MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 afb7b489250ca4a066d5cfc906f7bbbfbd3075fe77db9f773dab10e6c6d4a1ba. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: afb7b489250ca4a066d5cfc906f7bbbfbd3075fe77db9f773dab10e6c6d4a1ba
SHA3-384 hash: fc06fbe5662dc076a390cdab9c65ea619e87b20eb87282847ba01da66c493dd2d356a4fd3e1829951b7e1851dd231137
SHA1 hash: 7b095816df26502f658bf45a8398acae6188c58c
MD5 hash: c5f2d2b93d890b3ab9aa96f5aa168c26
humanhash: arizona-equal-fanta-jersey
File name:k.php
Download: download sample
File size:19'491 bytes
First seen:2026-03-03 14:44:58 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:n0ncuxOLnVYMSFnzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:nfuQL+FnzsP4cbddr7zsP4cbddrk
TLSH T14E924CB506497CB9BBC0CE799F3C7F0CAEE582C42129E39DBA1F39705A2065DC609359
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=38cf99f4-1600-0000-ae2a-2c329a0c0000 pid=3226 /usr/bin/sudo guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227 /tmp/sample.bin guuid=38cf99f4-1600-0000-ae2a-2c329a0c0000 pid=3226->guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227 execve guuid=03fff2f8-1600-0000-ae2a-2c329c0c0000 pid=3228 /usr/bin/bash guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=03fff2f8-1600-0000-ae2a-2c329c0c0000 pid=3228 clone guuid=b92f17f9-1600-0000-ae2a-2c329d0c0000 pid=3229 /usr/bin/bash guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=b92f17f9-1600-0000-ae2a-2c329d0c0000 pid=3229 clone guuid=dc208af9-1600-0000-ae2a-2c329e0c0000 pid=3230 /usr/bin/mkdir guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=dc208af9-1600-0000-ae2a-2c329e0c0000 pid=3230 execve guuid=2f9114fa-1600-0000-ae2a-2c329f0c0000 pid=3231 /usr/bin/mkdir guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=2f9114fa-1600-0000-ae2a-2c329f0c0000 pid=3231 execve guuid=89d87dfa-1600-0000-ae2a-2c32a00c0000 pid=3232 /usr/bin/mkdir guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=89d87dfa-1600-0000-ae2a-2c32a00c0000 pid=3232 execve guuid=dc9bf6fa-1600-0000-ae2a-2c32a10c0000 pid=3233 /usr/bin/mkdir guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=dc9bf6fa-1600-0000-ae2a-2c32a10c0000 pid=3233 execve guuid=799c6cfb-1600-0000-ae2a-2c32a20c0000 pid=3234 /usr/bin/mkdir guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=799c6cfb-1600-0000-ae2a-2c32a20c0000 pid=3234 execve guuid=a923dffb-1600-0000-ae2a-2c32a30c0000 pid=3235 /usr/bin/mkdir guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=a923dffb-1600-0000-ae2a-2c32a30c0000 pid=3235 execve guuid=dcde65fc-1600-0000-ae2a-2c32a50c0000 pid=3237 /usr/bin/mkdir guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=dcde65fc-1600-0000-ae2a-2c32a50c0000 pid=3237 execve guuid=3e37ccfc-1600-0000-ae2a-2c32a60c0000 pid=3238 /usr/bin/cp guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=3e37ccfc-1600-0000-ae2a-2c32a60c0000 pid=3238 execve guuid=9db841fd-1600-0000-ae2a-2c32a70c0000 pid=3239 /usr/bin/cp guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=9db841fd-1600-0000-ae2a-2c32a70c0000 pid=3239 execve guuid=8eb7fbfd-1600-0000-ae2a-2c32aa0c0000 pid=3242 /usr/bin/cp guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=8eb7fbfd-1600-0000-ae2a-2c32aa0c0000 pid=3242 execve guuid=ae7a6bfe-1600-0000-ae2a-2c32ac0c0000 pid=3244 /usr/bin/cp guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=ae7a6bfe-1600-0000-ae2a-2c32ac0c0000 pid=3244 execve guuid=6174d5fe-1600-0000-ae2a-2c32ad0c0000 pid=3245 /usr/bin/cp guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=6174d5fe-1600-0000-ae2a-2c32ad0c0000 pid=3245 execve guuid=72b742ff-1600-0000-ae2a-2c32af0c0000 pid=3247 /usr/bin/cp guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=72b742ff-1600-0000-ae2a-2c32af0c0000 pid=3247 execve guuid=d598adff-1600-0000-ae2a-2c32b10c0000 pid=3249 /usr/bin/cp guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=d598adff-1600-0000-ae2a-2c32b10c0000 pid=3249 execve guuid=94355800-1700-0000-ae2a-2c32b30c0000 pid=3251 /usr/bin/cp guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=94355800-1700-0000-ae2a-2c32b30c0000 pid=3251 execve guuid=dff5ff00-1700-0000-ae2a-2c32b50c0000 pid=3253 /usr/bin/cp guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=dff5ff00-1700-0000-ae2a-2c32b50c0000 pid=3253 execve guuid=69c97b01-1700-0000-ae2a-2c32b70c0000 pid=3255 /usr/bin/cp guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=69c97b01-1700-0000-ae2a-2c32b70c0000 pid=3255 execve guuid=75b30d02-1700-0000-ae2a-2c32b90c0000 pid=3257 /usr/bin/cp guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=75b30d02-1700-0000-ae2a-2c32b90c0000 pid=3257 execve guuid=5ba8a302-1700-0000-ae2a-2c32bc0c0000 pid=3260 /usr/bin/cp guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=5ba8a302-1700-0000-ae2a-2c32bc0c0000 pid=3260 execve guuid=57e63703-1700-0000-ae2a-2c32bf0c0000 pid=3263 /usr/bin/cp guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=57e63703-1700-0000-ae2a-2c32bf0c0000 pid=3263 execve guuid=7e6fc903-1700-0000-ae2a-2c32c10c0000 pid=3265 /usr/bin/cp guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=7e6fc903-1700-0000-ae2a-2c32c10c0000 pid=3265 execve guuid=57c16c04-1700-0000-ae2a-2c32c20c0000 pid=3266 /usr/bin/cp guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=57c16c04-1700-0000-ae2a-2c32c20c0000 pid=3266 execve guuid=9faf0905-1700-0000-ae2a-2c32c50c0000 pid=3269 /usr/bin/touch guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=9faf0905-1700-0000-ae2a-2c32c50c0000 pid=3269 execve guuid=9ed47f05-1700-0000-ae2a-2c32c70c0000 pid=3271 /usr/bin/bash guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=9ed47f05-1700-0000-ae2a-2c32c70c0000 pid=3271 clone guuid=cbcf8705-1700-0000-ae2a-2c32c90c0000 pid=3273 /usr/bin/bash guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=cbcf8705-1700-0000-ae2a-2c32c90c0000 pid=3273 clone guuid=39abb405-1700-0000-ae2a-2c32ca0c0000 pid=3274 /usr/bin/bash guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=39abb405-1700-0000-ae2a-2c32ca0c0000 pid=3274 clone guuid=19babd05-1700-0000-ae2a-2c32cb0c0000 pid=3275 /usr/bin/base64 write-file guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=19babd05-1700-0000-ae2a-2c32cb0c0000 pid=3275 execve guuid=8baf9606-1700-0000-ae2a-2c32ce0c0000 pid=3278 /usr/bin/bash guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=8baf9606-1700-0000-ae2a-2c32ce0c0000 pid=3278 execve guuid=5b97460e-1700-0000-ae2a-2c32e70c0000 pid=3303 /usr/bin/rm delete-file guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=5b97460e-1700-0000-ae2a-2c32e70c0000 pid=3303 execve guuid=5a5fa70e-1700-0000-ae2a-2c32e90c0000 pid=3305 /usr/bin/bash guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=5a5fa70e-1700-0000-ae2a-2c32e90c0000 pid=3305 clone guuid=1188ad0e-1700-0000-ae2a-2c32ea0c0000 pid=3306 /usr/bin/bash guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=1188ad0e-1700-0000-ae2a-2c32ea0c0000 pid=3306 clone guuid=8c76e80e-1700-0000-ae2a-2c32ec0c0000 pid=3308 /usr/bin/bash guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=8c76e80e-1700-0000-ae2a-2c32ec0c0000 pid=3308 execve guuid=ee645d0f-1700-0000-ae2a-2c32ee0c0000 pid=3310 /usr/bin/rm guuid=ee3aa7f7-1600-0000-ae2a-2c329b0c0000 pid=3227->guuid=ee645d0f-1700-0000-ae2a-2c32ee0c0000 pid=3310 execve guuid=bdbe6407-1700-0000-ae2a-2c32cf0c0000 pid=3279 /usr/bin/bash guuid=8baf9606-1700-0000-ae2a-2c32ce0c0000 pid=3278->guuid=bdbe6407-1700-0000-ae2a-2c32cf0c0000 pid=3279 clone guuid=af229007-1700-0000-ae2a-2c32d00c0000 pid=3280 /usr/bin/bash guuid=8baf9606-1700-0000-ae2a-2c32ce0c0000 pid=3278->guuid=af229007-1700-0000-ae2a-2c32d00c0000 pid=3280 clone guuid=99020508-1700-0000-ae2a-2c32d10c0000 pid=3281 /usr/bin/ls guuid=8baf9606-1700-0000-ae2a-2c32ce0c0000 pid=3278->guuid=99020508-1700-0000-ae2a-2c32d10c0000 pid=3281 execve guuid=f5e4e008-1700-0000-ae2a-2c32d20c0000 pid=3282 /usr/bin/cat guuid=8baf9606-1700-0000-ae2a-2c32ce0c0000 pid=3278->guuid=f5e4e008-1700-0000-ae2a-2c32d20c0000 pid=3282 execve guuid=bfa25009-1700-0000-ae2a-2c32d30c0000 pid=3283 /usr/bin/ls guuid=8baf9606-1700-0000-ae2a-2c32ce0c0000 pid=3278->guuid=bfa25009-1700-0000-ae2a-2c32d30c0000 pid=3283 execve guuid=3338e509-1700-0000-ae2a-2c32d40c0000 pid=3284 /usr/bin/mkdir guuid=8baf9606-1700-0000-ae2a-2c32ce0c0000 pid=3278->guuid=3338e509-1700-0000-ae2a-2c32d40c0000 pid=3284 execve guuid=4d346a0a-1700-0000-ae2a-2c32d50c0000 pid=3285 /usr/bin/mv guuid=8baf9606-1700-0000-ae2a-2c32ce0c0000 pid=3278->guuid=4d346a0a-1700-0000-ae2a-2c32d50c0000 pid=3285 execve guuid=1d29f80a-1700-0000-ae2a-2c32d70c0000 pid=3287 /usr/bin/bash guuid=8baf9606-1700-0000-ae2a-2c32ce0c0000 pid=3278->guuid=1d29f80a-1700-0000-ae2a-2c32d70c0000 pid=3287 clone guuid=42c3ff0a-1700-0000-ae2a-2c32d80c0000 pid=3288 /usr/bin/base64 write-file guuid=8baf9606-1700-0000-ae2a-2c32ce0c0000 pid=3278->guuid=42c3ff0a-1700-0000-ae2a-2c32d80c0000 pid=3288 execve guuid=ef8e770b-1700-0000-ae2a-2c32d90c0000 pid=3289 /usr/bin/rm delete-file guuid=8baf9606-1700-0000-ae2a-2c32ce0c0000 pid=3278->guuid=ef8e770b-1700-0000-ae2a-2c32d90c0000 pid=3289 execve guuid=e297ce0b-1700-0000-ae2a-2c32db0c0000 pid=3291 /usr/bin/ls guuid=8baf9606-1700-0000-ae2a-2c32ce0c0000 pid=3278->guuid=e297ce0b-1700-0000-ae2a-2c32db0c0000 pid=3291 execve guuid=ed85540c-1700-0000-ae2a-2c32de0c0000 pid=3294 /usr/bin/bash guuid=8baf9606-1700-0000-ae2a-2c32ce0c0000 pid=3278->guuid=ed85540c-1700-0000-ae2a-2c32de0c0000 pid=3294 clone guuid=fd7b5b0c-1700-0000-ae2a-2c32df0c0000 pid=3295 /usr/bin/base64 write-file guuid=8baf9606-1700-0000-ae2a-2c32ce0c0000 pid=3278->guuid=fd7b5b0c-1700-0000-ae2a-2c32df0c0000 pid=3295 execve guuid=17ebcd0c-1700-0000-ae2a-2c32e10c0000 pid=3297 /usr/bin/ls guuid=8baf9606-1700-0000-ae2a-2c32ce0c0000 pid=3278->guuid=17ebcd0c-1700-0000-ae2a-2c32e10c0000 pid=3297 execve guuid=a484510d-1700-0000-ae2a-2c32e40c0000 pid=3300 /usr/bin/cat guuid=8baf9606-1700-0000-ae2a-2c32ce0c0000 pid=3278->guuid=a484510d-1700-0000-ae2a-2c32e40c0000 pid=3300 execve guuid=869eb40d-1700-0000-ae2a-2c32e50c0000 pid=3301 /usr/bin/ls guuid=8baf9606-1700-0000-ae2a-2c32ce0c0000 pid=3278->guuid=869eb40d-1700-0000-ae2a-2c32e50c0000 pid=3301 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Gathering data
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh afb7b489250ca4a066d5cfc906f7bbbfbd3075fe77db9f773dab10e6c6d4a1ba

(this sample)

  
Delivery method
Distributed via web download

Comments