MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d05ead9c37bae18d150d0c693810d5c1651bfb326c007c4c89d88ba7b439b3ff. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: d05ead9c37bae18d150d0c693810d5c1651bfb326c007c4c89d88ba7b439b3ff
SHA3-384 hash: 95403c4aff6639a3b2edc273c4d59880b015da126c8b94825b4cc58bdcd478f8ed4d0664d6182454ba1efb5c00618d46
SHA1 hash: 6ad232781130a8f434d4b21ef14e2c120f5b093a
MD5 hash: 2123cfa51a7e9bc68185da47006e6cd6
humanhash: hot-failed-venus-romeo
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-13 08:13:36 UTC
Last seen:2026-03-14 04:45:25 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 384:O4FcuQpWx+BL0SWL0g3OzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:O4F8i+BL0SI0iOzsP4cbddr7zsP4cbdu
TLSH T184925CB512896C79FBD0CE39AF3C7F4DADE8C2C42124A3ACBA4F39215A1166DC705359
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
2
# of downloads :
71
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=160002f7-1600-0000-f9c1-9b5b630d0000 pid=3427 /usr/bin/sudo guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435 /tmp/sample.bin guuid=160002f7-1600-0000-f9c1-9b5b630d0000 pid=3427->guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435 execve guuid=9f0c68f9-1600-0000-f9c1-9b5b6d0d0000 pid=3437 /usr/bin/bash guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=9f0c68f9-1600-0000-f9c1-9b5b6d0d0000 pid=3437 clone guuid=05b36ff9-1600-0000-f9c1-9b5b6e0d0000 pid=3438 /usr/bin/bash guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=05b36ff9-1600-0000-f9c1-9b5b6e0d0000 pid=3438 clone guuid=78239df9-1600-0000-f9c1-9b5b700d0000 pid=3440 /usr/bin/mkdir guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=78239df9-1600-0000-f9c1-9b5b700d0000 pid=3440 execve guuid=85e6f1f9-1600-0000-f9c1-9b5b720d0000 pid=3442 /usr/bin/mkdir guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=85e6f1f9-1600-0000-f9c1-9b5b720d0000 pid=3442 execve guuid=2e203dfa-1600-0000-f9c1-9b5b740d0000 pid=3444 /usr/bin/mkdir guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=2e203dfa-1600-0000-f9c1-9b5b740d0000 pid=3444 execve guuid=4071a2fa-1600-0000-f9c1-9b5b770d0000 pid=3447 /usr/bin/mkdir guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=4071a2fa-1600-0000-f9c1-9b5b770d0000 pid=3447 execve guuid=00c1f8fa-1600-0000-f9c1-9b5b790d0000 pid=3449 /usr/bin/mkdir guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=00c1f8fa-1600-0000-f9c1-9b5b790d0000 pid=3449 execve guuid=951d52fb-1600-0000-f9c1-9b5b7b0d0000 pid=3451 /usr/bin/mkdir guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=951d52fb-1600-0000-f9c1-9b5b7b0d0000 pid=3451 execve guuid=7fbaabfb-1600-0000-f9c1-9b5b7d0d0000 pid=3453 /usr/bin/mkdir guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=7fbaabfb-1600-0000-f9c1-9b5b7d0d0000 pid=3453 execve guuid=d70802fc-1600-0000-f9c1-9b5b7f0d0000 pid=3455 /usr/bin/cp guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=d70802fc-1600-0000-f9c1-9b5b7f0d0000 pid=3455 execve guuid=b38656fc-1600-0000-f9c1-9b5b810d0000 pid=3457 /usr/bin/cp guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=b38656fc-1600-0000-f9c1-9b5b810d0000 pid=3457 execve guuid=4b2acbfc-1600-0000-f9c1-9b5b840d0000 pid=3460 /usr/bin/cp guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=4b2acbfc-1600-0000-f9c1-9b5b840d0000 pid=3460 execve guuid=513c2efd-1600-0000-f9c1-9b5b860d0000 pid=3462 /usr/bin/cp guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=513c2efd-1600-0000-f9c1-9b5b860d0000 pid=3462 execve guuid=376e8afd-1600-0000-f9c1-9b5b890d0000 pid=3465 /usr/bin/cp guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=376e8afd-1600-0000-f9c1-9b5b890d0000 pid=3465 execve guuid=17f00efe-1600-0000-f9c1-9b5b8b0d0000 pid=3467 /usr/bin/cp guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=17f00efe-1600-0000-f9c1-9b5b8b0d0000 pid=3467 execve guuid=3125c0fe-1600-0000-f9c1-9b5b8e0d0000 pid=3470 /usr/bin/cp guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=3125c0fe-1600-0000-f9c1-9b5b8e0d0000 pid=3470 execve guuid=a96057ff-1600-0000-f9c1-9b5b910d0000 pid=3473 /usr/bin/cp guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=a96057ff-1600-0000-f9c1-9b5b910d0000 pid=3473 execve guuid=87a6e2ff-1600-0000-f9c1-9b5b930d0000 pid=3475 /usr/bin/cp guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=87a6e2ff-1600-0000-f9c1-9b5b930d0000 pid=3475 execve guuid=b7957300-1700-0000-f9c1-9b5b960d0000 pid=3478 /usr/bin/cp guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=b7957300-1700-0000-f9c1-9b5b960d0000 pid=3478 execve guuid=ccb00601-1700-0000-f9c1-9b5b990d0000 pid=3481 /usr/bin/cp guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=ccb00601-1700-0000-f9c1-9b5b990d0000 pid=3481 execve guuid=a1f09c01-1700-0000-f9c1-9b5b9c0d0000 pid=3484 /usr/bin/cp guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=a1f09c01-1700-0000-f9c1-9b5b9c0d0000 pid=3484 execve guuid=1ab83102-1700-0000-f9c1-9b5b9e0d0000 pid=3486 /usr/bin/cp guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=1ab83102-1700-0000-f9c1-9b5b9e0d0000 pid=3486 execve guuid=dae6f102-1700-0000-f9c1-9b5ba10d0000 pid=3489 /usr/bin/cp guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=dae6f102-1700-0000-f9c1-9b5ba10d0000 pid=3489 execve guuid=397f8603-1700-0000-f9c1-9b5ba40d0000 pid=3492 /usr/bin/cp guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=397f8603-1700-0000-f9c1-9b5ba40d0000 pid=3492 execve guuid=aef31704-1700-0000-f9c1-9b5ba70d0000 pid=3495 /usr/bin/touch guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=aef31704-1700-0000-f9c1-9b5ba70d0000 pid=3495 execve guuid=d7628904-1700-0000-f9c1-9b5ba90d0000 pid=3497 /usr/bin/bash guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=d7628904-1700-0000-f9c1-9b5ba90d0000 pid=3497 clone guuid=dc789004-1700-0000-f9c1-9b5baa0d0000 pid=3498 /usr/bin/bash guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=dc789004-1700-0000-f9c1-9b5baa0d0000 pid=3498 clone guuid=0177ca04-1700-0000-f9c1-9b5bac0d0000 pid=3500 /usr/bin/bash guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=0177ca04-1700-0000-f9c1-9b5bac0d0000 pid=3500 clone guuid=9af7d004-1700-0000-f9c1-9b5bad0d0000 pid=3501 /usr/bin/base64 write-file guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=9af7d004-1700-0000-f9c1-9b5bad0d0000 pid=3501 execve guuid=05ea6005-1700-0000-f9c1-9b5baf0d0000 pid=3503 /usr/bin/bash guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=05ea6005-1700-0000-f9c1-9b5baf0d0000 pid=3503 execve guuid=b79fed0b-1700-0000-f9c1-9b5bcd0d0000 pid=3533 /usr/bin/rm delete-file guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=b79fed0b-1700-0000-f9c1-9b5bcd0d0000 pid=3533 execve guuid=3d114b0c-1700-0000-f9c1-9b5bce0d0000 pid=3534 /usr/bin/bash guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=3d114b0c-1700-0000-f9c1-9b5bce0d0000 pid=3534 clone guuid=5d40520c-1700-0000-f9c1-9b5bcf0d0000 pid=3535 /usr/bin/bash guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=5d40520c-1700-0000-f9c1-9b5bcf0d0000 pid=3535 clone guuid=a4498b0c-1700-0000-f9c1-9b5bd00d0000 pid=3536 /usr/bin/bash guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=a4498b0c-1700-0000-f9c1-9b5bd00d0000 pid=3536 execve guuid=14edff0c-1700-0000-f9c1-9b5bd10d0000 pid=3537 /usr/bin/rm guuid=8293fff8-1600-0000-f9c1-9b5b6b0d0000 pid=3435->guuid=14edff0c-1700-0000-f9c1-9b5bd10d0000 pid=3537 execve guuid=156cc705-1700-0000-f9c1-9b5bb10d0000 pid=3505 /usr/bin/bash guuid=05ea6005-1700-0000-f9c1-9b5baf0d0000 pid=3503->guuid=156cc705-1700-0000-f9c1-9b5bb10d0000 pid=3505 clone guuid=899ecf05-1700-0000-f9c1-9b5bb30d0000 pid=3507 /usr/bin/bash guuid=05ea6005-1700-0000-f9c1-9b5baf0d0000 pid=3503->guuid=899ecf05-1700-0000-f9c1-9b5bb30d0000 pid=3507 clone guuid=c5aefc05-1700-0000-f9c1-9b5bb40d0000 pid=3508 /usr/bin/ls guuid=05ea6005-1700-0000-f9c1-9b5baf0d0000 pid=3503->guuid=c5aefc05-1700-0000-f9c1-9b5bb40d0000 pid=3508 execve guuid=d64a9306-1700-0000-f9c1-9b5bb70d0000 pid=3511 /usr/bin/cat guuid=05ea6005-1700-0000-f9c1-9b5baf0d0000 pid=3503->guuid=d64a9306-1700-0000-f9c1-9b5bb70d0000 pid=3511 execve guuid=511ffe06-1700-0000-f9c1-9b5bb90d0000 pid=3513 /usr/bin/ls guuid=05ea6005-1700-0000-f9c1-9b5baf0d0000 pid=3503->guuid=511ffe06-1700-0000-f9c1-9b5bb90d0000 pid=3513 execve guuid=a2829507-1700-0000-f9c1-9b5bbb0d0000 pid=3515 /usr/bin/mkdir guuid=05ea6005-1700-0000-f9c1-9b5baf0d0000 pid=3503->guuid=a2829507-1700-0000-f9c1-9b5bbb0d0000 pid=3515 execve guuid=8eab0b08-1700-0000-f9c1-9b5bbe0d0000 pid=3518 /usr/bin/mv guuid=05ea6005-1700-0000-f9c1-9b5baf0d0000 pid=3503->guuid=8eab0b08-1700-0000-f9c1-9b5bbe0d0000 pid=3518 execve guuid=fc9caa08-1700-0000-f9c1-9b5bc00d0000 pid=3520 /usr/bin/bash guuid=05ea6005-1700-0000-f9c1-9b5baf0d0000 pid=3503->guuid=fc9caa08-1700-0000-f9c1-9b5bc00d0000 pid=3520 clone guuid=c470b208-1700-0000-f9c1-9b5bc10d0000 pid=3521 /usr/bin/base64 write-file guuid=05ea6005-1700-0000-f9c1-9b5baf0d0000 pid=3503->guuid=c470b208-1700-0000-f9c1-9b5bc10d0000 pid=3521 execve guuid=b7f31c09-1700-0000-f9c1-9b5bc60d0000 pid=3526 /usr/bin/rm delete-file guuid=05ea6005-1700-0000-f9c1-9b5baf0d0000 pid=3503->guuid=b7f31c09-1700-0000-f9c1-9b5bc60d0000 pid=3526 execve guuid=a8327b09-1700-0000-f9c1-9b5bc70d0000 pid=3527 /usr/bin/ls guuid=05ea6005-1700-0000-f9c1-9b5baf0d0000 pid=3503->guuid=a8327b09-1700-0000-f9c1-9b5bc70d0000 pid=3527 execve guuid=bd91050a-1700-0000-f9c1-9b5bc80d0000 pid=3528 /usr/bin/bash guuid=05ea6005-1700-0000-f9c1-9b5baf0d0000 pid=3503->guuid=bd91050a-1700-0000-f9c1-9b5bc80d0000 pid=3528 clone guuid=110b0d0a-1700-0000-f9c1-9b5bc90d0000 pid=3529 /usr/bin/base64 write-file guuid=05ea6005-1700-0000-f9c1-9b5baf0d0000 pid=3503->guuid=110b0d0a-1700-0000-f9c1-9b5bc90d0000 pid=3529 execve guuid=be987b0a-1700-0000-f9c1-9b5bca0d0000 pid=3530 /usr/bin/ls guuid=05ea6005-1700-0000-f9c1-9b5baf0d0000 pid=3503->guuid=be987b0a-1700-0000-f9c1-9b5bca0d0000 pid=3530 execve guuid=eaccfc0a-1700-0000-f9c1-9b5bcb0d0000 pid=3531 /usr/bin/cat guuid=05ea6005-1700-0000-f9c1-9b5baf0d0000 pid=3503->guuid=eaccfc0a-1700-0000-f9c1-9b5bcb0d0000 pid=3531 execve guuid=2cd65d0b-1700-0000-f9c1-9b5bcc0d0000 pid=3532 /usr/bin/ls guuid=05ea6005-1700-0000-f9c1-9b5baf0d0000 pid=3503->guuid=2cd65d0b-1700-0000-f9c1-9b5bcc0d0000 pid=3532 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-13 08:14:16 UTC
File Type:
Text (Shell)
AV detection:
9 of 23 (39.13%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh d05ead9c37bae18d150d0c693810d5c1651bfb326c007c4c89d88ba7b439b3ff

(this sample)

  
Delivery method
Distributed via web download

Comments