MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cdc0c515cc18f18f2c546b137b9af24802413dbe63412d1e345aced2240781b5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: cdc0c515cc18f18f2c546b137b9af24802413dbe63412d1e345aced2240781b5
SHA3-384 hash: f97668fda36fe0a2ab216a184344e12a86be05ffcf1a4c932dc4cd94b85a2bc2483023792282cd613389b83623775507
SHA1 hash: 58c4be0aebdc00caebd8f8184b5f7575ec3c4d7c
MD5 hash: 17c281f3375d44e3ec4925103d965a50
humanhash: lemon-hawaii-speaker-ink
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-25 02:53:25 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:Pq4cuQpWx+BL0SWL0gGzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:Pq48i+BL0SI0FzsP4cbddr7zsP4cbddo
TLSH T1E8924CB512896C79FBD1CE39AF3C6F4DADE8C2C42124A3ACBA0F39215A1165DC70535A
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=dfb8dba9-1600-0000-74f5-7edb2e0e0000 pid=3630 /usr/bin/sudo guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638 /tmp/sample.bin guuid=dfb8dba9-1600-0000-74f5-7edb2e0e0000 pid=3630->guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638 execve guuid=778e8eac-1600-0000-74f5-7edb390e0000 pid=3641 /usr/bin/bash guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=778e8eac-1600-0000-74f5-7edb390e0000 pid=3641 clone guuid=c0d9b4ac-1600-0000-74f5-7edb3a0e0000 pid=3642 /usr/bin/bash guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=c0d9b4ac-1600-0000-74f5-7edb3a0e0000 pid=3642 clone guuid=92ae17ad-1600-0000-74f5-7edb3c0e0000 pid=3644 /usr/bin/mkdir guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=92ae17ad-1600-0000-74f5-7edb3c0e0000 pid=3644 execve guuid=f84b6bad-1600-0000-74f5-7edb3e0e0000 pid=3646 /usr/bin/mkdir guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=f84b6bad-1600-0000-74f5-7edb3e0e0000 pid=3646 execve guuid=76bac9ad-1600-0000-74f5-7edb400e0000 pid=3648 /usr/bin/mkdir guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=76bac9ad-1600-0000-74f5-7edb400e0000 pid=3648 execve guuid=031c1eae-1600-0000-74f5-7edb420e0000 pid=3650 /usr/bin/mkdir guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=031c1eae-1600-0000-74f5-7edb420e0000 pid=3650 execve guuid=d98b69ae-1600-0000-74f5-7edb440e0000 pid=3652 /usr/bin/mkdir guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=d98b69ae-1600-0000-74f5-7edb440e0000 pid=3652 execve guuid=dbbdc4ae-1600-0000-74f5-7edb450e0000 pid=3653 /usr/bin/mkdir guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=dbbdc4ae-1600-0000-74f5-7edb450e0000 pid=3653 execve guuid=397b1caf-1600-0000-74f5-7edb470e0000 pid=3655 /usr/bin/mkdir guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=397b1caf-1600-0000-74f5-7edb470e0000 pid=3655 execve guuid=1ca76aaf-1600-0000-74f5-7edb4a0e0000 pid=3658 /usr/bin/cp guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=1ca76aaf-1600-0000-74f5-7edb4a0e0000 pid=3658 execve guuid=d2e5d1af-1600-0000-74f5-7edb4b0e0000 pid=3659 /usr/bin/cp guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=d2e5d1af-1600-0000-74f5-7edb4b0e0000 pid=3659 execve guuid=57744ab0-1600-0000-74f5-7edb500e0000 pid=3664 /usr/bin/cp guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=57744ab0-1600-0000-74f5-7edb500e0000 pid=3664 execve guuid=e039a4b0-1600-0000-74f5-7edb520e0000 pid=3666 /usr/bin/cp guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=e039a4b0-1600-0000-74f5-7edb520e0000 pid=3666 execve guuid=2e640cb1-1600-0000-74f5-7edb540e0000 pid=3668 /usr/bin/cp guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=2e640cb1-1600-0000-74f5-7edb540e0000 pid=3668 execve guuid=138975b1-1600-0000-74f5-7edb570e0000 pid=3671 /usr/bin/cp guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=138975b1-1600-0000-74f5-7edb570e0000 pid=3671 execve guuid=1091dab1-1600-0000-74f5-7edb590e0000 pid=3673 /usr/bin/cp guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=1091dab1-1600-0000-74f5-7edb590e0000 pid=3673 execve guuid=aafc62b2-1600-0000-74f5-7edb5a0e0000 pid=3674 /usr/bin/cp guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=aafc62b2-1600-0000-74f5-7edb5a0e0000 pid=3674 execve guuid=f222f3b2-1600-0000-74f5-7edb5b0e0000 pid=3675 /usr/bin/cp guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=f222f3b2-1600-0000-74f5-7edb5b0e0000 pid=3675 execve guuid=0de886b3-1600-0000-74f5-7edb5c0e0000 pid=3676 /usr/bin/cp guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=0de886b3-1600-0000-74f5-7edb5c0e0000 pid=3676 execve guuid=b13e1db4-1600-0000-74f5-7edb5d0e0000 pid=3677 /usr/bin/cp guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=b13e1db4-1600-0000-74f5-7edb5d0e0000 pid=3677 execve guuid=be98a2b4-1600-0000-74f5-7edb5e0e0000 pid=3678 /usr/bin/cp guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=be98a2b4-1600-0000-74f5-7edb5e0e0000 pid=3678 execve guuid=012a2fb5-1600-0000-74f5-7edb5f0e0000 pid=3679 /usr/bin/cp guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=012a2fb5-1600-0000-74f5-7edb5f0e0000 pid=3679 execve guuid=4277b9b5-1600-0000-74f5-7edb600e0000 pid=3680 /usr/bin/cp guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=4277b9b5-1600-0000-74f5-7edb600e0000 pid=3680 execve guuid=941c8bb6-1600-0000-74f5-7edb610e0000 pid=3681 /usr/bin/cp guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=941c8bb6-1600-0000-74f5-7edb610e0000 pid=3681 execve guuid=0a5918b7-1600-0000-74f5-7edb620e0000 pid=3682 /usr/bin/touch guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=0a5918b7-1600-0000-74f5-7edb620e0000 pid=3682 execve guuid=e5ea79b7-1600-0000-74f5-7edb630e0000 pid=3683 /usr/bin/bash guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=e5ea79b7-1600-0000-74f5-7edb630e0000 pid=3683 clone guuid=411e82b7-1600-0000-74f5-7edb640e0000 pid=3684 /usr/bin/bash guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=411e82b7-1600-0000-74f5-7edb640e0000 pid=3684 clone guuid=79faa9b7-1600-0000-74f5-7edb650e0000 pid=3685 /usr/bin/bash guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=79faa9b7-1600-0000-74f5-7edb650e0000 pid=3685 clone guuid=1cf1b1b7-1600-0000-74f5-7edb660e0000 pid=3686 /usr/bin/base64 write-file guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=1cf1b1b7-1600-0000-74f5-7edb660e0000 pid=3686 execve guuid=5d9a73b8-1600-0000-74f5-7edb670e0000 pid=3687 /usr/bin/bash guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=5d9a73b8-1600-0000-74f5-7edb670e0000 pid=3687 execve guuid=2d945dbf-1600-0000-74f5-7edb830e0000 pid=3715 /usr/bin/rm delete-file guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=2d945dbf-1600-0000-74f5-7edb830e0000 pid=3715 execve guuid=ef9da9bf-1600-0000-74f5-7edb850e0000 pid=3717 /usr/bin/bash guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=ef9da9bf-1600-0000-74f5-7edb850e0000 pid=3717 clone guuid=2043b0bf-1600-0000-74f5-7edb860e0000 pid=3718 /usr/bin/bash guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=2043b0bf-1600-0000-74f5-7edb860e0000 pid=3718 clone guuid=b22fd6bf-1600-0000-74f5-7edb870e0000 pid=3719 /usr/bin/bash guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=b22fd6bf-1600-0000-74f5-7edb870e0000 pid=3719 execve guuid=0e7b6ac0-1600-0000-74f5-7edb880e0000 pid=3720 /usr/bin/rm guuid=445ee2ab-1600-0000-74f5-7edb360e0000 pid=3638->guuid=0e7b6ac0-1600-0000-74f5-7edb880e0000 pid=3720 execve guuid=bfec16b9-1600-0000-74f5-7edb680e0000 pid=3688 /usr/bin/bash guuid=5d9a73b8-1600-0000-74f5-7edb670e0000 pid=3687->guuid=bfec16b9-1600-0000-74f5-7edb680e0000 pid=3688 clone guuid=6f9f27b9-1600-0000-74f5-7edb690e0000 pid=3689 /usr/bin/bash guuid=5d9a73b8-1600-0000-74f5-7edb670e0000 pid=3687->guuid=6f9f27b9-1600-0000-74f5-7edb690e0000 pid=3689 clone guuid=549196b9-1600-0000-74f5-7edb6a0e0000 pid=3690 /usr/bin/ls guuid=5d9a73b8-1600-0000-74f5-7edb670e0000 pid=3687->guuid=549196b9-1600-0000-74f5-7edb6a0e0000 pid=3690 execve guuid=59fa46ba-1600-0000-74f5-7edb6b0e0000 pid=3691 /usr/bin/cat guuid=5d9a73b8-1600-0000-74f5-7edb670e0000 pid=3687->guuid=59fa46ba-1600-0000-74f5-7edb6b0e0000 pid=3691 execve guuid=44779eba-1600-0000-74f5-7edb6c0e0000 pid=3692 /usr/bin/ls guuid=5d9a73b8-1600-0000-74f5-7edb670e0000 pid=3687->guuid=44779eba-1600-0000-74f5-7edb6c0e0000 pid=3692 execve guuid=180c3fbb-1600-0000-74f5-7edb6d0e0000 pid=3693 /usr/bin/mkdir guuid=5d9a73b8-1600-0000-74f5-7edb670e0000 pid=3687->guuid=180c3fbb-1600-0000-74f5-7edb6d0e0000 pid=3693 execve guuid=2650babb-1600-0000-74f5-7edb6e0e0000 pid=3694 /usr/bin/mv guuid=5d9a73b8-1600-0000-74f5-7edb670e0000 pid=3687->guuid=2650babb-1600-0000-74f5-7edb6e0e0000 pid=3694 execve guuid=f34943bc-1600-0000-74f5-7edb6f0e0000 pid=3695 /usr/bin/bash guuid=5d9a73b8-1600-0000-74f5-7edb670e0000 pid=3687->guuid=f34943bc-1600-0000-74f5-7edb6f0e0000 pid=3695 clone guuid=390652bc-1600-0000-74f5-7edb700e0000 pid=3696 /usr/bin/base64 write-file guuid=5d9a73b8-1600-0000-74f5-7edb670e0000 pid=3687->guuid=390652bc-1600-0000-74f5-7edb700e0000 pid=3696 execve guuid=f40aeebc-1600-0000-74f5-7edb740e0000 pid=3700 /usr/bin/rm delete-file guuid=5d9a73b8-1600-0000-74f5-7edb670e0000 pid=3687->guuid=f40aeebc-1600-0000-74f5-7edb740e0000 pid=3700 execve guuid=522866bd-1600-0000-74f5-7edb750e0000 pid=3701 /usr/bin/ls guuid=5d9a73b8-1600-0000-74f5-7edb670e0000 pid=3687->guuid=522866bd-1600-0000-74f5-7edb750e0000 pid=3701 execve guuid=1b54dabd-1600-0000-74f5-7edb790e0000 pid=3705 /usr/bin/bash guuid=5d9a73b8-1600-0000-74f5-7edb670e0000 pid=3687->guuid=1b54dabd-1600-0000-74f5-7edb790e0000 pid=3705 clone guuid=3572e0bd-1600-0000-74f5-7edb7a0e0000 pid=3706 /usr/bin/base64 write-file guuid=5d9a73b8-1600-0000-74f5-7edb670e0000 pid=3687->guuid=3572e0bd-1600-0000-74f5-7edb7a0e0000 pid=3706 execve guuid=ebe235be-1600-0000-74f5-7edb7c0e0000 pid=3708 /usr/bin/ls guuid=5d9a73b8-1600-0000-74f5-7edb670e0000 pid=3687->guuid=ebe235be-1600-0000-74f5-7edb7c0e0000 pid=3708 execve guuid=33cfa0be-1600-0000-74f5-7edb7f0e0000 pid=3711 /usr/bin/cat guuid=5d9a73b8-1600-0000-74f5-7edb670e0000 pid=3687->guuid=33cfa0be-1600-0000-74f5-7edb7f0e0000 pid=3711 execve guuid=7aede4be-1600-0000-74f5-7edb800e0000 pid=3712 /usr/bin/ls guuid=5d9a73b8-1600-0000-74f5-7edb670e0000 pid=3687->guuid=7aede4be-1600-0000-74f5-7edb800e0000 pid=3712 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Gathering data
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh cdc0c515cc18f18f2c546b137b9af24802413dbe63412d1e345aced2240781b5

(this sample)

  
Delivery method
Distributed via web download

Comments