MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a948603c6a98efe282053a11422765c2771444be9aa2c90d6c5447744aff0985. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: a948603c6a98efe282053a11422765c2771444be9aa2c90d6c5447744aff0985
SHA3-384 hash: 8b5d706cc66fd7f57fe4b101c0710b105e3e50b627f26479bdcf558f57d129d30a6679ef877fd597d61c58ee083e2b49
SHA1 hash: 9b57e870b396d9440fe8979ca57166c1da3d8a35
MD5 hash: dc99867f12cb56f2213f39c55416545a
humanhash: fanta-jupiter-ink-delta
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-14 21:44:38 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:RuFcuQpWx+BL0SWL0gKzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:oF8i+BL0SI0lzsP4cbddr7zsP4cbddrk
TLSH T163925DB512896C79FBD0CE399F3C7F4DADE8C2C42124A3ACBA4F39215A1166DC705359
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=480fbc91-1600-0000-feec-e565520d0000 pid=3410 /usr/bin/sudo guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418 /tmp/sample.bin guuid=480fbc91-1600-0000-feec-e565520d0000 pid=3410->guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418 execve guuid=e0f41694-1600-0000-feec-e5655b0d0000 pid=3419 /usr/bin/bash guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=e0f41694-1600-0000-feec-e5655b0d0000 pid=3419 clone guuid=58322294-1600-0000-feec-e5655d0d0000 pid=3421 /usr/bin/bash guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=58322294-1600-0000-feec-e5655d0d0000 pid=3421 clone guuid=5f9a4c94-1600-0000-feec-e5655e0d0000 pid=3422 /usr/bin/mkdir guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=5f9a4c94-1600-0000-feec-e5655e0d0000 pid=3422 execve guuid=520fd094-1600-0000-feec-e565610d0000 pid=3425 /usr/bin/mkdir guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=520fd094-1600-0000-feec-e565610d0000 pid=3425 execve guuid=e4152395-1600-0000-feec-e565630d0000 pid=3427 /usr/bin/mkdir guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=e4152395-1600-0000-feec-e565630d0000 pid=3427 execve guuid=716e7695-1600-0000-feec-e565650d0000 pid=3429 /usr/bin/mkdir guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=716e7695-1600-0000-feec-e565650d0000 pid=3429 execve guuid=9bbdc895-1600-0000-feec-e565670d0000 pid=3431 /usr/bin/mkdir guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=9bbdc895-1600-0000-feec-e565670d0000 pid=3431 execve guuid=c1cb2a96-1600-0000-feec-e565690d0000 pid=3433 /usr/bin/mkdir guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=c1cb2a96-1600-0000-feec-e565690d0000 pid=3433 execve guuid=a4bb7b96-1600-0000-feec-e5656b0d0000 pid=3435 /usr/bin/mkdir guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=a4bb7b96-1600-0000-feec-e5656b0d0000 pid=3435 execve guuid=15a5cc96-1600-0000-feec-e5656d0d0000 pid=3437 /usr/bin/cp guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=15a5cc96-1600-0000-feec-e5656d0d0000 pid=3437 execve guuid=3fea3497-1600-0000-feec-e565700d0000 pid=3440 /usr/bin/cp guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=3fea3497-1600-0000-feec-e565700d0000 pid=3440 execve guuid=277df197-1600-0000-feec-e565740d0000 pid=3444 /usr/bin/cp guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=277df197-1600-0000-feec-e565740d0000 pid=3444 execve guuid=e6a75b98-1600-0000-feec-e565770d0000 pid=3447 /usr/bin/cp guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=e6a75b98-1600-0000-feec-e565770d0000 pid=3447 execve guuid=631fc998-1600-0000-feec-e565790d0000 pid=3449 /usr/bin/cp guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=631fc998-1600-0000-feec-e565790d0000 pid=3449 execve guuid=0f4d2a99-1600-0000-feec-e5657c0d0000 pid=3452 /usr/bin/cp guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=0f4d2a99-1600-0000-feec-e5657c0d0000 pid=3452 execve guuid=ba1b8099-1600-0000-feec-e5657e0d0000 pid=3454 /usr/bin/cp guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=ba1b8099-1600-0000-feec-e5657e0d0000 pid=3454 execve guuid=34b8da99-1600-0000-feec-e565800d0000 pid=3456 /usr/bin/cp guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=34b8da99-1600-0000-feec-e565800d0000 pid=3456 execve guuid=b7c5359a-1600-0000-feec-e565820d0000 pid=3458 /usr/bin/cp guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=b7c5359a-1600-0000-feec-e565820d0000 pid=3458 execve guuid=be3d9d9a-1600-0000-feec-e565850d0000 pid=3461 /usr/bin/cp guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=be3d9d9a-1600-0000-feec-e565850d0000 pid=3461 execve guuid=f75d029b-1600-0000-feec-e565870d0000 pid=3463 /usr/bin/cp guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=f75d029b-1600-0000-feec-e565870d0000 pid=3463 execve guuid=25886d9b-1600-0000-feec-e5658a0d0000 pid=3466 /usr/bin/cp guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=25886d9b-1600-0000-feec-e5658a0d0000 pid=3466 execve guuid=6c8b0b9c-1600-0000-feec-e5658c0d0000 pid=3468 /usr/bin/cp guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=6c8b0b9c-1600-0000-feec-e5658c0d0000 pid=3468 execve guuid=aa27699c-1600-0000-feec-e5658f0d0000 pid=3471 /usr/bin/cp guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=aa27699c-1600-0000-feec-e5658f0d0000 pid=3471 execve guuid=eb30c49c-1600-0000-feec-e565910d0000 pid=3473 /usr/bin/cp guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=eb30c49c-1600-0000-feec-e565910d0000 pid=3473 execve guuid=c117339d-1600-0000-feec-e565940d0000 pid=3476 /usr/bin/touch guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=c117339d-1600-0000-feec-e565940d0000 pid=3476 execve guuid=1db67d9d-1600-0000-feec-e565960d0000 pid=3478 /usr/bin/bash guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=1db67d9d-1600-0000-feec-e565960d0000 pid=3478 clone guuid=2604889d-1600-0000-feec-e565970d0000 pid=3479 /usr/bin/bash guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=2604889d-1600-0000-feec-e565970d0000 pid=3479 clone guuid=d344ae9d-1600-0000-feec-e565990d0000 pid=3481 /usr/bin/bash guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=d344ae9d-1600-0000-feec-e565990d0000 pid=3481 clone guuid=ec01b49d-1600-0000-feec-e5659a0d0000 pid=3482 /usr/bin/base64 write-file guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=ec01b49d-1600-0000-feec-e5659a0d0000 pid=3482 execve guuid=a7af809e-1600-0000-feec-e5659d0d0000 pid=3485 /usr/bin/bash guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=a7af809e-1600-0000-feec-e5659d0d0000 pid=3485 execve guuid=479c57a3-1600-0000-feec-e565bf0d0000 pid=3519 /usr/bin/rm delete-file guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=479c57a3-1600-0000-feec-e565bf0d0000 pid=3519 execve guuid=9a7b97a3-1600-0000-feec-e565c10d0000 pid=3521 /usr/bin/bash guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=9a7b97a3-1600-0000-feec-e565c10d0000 pid=3521 clone guuid=6aa69ca3-1600-0000-feec-e565c20d0000 pid=3522 /usr/bin/bash guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=6aa69ca3-1600-0000-feec-e565c20d0000 pid=3522 clone guuid=8fdabda3-1600-0000-feec-e565c70d0000 pid=3527 /usr/bin/bash guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=8fdabda3-1600-0000-feec-e565c70d0000 pid=3527 execve guuid=26560ea4-1600-0000-feec-e565c80d0000 pid=3528 /usr/bin/rm guuid=5d07b593-1600-0000-feec-e5655a0d0000 pid=3418->guuid=26560ea4-1600-0000-feec-e565c80d0000 pid=3528 execve guuid=8ca0f29e-1600-0000-feec-e565a00d0000 pid=3488 /usr/bin/bash guuid=a7af809e-1600-0000-feec-e5659d0d0000 pid=3485->guuid=8ca0f29e-1600-0000-feec-e565a00d0000 pid=3488 clone guuid=3c71fe9e-1600-0000-feec-e565a10d0000 pid=3489 /usr/bin/bash guuid=a7af809e-1600-0000-feec-e5659d0d0000 pid=3485->guuid=3c71fe9e-1600-0000-feec-e565a10d0000 pid=3489 clone guuid=1b22199f-1600-0000-feec-e565a20d0000 pid=3490 /usr/bin/ls guuid=a7af809e-1600-0000-feec-e5659d0d0000 pid=3485->guuid=1b22199f-1600-0000-feec-e565a20d0000 pid=3490 execve guuid=bce8969f-1600-0000-feec-e565a40d0000 pid=3492 /usr/bin/cat guuid=a7af809e-1600-0000-feec-e5659d0d0000 pid=3485->guuid=bce8969f-1600-0000-feec-e565a40d0000 pid=3492 execve guuid=985cd99f-1600-0000-feec-e565a60d0000 pid=3494 /usr/bin/ls guuid=a7af809e-1600-0000-feec-e5659d0d0000 pid=3485->guuid=985cd99f-1600-0000-feec-e565a60d0000 pid=3494 execve guuid=f9853ba0-1600-0000-feec-e565a90d0000 pid=3497 /usr/bin/mkdir guuid=a7af809e-1600-0000-feec-e5659d0d0000 pid=3485->guuid=f9853ba0-1600-0000-feec-e565a90d0000 pid=3497 execve guuid=2ee58da0-1600-0000-feec-e565ab0d0000 pid=3499 /usr/bin/mv guuid=a7af809e-1600-0000-feec-e5659d0d0000 pid=3485->guuid=2ee58da0-1600-0000-feec-e565ab0d0000 pid=3499 execve guuid=42bceda0-1600-0000-feec-e565ae0d0000 pid=3502 /usr/bin/bash guuid=a7af809e-1600-0000-feec-e5659d0d0000 pid=3485->guuid=42bceda0-1600-0000-feec-e565ae0d0000 pid=3502 clone guuid=943cfea0-1600-0000-feec-e565af0d0000 pid=3503 /usr/bin/base64 write-file guuid=a7af809e-1600-0000-feec-e5659d0d0000 pid=3485->guuid=943cfea0-1600-0000-feec-e565af0d0000 pid=3503 execve guuid=feda4aa1-1600-0000-feec-e565b10d0000 pid=3505 /usr/bin/rm delete-file guuid=a7af809e-1600-0000-feec-e5659d0d0000 pid=3485->guuid=feda4aa1-1600-0000-feec-e565b10d0000 pid=3505 execve guuid=413697a1-1600-0000-feec-e565b30d0000 pid=3507 /usr/bin/ls guuid=a7af809e-1600-0000-feec-e5659d0d0000 pid=3485->guuid=413697a1-1600-0000-feec-e565b30d0000 pid=3507 execve guuid=51c3f8a1-1600-0000-feec-e565b50d0000 pid=3509 /usr/bin/bash guuid=a7af809e-1600-0000-feec-e5659d0d0000 pid=3485->guuid=51c3f8a1-1600-0000-feec-e565b50d0000 pid=3509 clone guuid=8daaffa1-1600-0000-feec-e565b60d0000 pid=3510 /usr/bin/base64 write-file guuid=a7af809e-1600-0000-feec-e5659d0d0000 pid=3485->guuid=8daaffa1-1600-0000-feec-e565b60d0000 pid=3510 execve guuid=2d5147a2-1600-0000-feec-e565b80d0000 pid=3512 /usr/bin/ls guuid=a7af809e-1600-0000-feec-e5659d0d0000 pid=3485->guuid=2d5147a2-1600-0000-feec-e565b80d0000 pid=3512 execve guuid=219ca7a2-1600-0000-feec-e565bb0d0000 pid=3515 /usr/bin/cat guuid=a7af809e-1600-0000-feec-e5659d0d0000 pid=3485->guuid=219ca7a2-1600-0000-feec-e565bb0d0000 pid=3515 execve guuid=a7d8e8a2-1600-0000-feec-e565bd0d0000 pid=3517 /usr/bin/ls guuid=a7af809e-1600-0000-feec-e5659d0d0000 pid=3485->guuid=a7d8e8a2-1600-0000-feec-e565bd0d0000 pid=3517 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-14 21:45:34 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh a948603c6a98efe282053a11422765c2771444be9aa2c90d6c5447744aff0985

(this sample)

  
Delivery method
Distributed via web download

Comments