MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d3b49e8fd9dd22c01b87b4b4bbc452eb147bf573478c60fb68d42ed0243a93b3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: d3b49e8fd9dd22c01b87b4b4bbc452eb147bf573478c60fb68d42ed0243a93b3
SHA3-384 hash: d7003faedb9a62842d49850b4d6ef9c0e37e1bd9e8d87e9949ac39c9f475b04f32ab443ee22560b5f9f6352c0af1d76f
SHA1 hash: 04a1d0fc2fb562e683cac40194079ad93b58536e
MD5 hash: 2f3308448a951086aa91ac051cb1e227
humanhash: mockingbird-harry-river-london
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-09 09:23:41 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:DT0M3vgRjGlsaq7YUzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:D3mjfEUzsP4cbddr7zsP4cbddrk
TLSH T128925BA916496C79BBC1DE7D9F3C7F0CADE4C1C02118A39CBE4F39618A206ADDA0535D
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
53
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=3540cdf7-1600-0000-1057-358da40d0000 pid=3492 /usr/bin/sudo guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497 /tmp/sample.bin guuid=3540cdf7-1600-0000-1057-358da40d0000 pid=3492->guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497 execve guuid=7ca4d5fa-1600-0000-1057-358daa0d0000 pid=3498 /usr/bin/bash guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=7ca4d5fa-1600-0000-1057-358daa0d0000 pid=3498 clone guuid=b372e7fa-1600-0000-1057-358dab0d0000 pid=3499 /usr/bin/bash guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=b372e7fa-1600-0000-1057-358dab0d0000 pid=3499 clone guuid=552920fb-1600-0000-1057-358dad0d0000 pid=3501 /usr/bin/mkdir guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=552920fb-1600-0000-1057-358dad0d0000 pid=3501 execve guuid=889af5fb-1600-0000-1057-358daf0d0000 pid=3503 /usr/bin/mkdir guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=889af5fb-1600-0000-1057-358daf0d0000 pid=3503 execve guuid=82b04cfc-1600-0000-1057-358db10d0000 pid=3505 /usr/bin/mkdir guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=82b04cfc-1600-0000-1057-358db10d0000 pid=3505 execve guuid=b6a7a1fc-1600-0000-1057-358db30d0000 pid=3507 /usr/bin/mkdir guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=b6a7a1fc-1600-0000-1057-358db30d0000 pid=3507 execve guuid=617ff5fc-1600-0000-1057-358db50d0000 pid=3509 /usr/bin/mkdir guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=617ff5fc-1600-0000-1057-358db50d0000 pid=3509 execve guuid=e44c47fd-1600-0000-1057-358db60d0000 pid=3510 /usr/bin/mkdir guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=e44c47fd-1600-0000-1057-358db60d0000 pid=3510 execve guuid=e67b9ffd-1600-0000-1057-358db80d0000 pid=3512 /usr/bin/mkdir guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=e67b9ffd-1600-0000-1057-358db80d0000 pid=3512 execve guuid=cf6204fe-1600-0000-1057-358db90d0000 pid=3513 /usr/bin/cp guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=cf6204fe-1600-0000-1057-358db90d0000 pid=3513 execve guuid=c4f071fe-1600-0000-1057-358dba0d0000 pid=3514 /usr/bin/cp guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=c4f071fe-1600-0000-1057-358dba0d0000 pid=3514 execve guuid=f3e01aff-1600-0000-1057-358dbb0d0000 pid=3515 /usr/bin/cp guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=f3e01aff-1600-0000-1057-358dbb0d0000 pid=3515 execve guuid=3b86cfff-1600-0000-1057-358dbc0d0000 pid=3516 /usr/bin/cp guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=3b86cfff-1600-0000-1057-358dbc0d0000 pid=3516 execve guuid=93d96700-1700-0000-1057-358dbd0d0000 pid=3517 /usr/bin/cp guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=93d96700-1700-0000-1057-358dbd0d0000 pid=3517 execve guuid=86450901-1700-0000-1057-358dbe0d0000 pid=3518 /usr/bin/cp guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=86450901-1700-0000-1057-358dbe0d0000 pid=3518 execve guuid=1ed69901-1700-0000-1057-358dc00d0000 pid=3520 /usr/bin/cp guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=1ed69901-1700-0000-1057-358dc00d0000 pid=3520 execve guuid=cd813602-1700-0000-1057-358dc10d0000 pid=3521 /usr/bin/cp guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=cd813602-1700-0000-1057-358dc10d0000 pid=3521 execve guuid=4dceb802-1700-0000-1057-358dc20d0000 pid=3522 /usr/bin/cp guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=4dceb802-1700-0000-1057-358dc20d0000 pid=3522 execve guuid=12a43503-1700-0000-1057-358dc30d0000 pid=3523 /usr/bin/cp guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=12a43503-1700-0000-1057-358dc30d0000 pid=3523 execve guuid=5e5fc703-1700-0000-1057-358dc60d0000 pid=3526 /usr/bin/cp guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=5e5fc703-1700-0000-1057-358dc60d0000 pid=3526 execve guuid=bfdc5c04-1700-0000-1057-358dc90d0000 pid=3529 /usr/bin/cp guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=bfdc5c04-1700-0000-1057-358dc90d0000 pid=3529 execve guuid=9882f204-1700-0000-1057-358dcb0d0000 pid=3531 /usr/bin/cp guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=9882f204-1700-0000-1057-358dcb0d0000 pid=3531 execve guuid=f3e88405-1700-0000-1057-358dce0d0000 pid=3534 /usr/bin/cp guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=f3e88405-1700-0000-1057-358dce0d0000 pid=3534 execve guuid=55a81706-1700-0000-1057-358dd10d0000 pid=3537 /usr/bin/cp guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=55a81706-1700-0000-1057-358dd10d0000 pid=3537 execve guuid=f967a606-1700-0000-1057-358dd30d0000 pid=3539 /usr/bin/touch guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=f967a606-1700-0000-1057-358dd30d0000 pid=3539 execve guuid=614e1f07-1700-0000-1057-358dd50d0000 pid=3541 /usr/bin/bash guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=614e1f07-1700-0000-1057-358dd50d0000 pid=3541 clone guuid=38a22707-1700-0000-1057-358dd60d0000 pid=3542 /usr/bin/bash guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=38a22707-1700-0000-1057-358dd60d0000 pid=3542 clone guuid=b5835e07-1700-0000-1057-358dd80d0000 pid=3544 /usr/bin/bash guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=b5835e07-1700-0000-1057-358dd80d0000 pid=3544 clone guuid=abb36907-1700-0000-1057-358dd90d0000 pid=3545 /usr/bin/base64 write-file guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=abb36907-1700-0000-1057-358dd90d0000 pid=3545 execve guuid=c317f607-1700-0000-1057-358ddb0d0000 pid=3547 /usr/bin/bash guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=c317f607-1700-0000-1057-358ddb0d0000 pid=3547 execve guuid=2015a20f-1700-0000-1057-358dfc0d0000 pid=3580 /usr/bin/rm delete-file guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=2015a20f-1700-0000-1057-358dfc0d0000 pid=3580 execve guuid=b4530e10-1700-0000-1057-358dfe0d0000 pid=3582 /usr/bin/bash guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=b4530e10-1700-0000-1057-358dfe0d0000 pid=3582 clone guuid=63621610-1700-0000-1057-358dff0d0000 pid=3583 /usr/bin/bash guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=63621610-1700-0000-1057-358dff0d0000 pid=3583 clone guuid=7ba05910-1700-0000-1057-358d010e0000 pid=3585 /usr/bin/bash guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=7ba05910-1700-0000-1057-358d010e0000 pid=3585 execve guuid=0715de10-1700-0000-1057-358d030e0000 pid=3587 /usr/bin/rm guuid=539b4ffa-1600-0000-1057-358da90d0000 pid=3497->guuid=0715de10-1700-0000-1057-358d030e0000 pid=3587 execve guuid=f7696408-1700-0000-1057-358ddd0d0000 pid=3549 /usr/bin/bash guuid=c317f607-1700-0000-1057-358ddb0d0000 pid=3547->guuid=f7696408-1700-0000-1057-358ddd0d0000 pid=3549 clone guuid=90f56c08-1700-0000-1057-358ddf0d0000 pid=3551 /usr/bin/bash guuid=c317f607-1700-0000-1057-358ddb0d0000 pid=3547->guuid=90f56c08-1700-0000-1057-358ddf0d0000 pid=3551 clone guuid=9edd9708-1700-0000-1057-358de00d0000 pid=3552 /usr/bin/ls guuid=c317f607-1700-0000-1057-358ddb0d0000 pid=3547->guuid=9edd9708-1700-0000-1057-358de00d0000 pid=3552 execve guuid=06596209-1700-0000-1057-358de20d0000 pid=3554 /usr/bin/cat guuid=c317f607-1700-0000-1057-358ddb0d0000 pid=3547->guuid=06596209-1700-0000-1057-358de20d0000 pid=3554 execve guuid=a89fd909-1700-0000-1057-358de30d0000 pid=3555 /usr/bin/ls guuid=c317f607-1700-0000-1057-358ddb0d0000 pid=3547->guuid=a89fd909-1700-0000-1057-358de30d0000 pid=3555 execve guuid=3028800a-1700-0000-1057-358de40d0000 pid=3556 /usr/bin/mkdir guuid=c317f607-1700-0000-1057-358ddb0d0000 pid=3547->guuid=3028800a-1700-0000-1057-358de40d0000 pid=3556 execve guuid=b4e1b20b-1700-0000-1057-358de70d0000 pid=3559 /usr/bin/mv guuid=c317f607-1700-0000-1057-358ddb0d0000 pid=3547->guuid=b4e1b20b-1700-0000-1057-358de70d0000 pid=3559 execve guuid=34bb430c-1700-0000-1057-358dea0d0000 pid=3562 /usr/bin/bash guuid=c317f607-1700-0000-1057-358ddb0d0000 pid=3547->guuid=34bb430c-1700-0000-1057-358dea0d0000 pid=3562 clone guuid=9ed4510c-1700-0000-1057-358deb0d0000 pid=3563 /usr/bin/base64 write-file guuid=c317f607-1700-0000-1057-358ddb0d0000 pid=3547->guuid=9ed4510c-1700-0000-1057-358deb0d0000 pid=3563 execve guuid=787ab00c-1700-0000-1057-358ded0d0000 pid=3565 /usr/bin/rm delete-file guuid=c317f607-1700-0000-1057-358ddb0d0000 pid=3547->guuid=787ab00c-1700-0000-1057-358ded0d0000 pid=3565 execve guuid=7cc9050d-1700-0000-1057-358def0d0000 pid=3567 /usr/bin/ls guuid=c317f607-1700-0000-1057-358ddb0d0000 pid=3547->guuid=7cc9050d-1700-0000-1057-358def0d0000 pid=3567 execve guuid=4c4c840d-1700-0000-1057-358df10d0000 pid=3569 /usr/bin/bash guuid=c317f607-1700-0000-1057-358ddb0d0000 pid=3547->guuid=4c4c840d-1700-0000-1057-358df10d0000 pid=3569 clone guuid=c3f78b0d-1700-0000-1057-358df20d0000 pid=3570 /usr/bin/base64 write-file guuid=c317f607-1700-0000-1057-358ddb0d0000 pid=3547->guuid=c3f78b0d-1700-0000-1057-358df20d0000 pid=3570 execve guuid=0f54fc0d-1700-0000-1057-358df50d0000 pid=3573 /usr/bin/ls guuid=c317f607-1700-0000-1057-358ddb0d0000 pid=3547->guuid=0f54fc0d-1700-0000-1057-358df50d0000 pid=3573 execve guuid=c663920e-1700-0000-1057-358df70d0000 pid=3575 /usr/bin/cat guuid=c317f607-1700-0000-1057-358ddb0d0000 pid=3547->guuid=c663920e-1700-0000-1057-358df70d0000 pid=3575 execve guuid=ea6ffc0e-1700-0000-1057-358df90d0000 pid=3577 /usr/bin/ls guuid=c317f607-1700-0000-1057-358ddb0d0000 pid=3547->guuid=ea6ffc0e-1700-0000-1057-358df90d0000 pid=3577 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-09 09:24:19 UTC
File Type:
Text (Shell)
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh d3b49e8fd9dd22c01b87b4b4bbc452eb147bf573478c60fb68d42ed0243a93b3

(this sample)

  
Delivery method
Distributed via web download

Comments