MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c0c9afb77978ba1446fd5bb4b57c5ceaa95467a90d9bd374ab08a065c7b19fcc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: c0c9afb77978ba1446fd5bb4b57c5ceaa95467a90d9bd374ab08a065c7b19fcc
SHA3-384 hash: d0c9240dd54b0ef8ac027418acbfefba09661884501b3aaf3fa56e30b5d5f14a7683ee65ace047c00c94b6a4079cc077
SHA1 hash: af9c5ec86c05a96304176aca46bd6bf4e0f28db9
MD5 hash: 1bbdbfda7bbd2f908ae8ca0aa5a03087
humanhash: sad-comet-alanine-fifteen
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-23 06:52:14 UTC
Last seen:2026-03-23 09:57:33 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 384:ZmccuQpWx+BL0SWL0gMzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:Zmc8i+BL0SI0fzsP4cbddr7zsP4cbddo
TLSH T13C925CB412896C79FBD1CE39AF3C6F4DADE8C2C42124E3ACBA0F39205A1166DC705349
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
2
# of downloads :
51
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=ae312f54-1700-0000-8087-c5b4a90a0000 pid=2729 /usr/bin/sudo guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734 /tmp/sample.bin guuid=ae312f54-1700-0000-8087-c5b4a90a0000 pid=2729->guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734 execve guuid=2d782156-1700-0000-8087-c5b4b10a0000 pid=2737 /usr/bin/bash guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=2d782156-1700-0000-8087-c5b4b10a0000 pid=2737 clone guuid=5b1a2b56-1700-0000-8087-c5b4b20a0000 pid=2738 /usr/bin/bash guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=5b1a2b56-1700-0000-8087-c5b4b20a0000 pid=2738 clone guuid=8ea74556-1700-0000-8087-c5b4b30a0000 pid=2739 /usr/bin/mkdir guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=8ea74556-1700-0000-8087-c5b4b30a0000 pid=2739 execve guuid=20629d56-1700-0000-8087-c5b4b60a0000 pid=2742 /usr/bin/mkdir guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=20629d56-1700-0000-8087-c5b4b60a0000 pid=2742 execve guuid=d700ee56-1700-0000-8087-c5b4b70a0000 pid=2743 /usr/bin/mkdir guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=d700ee56-1700-0000-8087-c5b4b70a0000 pid=2743 execve guuid=00554457-1700-0000-8087-c5b4b90a0000 pid=2745 /usr/bin/mkdir guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=00554457-1700-0000-8087-c5b4b90a0000 pid=2745 execve guuid=e8d69757-1700-0000-8087-c5b4bb0a0000 pid=2747 /usr/bin/mkdir guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=e8d69757-1700-0000-8087-c5b4bb0a0000 pid=2747 execve guuid=ab54f257-1700-0000-8087-c5b4bd0a0000 pid=2749 /usr/bin/mkdir guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=ab54f257-1700-0000-8087-c5b4bd0a0000 pid=2749 execve guuid=22615058-1700-0000-8087-c5b4bf0a0000 pid=2751 /usr/bin/mkdir guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=22615058-1700-0000-8087-c5b4bf0a0000 pid=2751 execve guuid=3bb2af58-1700-0000-8087-c5b4c10a0000 pid=2753 /usr/bin/cp guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=3bb2af58-1700-0000-8087-c5b4c10a0000 pid=2753 execve guuid=95341059-1700-0000-8087-c5b4c30a0000 pid=2755 /usr/bin/cp guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=95341059-1700-0000-8087-c5b4c30a0000 pid=2755 execve guuid=54717a59-1700-0000-8087-c5b4c50a0000 pid=2757 /usr/bin/cp guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=54717a59-1700-0000-8087-c5b4c50a0000 pid=2757 execve guuid=a16ee459-1700-0000-8087-c5b4c70a0000 pid=2759 /usr/bin/cp guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=a16ee459-1700-0000-8087-c5b4c70a0000 pid=2759 execve guuid=7b80575a-1700-0000-8087-c5b4c80a0000 pid=2760 /usr/bin/cp guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=7b80575a-1700-0000-8087-c5b4c80a0000 pid=2760 execve guuid=526dbb5a-1700-0000-8087-c5b4cb0a0000 pid=2763 /usr/bin/cp guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=526dbb5a-1700-0000-8087-c5b4cb0a0000 pid=2763 execve guuid=3b9a165b-1700-0000-8087-c5b4cd0a0000 pid=2765 /usr/bin/cp guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=3b9a165b-1700-0000-8087-c5b4cd0a0000 pid=2765 execve guuid=4a07735b-1700-0000-8087-c5b4d00a0000 pid=2768 /usr/bin/cp guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=4a07735b-1700-0000-8087-c5b4d00a0000 pid=2768 execve guuid=6bd6db5b-1700-0000-8087-c5b4d20a0000 pid=2770 /usr/bin/cp guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=6bd6db5b-1700-0000-8087-c5b4d20a0000 pid=2770 execve guuid=4bb8545c-1700-0000-8087-c5b4d30a0000 pid=2771 /usr/bin/cp guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=4bb8545c-1700-0000-8087-c5b4d30a0000 pid=2771 execve guuid=a4b2b55c-1700-0000-8087-c5b4d50a0000 pid=2773 /usr/bin/cp guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=a4b2b55c-1700-0000-8087-c5b4d50a0000 pid=2773 execve guuid=dfc61a5d-1700-0000-8087-c5b4d70a0000 pid=2775 /usr/bin/cp guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=dfc61a5d-1700-0000-8087-c5b4d70a0000 pid=2775 execve guuid=36e97b5d-1700-0000-8087-c5b4d90a0000 pid=2777 /usr/bin/cp guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=36e97b5d-1700-0000-8087-c5b4d90a0000 pid=2777 execve guuid=de13d55d-1700-0000-8087-c5b4db0a0000 pid=2779 /usr/bin/cp guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=de13d55d-1700-0000-8087-c5b4db0a0000 pid=2779 execve guuid=cb97345e-1700-0000-8087-c5b4de0a0000 pid=2782 /usr/bin/cp guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=cb97345e-1700-0000-8087-c5b4de0a0000 pid=2782 execve guuid=a57b995e-1700-0000-8087-c5b4e00a0000 pid=2784 /usr/bin/touch guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=a57b995e-1700-0000-8087-c5b4e00a0000 pid=2784 execve guuid=bcf3e65e-1700-0000-8087-c5b4e10a0000 pid=2785 /usr/bin/bash guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=bcf3e65e-1700-0000-8087-c5b4e10a0000 pid=2785 clone guuid=b105f15e-1700-0000-8087-c5b4e20a0000 pid=2786 /usr/bin/bash guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=b105f15e-1700-0000-8087-c5b4e20a0000 pid=2786 clone guuid=3fd9175f-1700-0000-8087-c5b4e40a0000 pid=2788 /usr/bin/bash guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=3fd9175f-1700-0000-8087-c5b4e40a0000 pid=2788 clone guuid=8216255f-1700-0000-8087-c5b4e50a0000 pid=2789 /usr/bin/base64 write-file guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=8216255f-1700-0000-8087-c5b4e50a0000 pid=2789 execve guuid=13a4b75f-1700-0000-8087-c5b4e70a0000 pid=2791 /usr/bin/bash guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=13a4b75f-1700-0000-8087-c5b4e70a0000 pid=2791 execve guuid=dc020665-1700-0000-8087-c5b4090b0000 pid=2825 /usr/bin/rm delete-file guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=dc020665-1700-0000-8087-c5b4090b0000 pid=2825 execve guuid=5f8a5e65-1700-0000-8087-c5b40a0b0000 pid=2826 /usr/bin/bash guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=5f8a5e65-1700-0000-8087-c5b40a0b0000 pid=2826 clone guuid=f3c96565-1700-0000-8087-c5b40b0b0000 pid=2827 /usr/bin/bash guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=f3c96565-1700-0000-8087-c5b40b0b0000 pid=2827 clone guuid=86ef8f65-1700-0000-8087-c5b40c0b0000 pid=2828 /usr/bin/bash guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=86ef8f65-1700-0000-8087-c5b40c0b0000 pid=2828 execve guuid=b050e465-1700-0000-8087-c5b40f0b0000 pid=2831 /usr/bin/rm guuid=04bfcc55-1700-0000-8087-c5b4ae0a0000 pid=2734->guuid=b050e465-1700-0000-8087-c5b40f0b0000 pid=2831 execve guuid=b8610460-1700-0000-8087-c5b4e90a0000 pid=2793 /usr/bin/bash guuid=13a4b75f-1700-0000-8087-c5b4e70a0000 pid=2791->guuid=b8610460-1700-0000-8087-c5b4e90a0000 pid=2793 clone guuid=87610a60-1700-0000-8087-c5b4ea0a0000 pid=2794 /usr/bin/bash guuid=13a4b75f-1700-0000-8087-c5b4e70a0000 pid=2791->guuid=87610a60-1700-0000-8087-c5b4ea0a0000 pid=2794 clone guuid=72742460-1700-0000-8087-c5b4eb0a0000 pid=2795 /usr/bin/ls guuid=13a4b75f-1700-0000-8087-c5b4e70a0000 pid=2791->guuid=72742460-1700-0000-8087-c5b4eb0a0000 pid=2795 execve guuid=14aca460-1700-0000-8087-c5b4ee0a0000 pid=2798 /usr/bin/cat guuid=13a4b75f-1700-0000-8087-c5b4e70a0000 pid=2791->guuid=14aca460-1700-0000-8087-c5b4ee0a0000 pid=2798 execve guuid=043feb60-1700-0000-8087-c5b4f10a0000 pid=2801 /usr/bin/ls guuid=13a4b75f-1700-0000-8087-c5b4e70a0000 pid=2791->guuid=043feb60-1700-0000-8087-c5b4f10a0000 pid=2801 execve guuid=d08b6561-1700-0000-8087-c5b4f30a0000 pid=2803 /usr/bin/mkdir guuid=13a4b75f-1700-0000-8087-c5b4e70a0000 pid=2791->guuid=d08b6561-1700-0000-8087-c5b4f30a0000 pid=2803 execve guuid=3d4cc861-1700-0000-8087-c5b4f40a0000 pid=2804 /usr/bin/mv guuid=13a4b75f-1700-0000-8087-c5b4e70a0000 pid=2791->guuid=3d4cc861-1700-0000-8087-c5b4f40a0000 pid=2804 execve guuid=8a7e4662-1700-0000-8087-c5b4f70a0000 pid=2807 /usr/bin/bash guuid=13a4b75f-1700-0000-8087-c5b4e70a0000 pid=2791->guuid=8a7e4662-1700-0000-8087-c5b4f70a0000 pid=2807 clone guuid=da804c62-1700-0000-8087-c5b4f80a0000 pid=2808 /usr/bin/base64 write-file guuid=13a4b75f-1700-0000-8087-c5b4e70a0000 pid=2791->guuid=da804c62-1700-0000-8087-c5b4f80a0000 pid=2808 execve guuid=46409962-1700-0000-8087-c5b4fa0a0000 pid=2810 /usr/bin/rm delete-file guuid=13a4b75f-1700-0000-8087-c5b4e70a0000 pid=2791->guuid=46409962-1700-0000-8087-c5b4fa0a0000 pid=2810 execve guuid=3c85e262-1700-0000-8087-c5b4fc0a0000 pid=2812 /usr/bin/ls guuid=13a4b75f-1700-0000-8087-c5b4e70a0000 pid=2791->guuid=3c85e262-1700-0000-8087-c5b4fc0a0000 pid=2812 execve guuid=172a4d63-1700-0000-8087-c5b4ff0a0000 pid=2815 /usr/bin/bash guuid=13a4b75f-1700-0000-8087-c5b4e70a0000 pid=2791->guuid=172a4d63-1700-0000-8087-c5b4ff0a0000 pid=2815 clone guuid=50a25263-1700-0000-8087-c5b4000b0000 pid=2816 /usr/bin/base64 write-file guuid=13a4b75f-1700-0000-8087-c5b4e70a0000 pid=2791->guuid=50a25263-1700-0000-8087-c5b4000b0000 pid=2816 execve guuid=ed2faf63-1700-0000-8087-c5b4020b0000 pid=2818 /usr/bin/ls guuid=13a4b75f-1700-0000-8087-c5b4e70a0000 pid=2791->guuid=ed2faf63-1700-0000-8087-c5b4020b0000 pid=2818 execve guuid=8a1b4764-1700-0000-8087-c5b4050b0000 pid=2821 /usr/bin/cat guuid=13a4b75f-1700-0000-8087-c5b4e70a0000 pid=2791->guuid=8a1b4764-1700-0000-8087-c5b4050b0000 pid=2821 execve guuid=2f768a64-1700-0000-8087-c5b4070b0000 pid=2823 /usr/bin/ls guuid=13a4b75f-1700-0000-8087-c5b4e70a0000 pid=2791->guuid=2f768a64-1700-0000-8087-c5b4070b0000 pid=2823 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Heuristic
Status:
Malicious
First seen:
2026-03-23 06:53:14 UTC
File Type:
Text (Shell)
AV detection:
14 of 36 (38.89%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh c0c9afb77978ba1446fd5bb4b57c5ceaa95467a90d9bd374ab08a065c7b19fcc

(this sample)

  
Delivery method
Distributed via web download

Comments