MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9aab893007c7dc97f98539b4a468bd978a6db7dff17a28fa9173e42252e8be55. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 9aab893007c7dc97f98539b4a468bd978a6db7dff17a28fa9173e42252e8be55
SHA3-384 hash: 02b546411a9763051d2ee5258c34c027abebb1857a1ccaa9af67e1c4ebe255f96c4b8848e0fe0d76c13f3be83e2cfe04
SHA1 hash: 3812c167aa0e6763eb8570a5a7677b9daddc7a86
MD5 hash: 6441aaa80cd62852eeb419c32ceb2fac
humanhash: alaska-blossom-summer-lake
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-14 20:16:23 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:ws0M3vgRjGlsaq7xzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:wWmjfNzsP4cbddr7zsP4cbddrk
TLSH T138925CA916496C79BBC0DE7D9F3C7F0CADE4C1C02218A39CBA4F39714A2469DDA0635D
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=cae752ee-1600-0000-a0a5-1718c50e0000 pid=3781 /usr/bin/sudo guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791 /tmp/sample.bin guuid=cae752ee-1600-0000-a0a5-1718c50e0000 pid=3781->guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791 execve guuid=928c73f0-1600-0000-a0a5-1718d20e0000 pid=3794 /usr/bin/bash guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=928c73f0-1600-0000-a0a5-1718d20e0000 pid=3794 clone guuid=43e879f0-1600-0000-a0a5-1718d30e0000 pid=3795 /usr/bin/bash guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=43e879f0-1600-0000-a0a5-1718d30e0000 pid=3795 clone guuid=2a0e96f0-1600-0000-a0a5-1718d40e0000 pid=3796 /usr/bin/mkdir guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=2a0e96f0-1600-0000-a0a5-1718d40e0000 pid=3796 execve guuid=959be4f0-1600-0000-a0a5-1718d70e0000 pid=3799 /usr/bin/mkdir guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=959be4f0-1600-0000-a0a5-1718d70e0000 pid=3799 execve guuid=4a5f51f1-1600-0000-a0a5-1718db0e0000 pid=3803 /usr/bin/mkdir guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=4a5f51f1-1600-0000-a0a5-1718db0e0000 pid=3803 execve guuid=af169af1-1600-0000-a0a5-1718de0e0000 pid=3806 /usr/bin/mkdir guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=af169af1-1600-0000-a0a5-1718de0e0000 pid=3806 execve guuid=a03edcf1-1600-0000-a0a5-1718e10e0000 pid=3809 /usr/bin/mkdir guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=a03edcf1-1600-0000-a0a5-1718e10e0000 pid=3809 execve guuid=53993cf2-1600-0000-a0a5-1718e50e0000 pid=3813 /usr/bin/mkdir guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=53993cf2-1600-0000-a0a5-1718e50e0000 pid=3813 execve guuid=b6a19df2-1600-0000-a0a5-1718e70e0000 pid=3815 /usr/bin/mkdir guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=b6a19df2-1600-0000-a0a5-1718e70e0000 pid=3815 execve guuid=ac3208f3-1600-0000-a0a5-1718ee0e0000 pid=3822 /usr/bin/cp guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=ac3208f3-1600-0000-a0a5-1718ee0e0000 pid=3822 execve guuid=80f89cf3-1600-0000-a0a5-1718f00e0000 pid=3824 /usr/bin/cp guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=80f89cf3-1600-0000-a0a5-1718f00e0000 pid=3824 execve guuid=f79f53f4-1600-0000-a0a5-1718f10e0000 pid=3825 /usr/bin/cp guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=f79f53f4-1600-0000-a0a5-1718f10e0000 pid=3825 execve guuid=fb7ddff4-1600-0000-a0a5-1718f20e0000 pid=3826 /usr/bin/cp guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=fb7ddff4-1600-0000-a0a5-1718f20e0000 pid=3826 execve guuid=c27a81f5-1600-0000-a0a5-1718f30e0000 pid=3827 /usr/bin/cp guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=c27a81f5-1600-0000-a0a5-1718f30e0000 pid=3827 execve guuid=1fe50ef6-1600-0000-a0a5-1718f40e0000 pid=3828 /usr/bin/cp guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=1fe50ef6-1600-0000-a0a5-1718f40e0000 pid=3828 execve guuid=73ad79f6-1600-0000-a0a5-1718f60e0000 pid=3830 /usr/bin/cp guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=73ad79f6-1600-0000-a0a5-1718f60e0000 pid=3830 execve guuid=8107d8f6-1600-0000-a0a5-1718f80e0000 pid=3832 /usr/bin/cp guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=8107d8f6-1600-0000-a0a5-1718f80e0000 pid=3832 execve guuid=e41243f7-1600-0000-a0a5-1718fa0e0000 pid=3834 /usr/bin/cp guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=e41243f7-1600-0000-a0a5-1718fa0e0000 pid=3834 execve guuid=98979ff7-1600-0000-a0a5-1718fd0e0000 pid=3837 /usr/bin/cp guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=98979ff7-1600-0000-a0a5-1718fd0e0000 pid=3837 execve guuid=0115f3f7-1600-0000-a0a5-1718ff0e0000 pid=3839 /usr/bin/cp guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=0115f3f7-1600-0000-a0a5-1718ff0e0000 pid=3839 execve guuid=2a8542f8-1600-0000-a0a5-1718010f0000 pid=3841 /usr/bin/cp guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=2a8542f8-1600-0000-a0a5-1718010f0000 pid=3841 execve guuid=e66f91f8-1600-0000-a0a5-1718040f0000 pid=3844 /usr/bin/cp guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=e66f91f8-1600-0000-a0a5-1718040f0000 pid=3844 execve guuid=19e0e1f8-1600-0000-a0a5-1718080f0000 pid=3848 /usr/bin/cp guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=19e0e1f8-1600-0000-a0a5-1718080f0000 pid=3848 execve guuid=e56a4cf9-1600-0000-a0a5-1718090f0000 pid=3849 /usr/bin/cp guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=e56a4cf9-1600-0000-a0a5-1718090f0000 pid=3849 execve guuid=dd7dccf9-1600-0000-a0a5-17180c0f0000 pid=3852 /usr/bin/touch guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=dd7dccf9-1600-0000-a0a5-17180c0f0000 pid=3852 execve guuid=2fe81afa-1600-0000-a0a5-17180f0f0000 pid=3855 /usr/bin/bash guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=2fe81afa-1600-0000-a0a5-17180f0f0000 pid=3855 clone guuid=eb0123fa-1600-0000-a0a5-1718110f0000 pid=3857 /usr/bin/bash guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=eb0123fa-1600-0000-a0a5-1718110f0000 pid=3857 clone guuid=34a651fa-1600-0000-a0a5-1718120f0000 pid=3858 /usr/bin/bash guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=34a651fa-1600-0000-a0a5-1718120f0000 pid=3858 clone guuid=68695efa-1600-0000-a0a5-1718140f0000 pid=3860 /usr/bin/base64 write-file guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=68695efa-1600-0000-a0a5-1718140f0000 pid=3860 execve guuid=648d0cfb-1600-0000-a0a5-1718180f0000 pid=3864 /usr/bin/bash guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=648d0cfb-1600-0000-a0a5-1718180f0000 pid=3864 execve guuid=f1b22801-1700-0000-a0a5-17183f0f0000 pid=3903 /usr/bin/rm delete-file guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=f1b22801-1700-0000-a0a5-17183f0f0000 pid=3903 execve guuid=875b7801-1700-0000-a0a5-1718410f0000 pid=3905 /usr/bin/bash guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=875b7801-1700-0000-a0a5-1718410f0000 pid=3905 clone guuid=b3e27f01-1700-0000-a0a5-1718420f0000 pid=3906 /usr/bin/bash guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=b3e27f01-1700-0000-a0a5-1718420f0000 pid=3906 clone guuid=b820ba01-1700-0000-a0a5-1718440f0000 pid=3908 /usr/bin/bash guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=b820ba01-1700-0000-a0a5-1718440f0000 pid=3908 execve guuid=379d2b02-1700-0000-a0a5-1718460f0000 pid=3910 /usr/bin/rm guuid=b56c23f0-1600-0000-a0a5-1718cf0e0000 pid=3791->guuid=379d2b02-1700-0000-a0a5-1718460f0000 pid=3910 execve guuid=c1d86bfb-1600-0000-a0a5-17181c0f0000 pid=3868 /usr/bin/bash guuid=648d0cfb-1600-0000-a0a5-1718180f0000 pid=3864->guuid=c1d86bfb-1600-0000-a0a5-17181c0f0000 pid=3868 clone guuid=575478fb-1600-0000-a0a5-17181d0f0000 pid=3869 /usr/bin/bash guuid=648d0cfb-1600-0000-a0a5-1718180f0000 pid=3864->guuid=575478fb-1600-0000-a0a5-17181d0f0000 pid=3869 clone guuid=8e47cffb-1600-0000-a0a5-17181e0f0000 pid=3870 /usr/bin/ls guuid=648d0cfb-1600-0000-a0a5-1718180f0000 pid=3864->guuid=8e47cffb-1600-0000-a0a5-17181e0f0000 pid=3870 execve guuid=1fec34fc-1600-0000-a0a5-1718210f0000 pid=3873 /usr/bin/cat guuid=648d0cfb-1600-0000-a0a5-1718180f0000 pid=3864->guuid=1fec34fc-1600-0000-a0a5-1718210f0000 pid=3873 execve guuid=920775fc-1600-0000-a0a5-1718230f0000 pid=3875 /usr/bin/ls guuid=648d0cfb-1600-0000-a0a5-1718180f0000 pid=3864->guuid=920775fc-1600-0000-a0a5-1718230f0000 pid=3875 execve guuid=c63ed6fc-1600-0000-a0a5-1718250f0000 pid=3877 /usr/bin/mkdir guuid=648d0cfb-1600-0000-a0a5-1718180f0000 pid=3864->guuid=c63ed6fc-1600-0000-a0a5-1718250f0000 pid=3877 execve guuid=f39727fd-1600-0000-a0a5-1718280f0000 pid=3880 /usr/bin/mv guuid=648d0cfb-1600-0000-a0a5-1718180f0000 pid=3864->guuid=f39727fd-1600-0000-a0a5-1718280f0000 pid=3880 execve guuid=82e0b1fd-1600-0000-a0a5-17182a0f0000 pid=3882 /usr/bin/bash guuid=648d0cfb-1600-0000-a0a5-1718180f0000 pid=3864->guuid=82e0b1fd-1600-0000-a0a5-17182a0f0000 pid=3882 clone guuid=86c3b9fd-1600-0000-a0a5-17182b0f0000 pid=3883 /usr/bin/base64 write-file guuid=648d0cfb-1600-0000-a0a5-1718180f0000 pid=3864->guuid=86c3b9fd-1600-0000-a0a5-17182b0f0000 pid=3883 execve guuid=1af529fe-1600-0000-a0a5-17182d0f0000 pid=3885 /usr/bin/rm delete-file guuid=648d0cfb-1600-0000-a0a5-1718180f0000 pid=3864->guuid=1af529fe-1600-0000-a0a5-17182d0f0000 pid=3885 execve guuid=d6ff83fe-1600-0000-a0a5-1718310f0000 pid=3889 /usr/bin/ls guuid=648d0cfb-1600-0000-a0a5-1718180f0000 pid=3864->guuid=d6ff83fe-1600-0000-a0a5-1718310f0000 pid=3889 execve guuid=94cd1dff-1600-0000-a0a5-1718320f0000 pid=3890 /usr/bin/bash guuid=648d0cfb-1600-0000-a0a5-1718180f0000 pid=3864->guuid=94cd1dff-1600-0000-a0a5-1718320f0000 pid=3890 clone guuid=3d342aff-1600-0000-a0a5-1718330f0000 pid=3891 /usr/bin/base64 write-file guuid=648d0cfb-1600-0000-a0a5-1718180f0000 pid=3864->guuid=3d342aff-1600-0000-a0a5-1718330f0000 pid=3891 execve guuid=da5899ff-1600-0000-a0a5-1718370f0000 pid=3895 /usr/bin/ls guuid=648d0cfb-1600-0000-a0a5-1718180f0000 pid=3864->guuid=da5899ff-1600-0000-a0a5-1718370f0000 pid=3895 execve guuid=a53e2e00-1700-0000-a0a5-17183a0f0000 pid=3898 /usr/bin/cat guuid=648d0cfb-1600-0000-a0a5-1718180f0000 pid=3864->guuid=a53e2e00-1700-0000-a0a5-17183a0f0000 pid=3898 execve guuid=ba018b00-1700-0000-a0a5-17183c0f0000 pid=3900 /usr/bin/ls guuid=648d0cfb-1600-0000-a0a5-1718180f0000 pid=3864->guuid=ba018b00-1700-0000-a0a5-17183c0f0000 pid=3900 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-14 20:17:18 UTC
File Type:
Text (Shell)
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 9aab893007c7dc97f98539b4a468bd978a6db7dff17a28fa9173e42252e8be55

(this sample)

  
Delivery method
Distributed via web download

Comments