin/base64 write-file guuid=26b2d84b-1700-0000-2d48-f1835c0d0000 pid=3420->guuid=c02c144e-1700-0000-2d48-f1836e0d0000 pid=3438 execve guuid=025a624e-1700-0000-2d48-f183700d0000 pid=3440 /usr/bin/rm delete-file guuid=26b2d84b-1700-0000-2d48-f1835c0d0000 pid=3420->guuid=025a624e-1700-0000-2d48-f183700d0000 pid=3440 execve guuid=36b0a54e-1700-0000-2d48-f183720d0000 pid=3442 /usr/bin/ls guuid=26b2d84b-1700-0000-2d48-f1835c0d0000 pid=3420->guuid=36b0a54e-1700-0000-2d48-f183720d0000 pid=3442 execve guuid=2ce4074f-1700-0000-2d48-f183750d0000 pid=3445 /usr/bin/bash guuid=26b2d84b-1700-0000-2d48-f1835c0d0000 pid=3420->guuid=2ce4074f-1700-0000-2d48-f183750d0000 pid=3445 clone guuid=2b0f0f4f-1700-0000-2d48-f183760d0000 pid=3446 /usr/bin/base64 write-file guuid=26b2d84b-1700-0000-2d48-f1835c0d0000 pid=3420->guuid=2b0f0f4f-1700-0000-2d48-f183760d0000 pid=3446 execve guuid=11f2544f-1700-0000-2d48-f183780d0000 pid=3448 /usr/bin/ls guuid=26b2d84b-1700-0000-2d48-f1835c0d0000 pid=3420->guuid=11f2544f-1700-0000-2d48-f183780d0000 pid=3448 execve guuid=d520c54f-1700-0000-2d48-f1837b0d0000 pid=3451 /usr/bin/cat guuid=26b2d84b-1700-0000-2d48-f1835c0d0000 pid=3420->guuid=d520c54f-1700-0000-2d48-f1837b0d0000 pid=3451 execve guuid=afca0650-1700-0000-2d48-f1837d0d0000 pid=3453 /usr/bin/ls guuid=26b2d84b-1700-0000-2d48-f1835c0d0000 pid=3420->guuid=afca0650-1700-0000-2d48-f1837d0d0000 pid=3453 execve
Threat name:
Script-Shell.Trojan.Heuristic
Status:
Malicious
First seen:
2026-03-18 09:54:31 UTC
File Type:
Text (Shell)
AV detection:
14 of 36 (38.89%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 887b96afc1ca21d53fcb21f6e95396b041ddeb34db4b1682ece4cd5a3abe56d6

(this sample)

  
Delivery method
Distributed via web download

Comments