MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d05fecfdf187e28b21ac5e5df5659f10a5e5a23eeb638440ca93789c721a9d5a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: d05fecfdf187e28b21ac5e5df5659f10a5e5a23eeb638440ca93789c721a9d5a
SHA3-384 hash: 423a5567425cc84eb3947e70bba151250ec34048df1672b33090d9bb62b7b665d2311a8727c63c2bee67b51e22354578
SHA1 hash: c2c6722813452bb4a9d5d7afb0cdbe541f7a5b8d
MD5 hash: bf93b64f89338ae6e1f345d5fdf75f85
humanhash: maine-monkey-mockingbird-batman
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-14 08:50:30 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:FFcuQpWx+BL0SWL0guzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:FF8i+BL0SI0FzsP4cbddr7zsP4cbddrk
TLSH T14C925CB512896C79FBD1CE39AF3C6F4CADE8C2C42124E3ACBA4F39215A1166DC705349
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=0120e7e3-1700-0000-d8ff-f1a4a00b0000 pid=2976 /usr/bin/sudo guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983 /tmp/sample.bin guuid=0120e7e3-1700-0000-d8ff-f1a4a00b0000 pid=2976->guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983 execve guuid=62c273e6-1700-0000-d8ff-f1a4a90b0000 pid=2985 /usr/bin/bash guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=62c273e6-1700-0000-d8ff-f1a4a90b0000 pid=2985 clone guuid=0916a3e6-1700-0000-d8ff-f1a4aa0b0000 pid=2986 /usr/bin/bash guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=0916a3e6-1700-0000-d8ff-f1a4aa0b0000 pid=2986 clone guuid=bbdddbe6-1700-0000-d8ff-f1a4ac0b0000 pid=2988 /usr/bin/mkdir guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=bbdddbe6-1700-0000-d8ff-f1a4ac0b0000 pid=2988 execve guuid=10f235e7-1700-0000-d8ff-f1a4ae0b0000 pid=2990 /usr/bin/mkdir guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=10f235e7-1700-0000-d8ff-f1a4ae0b0000 pid=2990 execve guuid=9ad38ae7-1700-0000-d8ff-f1a4b00b0000 pid=2992 /usr/bin/mkdir guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=9ad38ae7-1700-0000-d8ff-f1a4b00b0000 pid=2992 execve guuid=947fe7e7-1700-0000-d8ff-f1a4b20b0000 pid=2994 /usr/bin/mkdir guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=947fe7e7-1700-0000-d8ff-f1a4b20b0000 pid=2994 execve guuid=c26870e8-1700-0000-d8ff-f1a4b50b0000 pid=2997 /usr/bin/mkdir guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=c26870e8-1700-0000-d8ff-f1a4b50b0000 pid=2997 execve guuid=7eeaf1e8-1700-0000-d8ff-f1a4b70b0000 pid=2999 /usr/bin/mkdir guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=7eeaf1e8-1700-0000-d8ff-f1a4b70b0000 pid=2999 execve guuid=79c76de9-1700-0000-d8ff-f1a4ba0b0000 pid=3002 /usr/bin/mkdir guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=79c76de9-1700-0000-d8ff-f1a4ba0b0000 pid=3002 execve guuid=3194c5e9-1700-0000-d8ff-f1a4bc0b0000 pid=3004 /usr/bin/cp guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=3194c5e9-1700-0000-d8ff-f1a4bc0b0000 pid=3004 execve guuid=968524ea-1700-0000-d8ff-f1a4be0b0000 pid=3006 /usr/bin/cp guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=968524ea-1700-0000-d8ff-f1a4be0b0000 pid=3006 execve guuid=1eb9a2ea-1700-0000-d8ff-f1a4c00b0000 pid=3008 /usr/bin/cp guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=1eb9a2ea-1700-0000-d8ff-f1a4c00b0000 pid=3008 execve guuid=7acefcea-1700-0000-d8ff-f1a4c20b0000 pid=3010 /usr/bin/cp guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=7acefcea-1700-0000-d8ff-f1a4c20b0000 pid=3010 execve guuid=43b156eb-1700-0000-d8ff-f1a4c50b0000 pid=3013 /usr/bin/cp guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=43b156eb-1700-0000-d8ff-f1a4c50b0000 pid=3013 execve guuid=81b5afeb-1700-0000-d8ff-f1a4c70b0000 pid=3015 /usr/bin/cp guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=81b5afeb-1700-0000-d8ff-f1a4c70b0000 pid=3015 execve guuid=396d09ec-1700-0000-d8ff-f1a4ca0b0000 pid=3018 /usr/bin/cp guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=396d09ec-1700-0000-d8ff-f1a4ca0b0000 pid=3018 execve guuid=bb2a6fec-1700-0000-d8ff-f1a4cc0b0000 pid=3020 /usr/bin/cp guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=bb2a6fec-1700-0000-d8ff-f1a4cc0b0000 pid=3020 execve guuid=f692ccec-1700-0000-d8ff-f1a4ce0b0000 pid=3022 /usr/bin/cp guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=f692ccec-1700-0000-d8ff-f1a4ce0b0000 pid=3022 execve guuid=d4a727ed-1700-0000-d8ff-f1a4d00b0000 pid=3024 /usr/bin/cp guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=d4a727ed-1700-0000-d8ff-f1a4d00b0000 pid=3024 execve guuid=cb1097ed-1700-0000-d8ff-f1a4d20b0000 pid=3026 /usr/bin/cp guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=cb1097ed-1700-0000-d8ff-f1a4d20b0000 pid=3026 execve guuid=0bdff7ed-1700-0000-d8ff-f1a4d40b0000 pid=3028 /usr/bin/cp guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=0bdff7ed-1700-0000-d8ff-f1a4d40b0000 pid=3028 execve guuid=785c62ee-1700-0000-d8ff-f1a4d60b0000 pid=3030 /usr/bin/cp guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=785c62ee-1700-0000-d8ff-f1a4d60b0000 pid=3030 execve guuid=f7f9d2ee-1700-0000-d8ff-f1a4d90b0000 pid=3033 /usr/bin/cp guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=f7f9d2ee-1700-0000-d8ff-f1a4d90b0000 pid=3033 execve guuid=10063bef-1700-0000-d8ff-f1a4db0b0000 pid=3035 /usr/bin/cp guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=10063bef-1700-0000-d8ff-f1a4db0b0000 pid=3035 execve guuid=7f09acef-1700-0000-d8ff-f1a4de0b0000 pid=3038 /usr/bin/touch guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=7f09acef-1700-0000-d8ff-f1a4de0b0000 pid=3038 execve guuid=371cfcef-1700-0000-d8ff-f1a4e00b0000 pid=3040 /usr/bin/bash guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=371cfcef-1700-0000-d8ff-f1a4e00b0000 pid=3040 clone guuid=aca309f0-1700-0000-d8ff-f1a4e10b0000 pid=3041 /usr/bin/bash guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=aca309f0-1700-0000-d8ff-f1a4e10b0000 pid=3041 clone guuid=33462ff0-1700-0000-d8ff-f1a4e30b0000 pid=3043 /usr/bin/bash guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=33462ff0-1700-0000-d8ff-f1a4e30b0000 pid=3043 clone guuid=d20637f0-1700-0000-d8ff-f1a4e40b0000 pid=3044 /usr/bin/base64 write-file guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=d20637f0-1700-0000-d8ff-f1a4e40b0000 pid=3044 execve guuid=00c0e8f0-1700-0000-d8ff-f1a4e70b0000 pid=3047 /usr/bin/bash guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=00c0e8f0-1700-0000-d8ff-f1a4e70b0000 pid=3047 execve guuid=e07e52f6-1700-0000-d8ff-f1a4090c0000 pid=3081 /usr/bin/rm delete-file guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=e07e52f6-1700-0000-d8ff-f1a4090c0000 pid=3081 execve guuid=22aa9ff6-1700-0000-d8ff-f1a40b0c0000 pid=3083 /usr/bin/bash guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=22aa9ff6-1700-0000-d8ff-f1a40b0c0000 pid=3083 clone guuid=fce0a6f6-1700-0000-d8ff-f1a40c0c0000 pid=3084 /usr/bin/bash guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=fce0a6f6-1700-0000-d8ff-f1a40c0c0000 pid=3084 clone guuid=2014fbf6-1700-0000-d8ff-f1a40e0c0000 pid=3086 /usr/bin/bash guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=2014fbf6-1700-0000-d8ff-f1a40e0c0000 pid=3086 execve guuid=ee3f5ff7-1700-0000-d8ff-f1a40f0c0000 pid=3087 /usr/bin/rm guuid=a8947de5-1700-0000-d8ff-f1a4a70b0000 pid=2983->guuid=ee3f5ff7-1700-0000-d8ff-f1a40f0c0000 pid=3087 execve guuid=62cb6af1-1700-0000-d8ff-f1a4e90b0000 pid=3049 /usr/bin/bash guuid=00c0e8f0-1700-0000-d8ff-f1a4e70b0000 pid=3047->guuid=62cb6af1-1700-0000-d8ff-f1a4e90b0000 pid=3049 clone guuid=526e77f1-1700-0000-d8ff-f1a4eb0b0000 pid=3051 /usr/bin/bash guuid=00c0e8f0-1700-0000-d8ff-f1a4e70b0000 pid=3047->guuid=526e77f1-1700-0000-d8ff-f1a4eb0b0000 pid=3051 clone guuid=ddc197f1-1700-0000-d8ff-f1a4ec0b0000 pid=3052 /usr/bin/ls guuid=00c0e8f0-1700-0000-d8ff-f1a4e70b0000 pid=3047->guuid=ddc197f1-1700-0000-d8ff-f1a4ec0b0000 pid=3052 execve guuid=34434ff2-1700-0000-d8ff-f1a4ef0b0000 pid=3055 /usr/bin/cat guuid=00c0e8f0-1700-0000-d8ff-f1a4e70b0000 pid=3047->guuid=34434ff2-1700-0000-d8ff-f1a4ef0b0000 pid=3055 execve guuid=7f4ba2f2-1700-0000-d8ff-f1a4f10b0000 pid=3057 /usr/bin/ls guuid=00c0e8f0-1700-0000-d8ff-f1a4e70b0000 pid=3047->guuid=7f4ba2f2-1700-0000-d8ff-f1a4f10b0000 pid=3057 execve guuid=14c20bf3-1700-0000-d8ff-f1a4f40b0000 pid=3060 /usr/bin/mkdir guuid=00c0e8f0-1700-0000-d8ff-f1a4e70b0000 pid=3047->guuid=14c20bf3-1700-0000-d8ff-f1a4f40b0000 pid=3060 execve guuid=99e05df3-1700-0000-d8ff-f1a4f60b0000 pid=3062 /usr/bin/mv guuid=00c0e8f0-1700-0000-d8ff-f1a4e70b0000 pid=3047->guuid=99e05df3-1700-0000-d8ff-f1a4f60b0000 pid=3062 execve guuid=eea7baf3-1700-0000-d8ff-f1a4f80b0000 pid=3064 /usr/bin/bash guuid=00c0e8f0-1700-0000-d8ff-f1a4e70b0000 pid=3047->guuid=eea7baf3-1700-0000-d8ff-f1a4f80b0000 pid=3064 clone guuid=0144c0f3-1700-0000-d8ff-f1a4f90b0000 pid=3065 /usr/bin/base64 write-file guuid=00c0e8f0-1700-0000-d8ff-f1a4e70b0000 pid=3047->guuid=0144c0f3-1700-0000-d8ff-f1a4f90b0000 pid=3065 execve guuid=f3fb1df4-1700-0000-d8ff-f1a4fb0b0000 pid=3067 /usr/bin/rm delete-file guuid=00c0e8f0-1700-0000-d8ff-f1a4e70b0000 pid=3047->guuid=f3fb1df4-1700-0000-d8ff-f1a4fb0b0000 pid=3067 execve guuid=5a9d6cf4-1700-0000-d8ff-f1a4fd0b0000 pid=3069 /usr/bin/ls guuid=00c0e8f0-1700-0000-d8ff-f1a4e70b0000 pid=3047->guuid=5a9d6cf4-1700-0000-d8ff-f1a4fd0b0000 pid=3069 execve guuid=d44cd3f4-1700-0000-d8ff-f1a4ff0b0000 pid=3071 /usr/bin/bash guuid=00c0e8f0-1700-0000-d8ff-f1a4e70b0000 pid=3047->guuid=d44cd3f4-1700-0000-d8ff-f1a4ff0b0000 pid=3071 clone guuid=4e3eddf4-1700-0000-d8ff-f1a4000c0000 pid=3072 /usr/bin/base64 write-file guuid=00c0e8f0-1700-0000-d8ff-f1a4e70b0000 pid=3047->guuid=4e3eddf4-1700-0000-d8ff-f1a4000c0000 pid=3072 execve guuid=234d2bf5-1700-0000-d8ff-f1a4020c0000 pid=3074 /usr/bin/ls guuid=00c0e8f0-1700-0000-d8ff-f1a4e70b0000 pid=3047->guuid=234d2bf5-1700-0000-d8ff-f1a4020c0000 pid=3074 execve guuid=825795f5-1700-0000-d8ff-f1a4040c0000 pid=3076 /usr/bin/cat guuid=00c0e8f0-1700-0000-d8ff-f1a4e70b0000 pid=3047->guuid=825795f5-1700-0000-d8ff-f1a4040c0000 pid=3076 execve guuid=88e8dff5-1700-0000-d8ff-f1a4060c0000 pid=3078 /usr/bin/ls guuid=00c0e8f0-1700-0000-d8ff-f1a4e70b0000 pid=3047->guuid=88e8dff5-1700-0000-d8ff-f1a4060c0000 pid=3078 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-14 08:51:17 UTC
File Type:
Text (Shell)
AV detection:
9 of 23 (39.13%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh d05fecfdf187e28b21ac5e5df5659f10a5e5a23eeb638440ca93789c721a9d5a

(this sample)

  
Delivery method
Distributed via web download

Comments