MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8fb95694f8403b0daac49f9cab0a68da45d06e7c14ba67c30c0a6b466ea3d52d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 8fb95694f8403b0daac49f9cab0a68da45d06e7c14ba67c30c0a6b466ea3d52d
SHA3-384 hash: baba16da4caf9757d89fcf1cdd84d86003bace0d8c488adefdaebae8a1a450fbbfcd487f23bc085023d5558e2033c1e5
SHA1 hash: c861d2677da3688ecb61305c2dd7ea7e52e6159a
MD5 hash: 58c4a007f30b2489789c96dd574713ae
humanhash: lion-low-mississippi-california
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-16 16:59:49 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:hQFcuQpWx+BL0SWL0gxzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:hQF8i+BL0SI0SzsP4cbddr7zsP4cbddo
TLSH T156925CB512896C79FBD1CE39AF3C7F4CADE8C2C42124A3ACBA0F39215A1166DC705359
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=df635aa8-1600-0000-2282-e9eea10e0000 pid=3745 /usr/bin/sudo guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752 /tmp/sample.bin guuid=df635aa8-1600-0000-2282-e9eea10e0000 pid=3745->guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752 execve guuid=01560cab-1600-0000-2282-e9eeaa0e0000 pid=3754 /usr/bin/bash guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=01560cab-1600-0000-2282-e9eeaa0e0000 pid=3754 clone guuid=4d6f17ab-1600-0000-2282-e9eeab0e0000 pid=3755 /usr/bin/bash guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=4d6f17ab-1600-0000-2282-e9eeab0e0000 pid=3755 clone guuid=cc8535ab-1600-0000-2282-e9eead0e0000 pid=3757 /usr/bin/mkdir guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=cc8535ab-1600-0000-2282-e9eead0e0000 pid=3757 execve guuid=fb809fab-1600-0000-2282-e9eeae0e0000 pid=3758 /usr/bin/mkdir guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=fb809fab-1600-0000-2282-e9eeae0e0000 pid=3758 execve guuid=d149f9ab-1600-0000-2282-e9eeb00e0000 pid=3760 /usr/bin/mkdir guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=d149f9ab-1600-0000-2282-e9eeb00e0000 pid=3760 execve guuid=23f74cac-1600-0000-2282-e9eeb20e0000 pid=3762 /usr/bin/mkdir guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=23f74cac-1600-0000-2282-e9eeb20e0000 pid=3762 execve guuid=0758afac-1600-0000-2282-e9eeb50e0000 pid=3765 /usr/bin/mkdir guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=0758afac-1600-0000-2282-e9eeb50e0000 pid=3765 execve guuid=053211ad-1600-0000-2282-e9eeb70e0000 pid=3767 /usr/bin/mkdir guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=053211ad-1600-0000-2282-e9eeb70e0000 pid=3767 execve guuid=48386bad-1600-0000-2282-e9eeba0e0000 pid=3770 /usr/bin/mkdir guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=48386bad-1600-0000-2282-e9eeba0e0000 pid=3770 execve guuid=2877c8ad-1600-0000-2282-e9eebc0e0000 pid=3772 /usr/bin/cp guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=2877c8ad-1600-0000-2282-e9eebc0e0000 pid=3772 execve guuid=80143eae-1600-0000-2282-e9eec10e0000 pid=3777 /usr/bin/cp guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=80143eae-1600-0000-2282-e9eec10e0000 pid=3777 execve guuid=988ea5ae-1600-0000-2282-e9eec40e0000 pid=3780 /usr/bin/cp guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=988ea5ae-1600-0000-2282-e9eec40e0000 pid=3780 execve guuid=f0201faf-1600-0000-2282-e9eec90e0000 pid=3785 /usr/bin/cp guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=f0201faf-1600-0000-2282-e9eec90e0000 pid=3785 execve guuid=932b95af-1600-0000-2282-e9eecc0e0000 pid=3788 /usr/bin/cp guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=932b95af-1600-0000-2282-e9eecc0e0000 pid=3788 execve guuid=bd0a02b0-1600-0000-2282-e9eecf0e0000 pid=3791 /usr/bin/cp guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=bd0a02b0-1600-0000-2282-e9eecf0e0000 pid=3791 execve guuid=113a57b0-1600-0000-2282-e9eed20e0000 pid=3794 /usr/bin/cp guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=113a57b0-1600-0000-2282-e9eed20e0000 pid=3794 execve guuid=38cbd3b0-1600-0000-2282-e9eed50e0000 pid=3797 /usr/bin/cp guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=38cbd3b0-1600-0000-2282-e9eed50e0000 pid=3797 execve guuid=911931b1-1600-0000-2282-e9eed80e0000 pid=3800 /usr/bin/cp guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=911931b1-1600-0000-2282-e9eed80e0000 pid=3800 execve guuid=54fc9ab1-1600-0000-2282-e9eedb0e0000 pid=3803 /usr/bin/cp guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=54fc9ab1-1600-0000-2282-e9eedb0e0000 pid=3803 execve guuid=bd6bf0b1-1600-0000-2282-e9eede0e0000 pid=3806 /usr/bin/cp guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=bd6bf0b1-1600-0000-2282-e9eede0e0000 pid=3806 execve guuid=09b055b2-1600-0000-2282-e9eee20e0000 pid=3810 /usr/bin/cp guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=09b055b2-1600-0000-2282-e9eee20e0000 pid=3810 execve guuid=a149aeb2-1600-0000-2282-e9eee60e0000 pid=3814 /usr/bin/cp guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=a149aeb2-1600-0000-2282-e9eee60e0000 pid=3814 execve guuid=2ed82db3-1600-0000-2282-e9eee90e0000 pid=3817 /usr/bin/cp guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=2ed82db3-1600-0000-2282-e9eee90e0000 pid=3817 execve guuid=90679eb3-1600-0000-2282-e9eeed0e0000 pid=3821 /usr/bin/cp guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=90679eb3-1600-0000-2282-e9eeed0e0000 pid=3821 execve guuid=a60afdb3-1600-0000-2282-e9eef10e0000 pid=3825 /usr/bin/touch guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=a60afdb3-1600-0000-2282-e9eef10e0000 pid=3825 execve guuid=9bbe5cb4-1600-0000-2282-e9eef40e0000 pid=3828 /usr/bin/bash guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=9bbe5cb4-1600-0000-2282-e9eef40e0000 pid=3828 clone guuid=7f8a62b4-1600-0000-2282-e9eef50e0000 pid=3829 /usr/bin/bash guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=7f8a62b4-1600-0000-2282-e9eef50e0000 pid=3829 clone guuid=d4bf98b4-1600-0000-2282-e9eef70e0000 pid=3831 /usr/bin/bash guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=d4bf98b4-1600-0000-2282-e9eef70e0000 pid=3831 clone guuid=d9c2aab4-1600-0000-2282-e9eef80e0000 pid=3832 /usr/bin/base64 write-file guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=d9c2aab4-1600-0000-2282-e9eef80e0000 pid=3832 execve guuid=ce7735b5-1600-0000-2282-e9eefb0e0000 pid=3835 /usr/bin/bash guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=ce7735b5-1600-0000-2282-e9eefb0e0000 pid=3835 execve guuid=8a21b7bb-1600-0000-2282-e9ee1f0f0000 pid=3871 /usr/bin/rm delete-file guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=8a21b7bb-1600-0000-2282-e9ee1f0f0000 pid=3871 execve guuid=3691fdbb-1600-0000-2282-e9ee200f0000 pid=3872 /usr/bin/bash guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=3691fdbb-1600-0000-2282-e9ee200f0000 pid=3872 clone guuid=26bd03bc-1600-0000-2282-e9ee210f0000 pid=3873 /usr/bin/bash guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=26bd03bc-1600-0000-2282-e9ee210f0000 pid=3873 clone guuid=8b5f40bc-1600-0000-2282-e9ee220f0000 pid=3874 /usr/bin/bash guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=8b5f40bc-1600-0000-2282-e9ee220f0000 pid=3874 execve guuid=e3c0a2bc-1600-0000-2282-e9ee250f0000 pid=3877 /usr/bin/rm guuid=153ab3aa-1600-0000-2282-e9eea80e0000 pid=3752->guuid=e3c0a2bc-1600-0000-2282-e9ee250f0000 pid=3877 execve guuid=15d888b5-1600-0000-2282-e9ee010f0000 pid=3841 /usr/bin/bash guuid=ce7735b5-1600-0000-2282-e9eefb0e0000 pid=3835->guuid=15d888b5-1600-0000-2282-e9ee010f0000 pid=3841 clone guuid=5cd091b5-1600-0000-2282-e9ee020f0000 pid=3842 /usr/bin/bash guuid=ce7735b5-1600-0000-2282-e9eefb0e0000 pid=3835->guuid=5cd091b5-1600-0000-2282-e9ee020f0000 pid=3842 clone guuid=b45e00b6-1600-0000-2282-e9ee050f0000 pid=3845 /usr/bin/ls guuid=ce7735b5-1600-0000-2282-e9eefb0e0000 pid=3835->guuid=b45e00b6-1600-0000-2282-e9ee050f0000 pid=3845 execve guuid=2d36ddb6-1600-0000-2282-e9ee060f0000 pid=3846 /usr/bin/cat guuid=ce7735b5-1600-0000-2282-e9eefb0e0000 pid=3835->guuid=2d36ddb6-1600-0000-2282-e9ee060f0000 pid=3846 execve guuid=df9b34b7-1600-0000-2282-e9ee070f0000 pid=3847 /usr/bin/ls guuid=ce7735b5-1600-0000-2282-e9eefb0e0000 pid=3835->guuid=df9b34b7-1600-0000-2282-e9ee070f0000 pid=3847 execve guuid=67bc00b8-1600-0000-2282-e9ee080f0000 pid=3848 /usr/bin/mkdir guuid=ce7735b5-1600-0000-2282-e9eefb0e0000 pid=3835->guuid=67bc00b8-1600-0000-2282-e9ee080f0000 pid=3848 execve guuid=c9a169b8-1600-0000-2282-e9ee090f0000 pid=3849 /usr/bin/mv guuid=ce7735b5-1600-0000-2282-e9eefb0e0000 pid=3835->guuid=c9a169b8-1600-0000-2282-e9ee090f0000 pid=3849 execve guuid=0eddddb8-1600-0000-2282-e9ee0a0f0000 pid=3850 /usr/bin/bash guuid=ce7735b5-1600-0000-2282-e9eefb0e0000 pid=3835->guuid=0eddddb8-1600-0000-2282-e9ee0a0f0000 pid=3850 clone guuid=15cbe9b8-1600-0000-2282-e9ee0b0f0000 pid=3851 /usr/bin/base64 write-file guuid=ce7735b5-1600-0000-2282-e9eefb0e0000 pid=3835->guuid=15cbe9b8-1600-0000-2282-e9ee0b0f0000 pid=3851 execve guuid=87b289b9-1600-0000-2282-e9ee0e0f0000 pid=3854 /usr/bin/rm delete-file guuid=ce7735b5-1600-0000-2282-e9eefb0e0000 pid=3835->guuid=87b289b9-1600-0000-2282-e9ee0e0f0000 pid=3854 execve guuid=bc15cfb9-1600-0000-2282-e9ee100f0000 pid=3856 /usr/bin/ls guuid=ce7735b5-1600-0000-2282-e9eefb0e0000 pid=3835->guuid=bc15cfb9-1600-0000-2282-e9ee100f0000 pid=3856 execve guuid=f5b73fba-1600-0000-2282-e9ee130f0000 pid=3859 /usr/bin/bash guuid=ce7735b5-1600-0000-2282-e9eefb0e0000 pid=3835->guuid=f5b73fba-1600-0000-2282-e9ee130f0000 pid=3859 clone guuid=24d645ba-1600-0000-2282-e9ee140f0000 pid=3860 /usr/bin/base64 write-file guuid=ce7735b5-1600-0000-2282-e9eefb0e0000 pid=3835->guuid=24d645ba-1600-0000-2282-e9ee140f0000 pid=3860 execve guuid=dc3193ba-1600-0000-2282-e9ee160f0000 pid=3862 /usr/bin/ls guuid=ce7735b5-1600-0000-2282-e9eefb0e0000 pid=3835->guuid=dc3193ba-1600-0000-2282-e9ee160f0000 pid=3862 execve guuid=f92cf2ba-1600-0000-2282-e9ee190f0000 pid=3865 /usr/bin/cat guuid=ce7735b5-1600-0000-2282-e9eefb0e0000 pid=3835->guuid=f92cf2ba-1600-0000-2282-e9ee190f0000 pid=3865 execve guuid=c21c3dbb-1600-0000-2282-e9ee1b0f0000 pid=3867 /usr/bin/ls guuid=ce7735b5-1600-0000-2282-e9eefb0e0000 pid=3835->guuid=c21c3dbb-1600-0000-2282-e9ee1b0f0000 pid=3867 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-16 17:00:26 UTC
File Type:
Text (Shell)
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 8fb95694f8403b0daac49f9cab0a68da45d06e7c14ba67c30c0a6b466ea3d52d

(this sample)

  
Delivery method
Distributed via web download

Comments