MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 92a254eff4ae5a3072343f65148d4b864ff60802aca0bee44a59ba0cce3af854. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 92a254eff4ae5a3072343f65148d4b864ff60802aca0bee44a59ba0cce3af854
SHA3-384 hash: e9281fc8779e70ef7630be779474c22b2d538cc035ef7b6647ffc0d585c7a330423824d7c7bec170da96d68d2c41a16c
SHA1 hash: 56833595fe690aeb4983216f47da8b97a80d6ad8
MD5 hash: 87f94baff83795181437980f729aa89c
humanhash: robin-fix-uncle-yellow
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-10 21:38:01 UTC
Last seen:2026-03-11 04:50:18 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 384:AFcuQpWx+BL0SWL0gtzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:AF8i+BL0SI0izsP4cbddr7zsP4cbddrk
TLSH T188925CB512896C79FBD0CE399F3C7F4CADE882C42124A3ACBA4F39215A1166DCB05359
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
2
# of downloads :
57
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=8fbbd7c1-1700-0000-3f71-ed4df90b0000 pid=3065 /usr/bin/sudo guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071 /tmp/sample.bin guuid=8fbbd7c1-1700-0000-3f71-ed4df90b0000 pid=3065->guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071 execve guuid=4047c6c3-1700-0000-3f71-ed4d010c0000 pid=3073 /usr/bin/bash guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=4047c6c3-1700-0000-3f71-ed4d010c0000 pid=3073 clone guuid=99a6cbc3-1700-0000-3f71-ed4d020c0000 pid=3074 /usr/bin/bash guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=99a6cbc3-1700-0000-3f71-ed4d020c0000 pid=3074 clone guuid=99361ac4-1700-0000-3f71-ed4d040c0000 pid=3076 /usr/bin/mkdir guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=99361ac4-1700-0000-3f71-ed4d040c0000 pid=3076 execve guuid=a37e6cc4-1700-0000-3f71-ed4d060c0000 pid=3078 /usr/bin/mkdir guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=a37e6cc4-1700-0000-3f71-ed4d060c0000 pid=3078 execve guuid=3d08bac4-1700-0000-3f71-ed4d080c0000 pid=3080 /usr/bin/mkdir guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=3d08bac4-1700-0000-3f71-ed4d080c0000 pid=3080 execve guuid=a29d37c5-1700-0000-3f71-ed4d0b0c0000 pid=3083 /usr/bin/mkdir guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=a29d37c5-1700-0000-3f71-ed4d0b0c0000 pid=3083 execve guuid=e88e8bc5-1700-0000-3f71-ed4d0c0c0000 pid=3084 /usr/bin/mkdir guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=e88e8bc5-1700-0000-3f71-ed4d0c0c0000 pid=3084 execve guuid=8c26d9c5-1700-0000-3f71-ed4d0e0c0000 pid=3086 /usr/bin/mkdir guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=8c26d9c5-1700-0000-3f71-ed4d0e0c0000 pid=3086 execve guuid=2d7740c6-1700-0000-3f71-ed4d0f0c0000 pid=3087 /usr/bin/mkdir guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=2d7740c6-1700-0000-3f71-ed4d0f0c0000 pid=3087 execve guuid=4d93a3c6-1700-0000-3f71-ed4d100c0000 pid=3088 /usr/bin/cp guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=4d93a3c6-1700-0000-3f71-ed4d100c0000 pid=3088 execve guuid=36920ec7-1700-0000-3f71-ed4d110c0000 pid=3089 /usr/bin/cp guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=36920ec7-1700-0000-3f71-ed4d110c0000 pid=3089 execve guuid=e0d1b4c7-1700-0000-3f71-ed4d150c0000 pid=3093 /usr/bin/cp guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=e0d1b4c7-1700-0000-3f71-ed4d150c0000 pid=3093 execve guuid=bab814c8-1700-0000-3f71-ed4d170c0000 pid=3095 /usr/bin/cp guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=bab814c8-1700-0000-3f71-ed4d170c0000 pid=3095 execve guuid=452b77c8-1700-0000-3f71-ed4d1a0c0000 pid=3098 /usr/bin/cp guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=452b77c8-1700-0000-3f71-ed4d1a0c0000 pid=3098 execve guuid=5934cac8-1700-0000-3f71-ed4d1c0c0000 pid=3100 /usr/bin/cp guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=5934cac8-1700-0000-3f71-ed4d1c0c0000 pid=3100 execve guuid=c6c82cc9-1700-0000-3f71-ed4d1e0c0000 pid=3102 /usr/bin/cp guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=c6c82cc9-1700-0000-3f71-ed4d1e0c0000 pid=3102 execve guuid=291882c9-1700-0000-3f71-ed4d200c0000 pid=3104 /usr/bin/cp guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=291882c9-1700-0000-3f71-ed4d200c0000 pid=3104 execve guuid=0e33dbc9-1700-0000-3f71-ed4d220c0000 pid=3106 /usr/bin/cp guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=0e33dbc9-1700-0000-3f71-ed4d220c0000 pid=3106 execve guuid=c4e54cca-1700-0000-3f71-ed4d240c0000 pid=3108 /usr/bin/cp guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=c4e54cca-1700-0000-3f71-ed4d240c0000 pid=3108 execve guuid=f29fd4ca-1700-0000-3f71-ed4d270c0000 pid=3111 /usr/bin/cp guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=f29fd4ca-1700-0000-3f71-ed4d270c0000 pid=3111 execve guuid=9c0885cb-1700-0000-3f71-ed4d280c0000 pid=3112 /usr/bin/cp guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=9c0885cb-1700-0000-3f71-ed4d280c0000 pid=3112 execve guuid=b6a920cc-1700-0000-3f71-ed4d2a0c0000 pid=3114 /usr/bin/cp guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=b6a920cc-1700-0000-3f71-ed4d2a0c0000 pid=3114 execve guuid=85f399cc-1700-0000-3f71-ed4d2d0c0000 pid=3117 /usr/bin/cp guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=85f399cc-1700-0000-3f71-ed4d2d0c0000 pid=3117 execve guuid=c78e12cd-1700-0000-3f71-ed4d300c0000 pid=3120 /usr/bin/cp guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=c78e12cd-1700-0000-3f71-ed4d300c0000 pid=3120 execve guuid=51916dcd-1700-0000-3f71-ed4d320c0000 pid=3122 /usr/bin/touch guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=51916dcd-1700-0000-3f71-ed4d320c0000 pid=3122 execve guuid=7600d8cd-1700-0000-3f71-ed4d340c0000 pid=3124 /usr/bin/bash guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=7600d8cd-1700-0000-3f71-ed4d340c0000 pid=3124 clone guuid=d968e1cd-1700-0000-3f71-ed4d360c0000 pid=3126 /usr/bin/bash guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=d968e1cd-1700-0000-3f71-ed4d360c0000 pid=3126 clone guuid=f0a6fecd-1700-0000-3f71-ed4d370c0000 pid=3127 /usr/bin/bash guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=f0a6fecd-1700-0000-3f71-ed4d370c0000 pid=3127 clone guuid=4c1605ce-1700-0000-3f71-ed4d380c0000 pid=3128 /usr/bin/base64 write-file guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=4c1605ce-1700-0000-3f71-ed4d380c0000 pid=3128 execve guuid=145381ce-1700-0000-3f71-ed4d3b0c0000 pid=3131 /usr/bin/bash guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=145381ce-1700-0000-3f71-ed4d3b0c0000 pid=3131 execve guuid=0fa0ebd3-1700-0000-3f71-ed4d590c0000 pid=3161 /usr/bin/rm delete-file guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=0fa0ebd3-1700-0000-3f71-ed4d590c0000 pid=3161 execve guuid=25a930d4-1700-0000-3f71-ed4d5c0c0000 pid=3164 /usr/bin/bash guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=25a930d4-1700-0000-3f71-ed4d5c0c0000 pid=3164 clone guuid=75dd37d4-1700-0000-3f71-ed4d5d0c0000 pid=3165 /usr/bin/bash guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=75dd37d4-1700-0000-3f71-ed4d5d0c0000 pid=3165 clone guuid=4a59b5d5-1700-0000-3f71-ed4d630c0000 pid=3171 /usr/bin/bash guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=4a59b5d5-1700-0000-3f71-ed4d630c0000 pid=3171 execve guuid=48bf0dd6-1700-0000-3f71-ed4d660c0000 pid=3174 /usr/bin/rm guuid=1acd77c3-1700-0000-3f71-ed4dff0b0000 pid=3071->guuid=48bf0dd6-1700-0000-3f71-ed4d660c0000 pid=3174 execve guuid=a38ed5ce-1700-0000-3f71-ed4d3d0c0000 pid=3133 /usr/bin/bash guuid=145381ce-1700-0000-3f71-ed4d3b0c0000 pid=3131->guuid=a38ed5ce-1700-0000-3f71-ed4d3d0c0000 pid=3133 clone guuid=e300dcce-1700-0000-3f71-ed4d3e0c0000 pid=3134 /usr/bin/bash guuid=145381ce-1700-0000-3f71-ed4d3b0c0000 pid=3131->guuid=e300dcce-1700-0000-3f71-ed4d3e0c0000 pid=3134 clone guuid=d5d6face-1700-0000-3f71-ed4d3f0c0000 pid=3135 /usr/bin/ls guuid=145381ce-1700-0000-3f71-ed4d3b0c0000 pid=3131->guuid=d5d6face-1700-0000-3f71-ed4d3f0c0000 pid=3135 execve guuid=1d877ecf-1700-0000-3f71-ed4d410c0000 pid=3137 /usr/bin/cat guuid=145381ce-1700-0000-3f71-ed4d3b0c0000 pid=3131->guuid=1d877ecf-1700-0000-3f71-ed4d410c0000 pid=3137 execve guuid=d90ecacf-1700-0000-3f71-ed4d430c0000 pid=3139 /usr/bin/ls guuid=145381ce-1700-0000-3f71-ed4d3b0c0000 pid=3131->guuid=d90ecacf-1700-0000-3f71-ed4d430c0000 pid=3139 execve guuid=73e149d0-1700-0000-3f71-ed4d440c0000 pid=3140 /usr/bin/mkdir guuid=145381ce-1700-0000-3f71-ed4d3b0c0000 pid=3131->guuid=73e149d0-1700-0000-3f71-ed4d440c0000 pid=3140 execve guuid=5e48f2d0-1700-0000-3f71-ed4d450c0000 pid=3141 /usr/bin/mv guuid=145381ce-1700-0000-3f71-ed4d3b0c0000 pid=3131->guuid=5e48f2d0-1700-0000-3f71-ed4d450c0000 pid=3141 execve guuid=dcf769d1-1700-0000-3f71-ed4d470c0000 pid=3143 /usr/bin/bash guuid=145381ce-1700-0000-3f71-ed4d3b0c0000 pid=3131->guuid=dcf769d1-1700-0000-3f71-ed4d470c0000 pid=3143 clone guuid=27d86fd1-1700-0000-3f71-ed4d480c0000 pid=3144 /usr/bin/base64 write-file guuid=145381ce-1700-0000-3f71-ed4d3b0c0000 pid=3131->guuid=27d86fd1-1700-0000-3f71-ed4d480c0000 pid=3144 execve guuid=9b08bcd1-1700-0000-3f71-ed4d4a0c0000 pid=3146 /usr/bin/rm delete-file guuid=145381ce-1700-0000-3f71-ed4d3b0c0000 pid=3131->guuid=9b08bcd1-1700-0000-3f71-ed4d4a0c0000 pid=3146 execve guuid=cb0405d2-1700-0000-3f71-ed4d4c0c0000 pid=3148 /usr/bin/ls guuid=145381ce-1700-0000-3f71-ed4d3b0c0000 pid=3131->guuid=cb0405d2-1700-0000-3f71-ed4d4c0c0000 pid=3148 execve guuid=512274d2-1700-0000-3f71-ed4d4f0c0000 pid=3151 /usr/bin/bash guuid=145381ce-1700-0000-3f71-ed4d3b0c0000 pid=3131->guuid=512274d2-1700-0000-3f71-ed4d4f0c0000 pid=3151 clone guuid=f8c27bd2-1700-0000-3f71-ed4d500c0000 pid=3152 /usr/bin/base64 write-file guuid=145381ce-1700-0000-3f71-ed4d3b0c0000 pid=3131->guuid=f8c27bd2-1700-0000-3f71-ed4d500c0000 pid=3152 execve guuid=98d2d0d2-1700-0000-3f71-ed4d520c0000 pid=3154 /usr/bin/ls guuid=145381ce-1700-0000-3f71-ed4d3b0c0000 pid=3131->guuid=98d2d0d2-1700-0000-3f71-ed4d520c0000 pid=3154 execve guuid=fd4d3ed3-1700-0000-3f71-ed4d550c0000 pid=3157 /usr/bin/cat guuid=145381ce-1700-0000-3f71-ed4d3b0c0000 pid=3131->guuid=fd4d3ed3-1700-0000-3f71-ed4d550c0000 pid=3157 execve guuid=ca7a7dd3-1700-0000-3f71-ed4d570c0000 pid=3159 /usr/bin/ls guuid=145381ce-1700-0000-3f71-ed4d3b0c0000 pid=3131->guuid=ca7a7dd3-1700-0000-3f71-ed4d570c0000 pid=3159 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-10 21:38:19 UTC
File Type:
Text (Shell)
AV detection:
17 of 38 (44.74%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 92a254eff4ae5a3072343f65148d4b864ff60802aca0bee44a59ba0cce3af854

(this sample)

  
Delivery method
Distributed via web download

Comments