MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d416f76290f56c503d16f8db41a5eb6c6702495b1397a5b431eb0a089582321e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: d416f76290f56c503d16f8db41a5eb6c6702495b1397a5b431eb0a089582321e
SHA3-384 hash: 59ad89f06029939ee3b45702e365add79a7d121c2fb7779d0c9a2f3207ad78fecfce9fe5edfa3cb9983ad9b3047fc871
SHA1 hash: 4a1b05b97cf2b2091598a86c0541abd3ef0cd652
MD5 hash: f6be9053fc562c6d5c58487178c09bcc
humanhash: autumn-johnny-twelve-twenty
File name:k.php
Download: download sample
File size:19'491 bytes
First seen:2026-03-15 15:45:47 UTC
Last seen:2026-03-15 21:00:41 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 384:nvncuxOLnVYMSczsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:nUuQL+czsP4cbddr7zsP4cbddrk
TLSH T12B924BB506496C75FBC0CE799F3C7F0CADE582C42129E39DBA1F39705A2065DC60935A
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
2
# of downloads :
102
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=2e0b28a6-1600-0000-0225-2901fa0c0000 pid=3322 /usr/bin/sudo guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323 /tmp/sample.bin guuid=2e0b28a6-1600-0000-0225-2901fa0c0000 pid=3322->guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323 execve guuid=63263ea9-1600-0000-0225-2901fc0c0000 pid=3324 /usr/bin/bash guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=63263ea9-1600-0000-0225-2901fc0c0000 pid=3324 clone guuid=6f0651a9-1600-0000-0225-2901fd0c0000 pid=3325 /usr/bin/bash guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=6f0651a9-1600-0000-0225-2901fd0c0000 pid=3325 clone guuid=dd7f87a9-1600-0000-0225-2901fe0c0000 pid=3326 /usr/bin/mkdir guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=dd7f87a9-1600-0000-0225-2901fe0c0000 pid=3326 execve guuid=996f27aa-1600-0000-0225-2901ff0c0000 pid=3327 /usr/bin/mkdir guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=996f27aa-1600-0000-0225-2901ff0c0000 pid=3327 execve guuid=972d8aaa-1600-0000-0225-2901000d0000 pid=3328 /usr/bin/mkdir guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=972d8aaa-1600-0000-0225-2901000d0000 pid=3328 execve guuid=f08af2aa-1600-0000-0225-2901010d0000 pid=3329 /usr/bin/mkdir guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=f08af2aa-1600-0000-0225-2901010d0000 pid=3329 execve guuid=60f956ab-1600-0000-0225-2901020d0000 pid=3330 /usr/bin/mkdir guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=60f956ab-1600-0000-0225-2901020d0000 pid=3330 execve guuid=d08abdab-1600-0000-0225-2901030d0000 pid=3331 /usr/bin/mkdir guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=d08abdab-1600-0000-0225-2901030d0000 pid=3331 execve guuid=987119ac-1600-0000-0225-2901050d0000 pid=3333 /usr/bin/mkdir guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=987119ac-1600-0000-0225-2901050d0000 pid=3333 execve guuid=afdd7dac-1600-0000-0225-2901060d0000 pid=3334 /usr/bin/cp guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=afdd7dac-1600-0000-0225-2901060d0000 pid=3334 execve guuid=fa66f3ac-1600-0000-0225-2901070d0000 pid=3335 /usr/bin/cp guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=fa66f3ac-1600-0000-0225-2901070d0000 pid=3335 execve guuid=ccfcaaad-1600-0000-0225-2901080d0000 pid=3336 /usr/bin/cp guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=ccfcaaad-1600-0000-0225-2901080d0000 pid=3336 execve guuid=8b330dae-1600-0000-0225-29010b0d0000 pid=3339 /usr/bin/cp guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=8b330dae-1600-0000-0225-29010b0d0000 pid=3339 execve guuid=e2c4c2ae-1600-0000-0225-29010e0d0000 pid=3342 /usr/bin/cp guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=e2c4c2ae-1600-0000-0225-29010e0d0000 pid=3342 execve guuid=cd4730af-1600-0000-0225-2901100d0000 pid=3344 /usr/bin/cp guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=cd4730af-1600-0000-0225-2901100d0000 pid=3344 execve guuid=b5b197af-1600-0000-0225-2901130d0000 pid=3347 /usr/bin/cp guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=b5b197af-1600-0000-0225-2901130d0000 pid=3347 execve guuid=354cfeaf-1600-0000-0225-2901150d0000 pid=3349 /usr/bin/cp guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=354cfeaf-1600-0000-0225-2901150d0000 pid=3349 execve guuid=357d61b0-1600-0000-0225-2901180d0000 pid=3352 /usr/bin/cp guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=357d61b0-1600-0000-0225-2901180d0000 pid=3352 execve guuid=86c5cab0-1600-0000-0225-29011a0d0000 pid=3354 /usr/bin/cp guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=86c5cab0-1600-0000-0225-29011a0d0000 pid=3354 execve guuid=cff037b1-1600-0000-0225-29011b0d0000 pid=3355 /usr/bin/cp guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=cff037b1-1600-0000-0225-29011b0d0000 pid=3355 execve guuid=54e4b8b1-1600-0000-0225-29011c0d0000 pid=3356 /usr/bin/cp guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=54e4b8b1-1600-0000-0225-29011c0d0000 pid=3356 execve guuid=1b362db2-1600-0000-0225-29011e0d0000 pid=3358 /usr/bin/cp guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=1b362db2-1600-0000-0225-29011e0d0000 pid=3358 execve guuid=1bdd84b2-1600-0000-0225-2901200d0000 pid=3360 /usr/bin/cp guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=1bdd84b2-1600-0000-0225-2901200d0000 pid=3360 execve guuid=7251e6b2-1600-0000-0225-2901220d0000 pid=3362 /usr/bin/cp guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=7251e6b2-1600-0000-0225-2901220d0000 pid=3362 execve guuid=a8fa4eb3-1600-0000-0225-2901240d0000 pid=3364 /usr/bin/touch guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=a8fa4eb3-1600-0000-0225-2901240d0000 pid=3364 execve guuid=45c696b3-1600-0000-0225-2901260d0000 pid=3366 /usr/bin/bash guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=45c696b3-1600-0000-0225-2901260d0000 pid=3366 clone guuid=e2159db3-1600-0000-0225-2901270d0000 pid=3367 /usr/bin/bash guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=e2159db3-1600-0000-0225-2901270d0000 pid=3367 clone guuid=e6b2b8b3-1600-0000-0225-2901290d0000 pid=3369 /usr/bin/bash guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=e6b2b8b3-1600-0000-0225-2901290d0000 pid=3369 clone guuid=9fa6beb3-1600-0000-0225-29012a0d0000 pid=3370 /usr/bin/base64 write-file guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=9fa6beb3-1600-0000-0225-29012a0d0000 pid=3370 execve guuid=a35143b4-1600-0000-0225-29012c0d0000 pid=3372 /usr/bin/bash guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=a35143b4-1600-0000-0225-29012c0d0000 pid=3372 execve guuid=5ff3c3b9-1600-0000-0225-2901460d0000 pid=3398 /usr/bin/rm delete-file guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=5ff3c3b9-1600-0000-0225-2901460d0000 pid=3398 execve guuid=60ee0cba-1600-0000-0225-2901480d0000 pid=3400 /usr/bin/bash guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=60ee0cba-1600-0000-0225-2901480d0000 pid=3400 clone guuid=775814ba-1600-0000-0225-2901490d0000 pid=3401 /usr/bin/bash guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=775814ba-1600-0000-0225-2901490d0000 pid=3401 clone guuid=201834ba-1600-0000-0225-29014a0d0000 pid=3402 /usr/bin/bash guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=201834ba-1600-0000-0225-29014a0d0000 pid=3402 execve guuid=f45a84ba-1600-0000-0225-29014d0d0000 pid=3405 /usr/bin/rm guuid=606e57a8-1600-0000-0225-2901fb0c0000 pid=3323->guuid=f45a84ba-1600-0000-0225-29014d0d0000 pid=3405 execve guuid=e3259db4-1600-0000-0225-29012d0d0000 pid=3373 /usr/bin/bash guuid=a35143b4-1600-0000-0225-29012c0d0000 pid=3372->guuid=e3259db4-1600-0000-0225-29012d0d0000 pid=3373 clone guuid=72ada4b4-1600-0000-0225-29012e0d0000 pid=3374 /usr/bin/bash guuid=a35143b4-1600-0000-0225-29012c0d0000 pid=3372->guuid=72ada4b4-1600-0000-0225-29012e0d0000 pid=3374 clone guuid=27c9d1b4-1600-0000-0225-29012f0d0000 pid=3375 /usr/bin/ls guuid=a35143b4-1600-0000-0225-29012c0d0000 pid=3372->guuid=27c9d1b4-1600-0000-0225-29012f0d0000 pid=3375 execve guuid=0a1b69b5-1600-0000-0225-2901300d0000 pid=3376 /usr/bin/cat guuid=a35143b4-1600-0000-0225-29012c0d0000 pid=3372->guuid=0a1b69b5-1600-0000-0225-2901300d0000 pid=3376 execve guuid=d3f7acb5-1600-0000-0225-2901320d0000 pid=3378 /usr/bin/ls guuid=a35143b4-1600-0000-0225-29012c0d0000 pid=3372->guuid=d3f7acb5-1600-0000-0225-2901320d0000 pid=3378 execve guuid=b27a20b6-1600-0000-0225-2901340d0000 pid=3380 /usr/bin/mkdir guuid=a35143b4-1600-0000-0225-29012c0d0000 pid=3372->guuid=b27a20b6-1600-0000-0225-2901340d0000 pid=3380 execve guuid=52317db6-1600-0000-0225-2901360d0000 pid=3382 /usr/bin/mv guuid=a35143b4-1600-0000-0225-29012c0d0000 pid=3372->guuid=52317db6-1600-0000-0225-2901360d0000 pid=3382 execve guuid=08b2dfb6-1600-0000-0225-2901380d0000 pid=3384 /usr/bin/bash guuid=a35143b4-1600-0000-0225-29012c0d0000 pid=3372->guuid=08b2dfb6-1600-0000-0225-2901380d0000 pid=3384 clone guuid=c1e5ebb6-1600-0000-0225-2901390d0000 pid=3385 /usr/bin/base64 write-file guuid=a35143b4-1600-0000-0225-29012c0d0000 pid=3372->guuid=c1e5ebb6-1600-0000-0225-2901390d0000 pid=3385 execve guuid=594439b7-1600-0000-0225-29013c0d0000 pid=3388 /usr/bin/rm delete-file guuid=a35143b4-1600-0000-0225-29012c0d0000 pid=3372->guuid=594439b7-1600-0000-0225-29013c0d0000 pid=3388 execve guuid=a8158bb7-1600-0000-0225-29013d0d0000 pid=3389 /usr/bin/ls guuid=a35143b4-1600-0000-0225-29012c0d0000 pid=3372->guuid=a8158bb7-1600-0000-0225-29013d0d0000 pid=3389 execve guuid=b90a15b8-1600-0000-0225-29013f0d0000 pid=3391 /usr/bin/bash guuid=a35143b4-1600-0000-0225-29012c0d0000 pid=3372->guuid=b90a15b8-1600-0000-0225-29013f0d0000 pid=3391 clone guuid=989a1bb8-1600-0000-0225-2901400d0000 pid=3392 /usr/bin/base64 write-file guuid=a35143b4-1600-0000-0225-29012c0d0000 pid=3372->guuid=989a1bb8-1600-0000-0225-2901400d0000 pid=3392 execve guuid=4a8c82b8-1600-0000-0225-2901410d0000 pid=3393 /usr/bin/ls guuid=a35143b4-1600-0000-0225-29012c0d0000 pid=3372->guuid=4a8c82b8-1600-0000-0225-2901410d0000 pid=3393 execve guuid=118905b9-1600-0000-0225-2901420d0000 pid=3394 /usr/bin/cat guuid=a35143b4-1600-0000-0225-29012c0d0000 pid=3372->guuid=118905b9-1600-0000-0225-2901420d0000 pid=3394 execve guuid=cf9852b9-1600-0000-0225-2901430d0000 pid=3395 /usr/bin/ls guuid=a35143b4-1600-0000-0225-29012c0d0000 pid=3372->guuid=cf9852b9-1600-0000-0225-2901430d0000 pid=3395 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-15 15:46:11 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh d416f76290f56c503d16f8db41a5eb6c6702495b1397a5b431eb0a089582321e

(this sample)

  
Delivery method
Distributed via web download

Comments