MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d5202780fa8879955093dd41dcd0617e5a36e0937be8d3bddc9677142491802f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: d5202780fa8879955093dd41dcd0617e5a36e0937be8d3bddc9677142491802f
SHA3-384 hash: f4ce249c17892cc79be6740d57a486a6911d214ede1e1ff6c38ad29ede7e326e9c54d5979dc040e8de9f618be35b39fe
SHA1 hash: f955ea3d57bdd0d7c12bdf8cf70563b70a1329eb
MD5 hash: 1b8c31e19dacc7cb08b943adf27b687f
humanhash: social-four-twelve-diet
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-18 14:28:54 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:RLFcuQpWx+BL0SWL0gizsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:RLF8i+BL0SI0tzsP4cbddr7zsP4cbddo
TLSH T1A7925DB512896C79FBD0CE39AF3C7F4DADE8C2C42124A3ACBA4F39215A1166DC705359
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
49
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=9a10c0b9-1600-0000-c653-4fcacc0c0000 pid=3276 /usr/bin/sudo guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283 /tmp/sample.bin guuid=9a10c0b9-1600-0000-c653-4fcacc0c0000 pid=3276->guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283 execve guuid=4450ffbb-1600-0000-c653-4fcad50c0000 pid=3285 /usr/bin/bash guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=4450ffbb-1600-0000-c653-4fcad50c0000 pid=3285 clone guuid=99ec07bc-1600-0000-c653-4fcad60c0000 pid=3286 /usr/bin/bash guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=99ec07bc-1600-0000-c653-4fcad60c0000 pid=3286 clone guuid=1c9c39bc-1600-0000-c653-4fcad80c0000 pid=3288 /usr/bin/mkdir guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=1c9c39bc-1600-0000-c653-4fcad80c0000 pid=3288 execve guuid=4a5c8abc-1600-0000-c653-4fcad90c0000 pid=3289 /usr/bin/mkdir guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=4a5c8abc-1600-0000-c653-4fcad90c0000 pid=3289 execve guuid=e203dcbc-1600-0000-c653-4fcadb0c0000 pid=3291 /usr/bin/mkdir guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=e203dcbc-1600-0000-c653-4fcadb0c0000 pid=3291 execve guuid=bfe92ebd-1600-0000-c653-4fcadd0c0000 pid=3293 /usr/bin/mkdir guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=bfe92ebd-1600-0000-c653-4fcadd0c0000 pid=3293 execve guuid=85af7fbd-1600-0000-c653-4fcade0c0000 pid=3294 /usr/bin/mkdir guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=85af7fbd-1600-0000-c653-4fcade0c0000 pid=3294 execve guuid=b225ccbd-1600-0000-c653-4fcae00c0000 pid=3296 /usr/bin/mkdir guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=b225ccbd-1600-0000-c653-4fcae00c0000 pid=3296 execve guuid=6f1318be-1600-0000-c653-4fcae20c0000 pid=3298 /usr/bin/mkdir guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=6f1318be-1600-0000-c653-4fcae20c0000 pid=3298 execve guuid=d22c6fbe-1600-0000-c653-4fcae30c0000 pid=3299 /usr/bin/cp guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=d22c6fbe-1600-0000-c653-4fcae30c0000 pid=3299 execve guuid=e53fc9be-1600-0000-c653-4fcae50c0000 pid=3301 /usr/bin/cp guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=e53fc9be-1600-0000-c653-4fcae50c0000 pid=3301 execve guuid=ce9bbbbf-1600-0000-c653-4fcae60c0000 pid=3302 /usr/bin/cp guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=ce9bbbbf-1600-0000-c653-4fcae60c0000 pid=3302 execve guuid=432533c0-1600-0000-c653-4fcae70c0000 pid=3303 /usr/bin/cp guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=432533c0-1600-0000-c653-4fcae70c0000 pid=3303 execve guuid=b4f79cc0-1600-0000-c653-4fcaea0c0000 pid=3306 /usr/bin/cp guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=b4f79cc0-1600-0000-c653-4fcaea0c0000 pid=3306 execve guuid=d0dafec0-1600-0000-c653-4fcaec0c0000 pid=3308 /usr/bin/cp guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=d0dafec0-1600-0000-c653-4fcaec0c0000 pid=3308 execve guuid=f28c83c1-1600-0000-c653-4fcaef0c0000 pid=3311 /usr/bin/cp guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=f28c83c1-1600-0000-c653-4fcaef0c0000 pid=3311 execve guuid=49f3f4c1-1600-0000-c653-4fcaf10c0000 pid=3313 /usr/bin/cp guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=49f3f4c1-1600-0000-c653-4fcaf10c0000 pid=3313 execve guuid=ded972c2-1600-0000-c653-4fcaf30c0000 pid=3315 /usr/bin/cp guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=ded972c2-1600-0000-c653-4fcaf30c0000 pid=3315 execve guuid=d59dd5c2-1600-0000-c653-4fcaf40c0000 pid=3316 /usr/bin/cp guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=d59dd5c2-1600-0000-c653-4fcaf40c0000 pid=3316 execve guuid=dd9775c3-1600-0000-c653-4fcaf70c0000 pid=3319 /usr/bin/cp guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=dd9775c3-1600-0000-c653-4fcaf70c0000 pid=3319 execve guuid=5450e7c3-1600-0000-c653-4fcafa0c0000 pid=3322 /usr/bin/cp guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=5450e7c3-1600-0000-c653-4fcafa0c0000 pid=3322 execve guuid=3cd153c4-1600-0000-c653-4fcafd0c0000 pid=3325 /usr/bin/cp guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=3cd153c4-1600-0000-c653-4fcafd0c0000 pid=3325 execve guuid=46ccffc4-1600-0000-c653-4fca000d0000 pid=3328 /usr/bin/cp guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=46ccffc4-1600-0000-c653-4fca000d0000 pid=3328 execve guuid=ed3163c5-1600-0000-c653-4fca020d0000 pid=3330 /usr/bin/cp guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=ed3163c5-1600-0000-c653-4fca020d0000 pid=3330 execve guuid=06fbc6c5-1600-0000-c653-4fca040d0000 pid=3332 /usr/bin/touch guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=06fbc6c5-1600-0000-c653-4fca040d0000 pid=3332 execve guuid=ed0e07c6-1600-0000-c653-4fca060d0000 pid=3334 /usr/bin/bash guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=ed0e07c6-1600-0000-c653-4fca060d0000 pid=3334 clone guuid=738411c6-1600-0000-c653-4fca080d0000 pid=3336 /usr/bin/bash guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=738411c6-1600-0000-c653-4fca080d0000 pid=3336 clone guuid=48632cc6-1600-0000-c653-4fca090d0000 pid=3337 /usr/bin/bash guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=48632cc6-1600-0000-c653-4fca090d0000 pid=3337 clone guuid=2b1f32c6-1600-0000-c653-4fca0a0d0000 pid=3338 /usr/bin/base64 write-file guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=2b1f32c6-1600-0000-c653-4fca0a0d0000 pid=3338 execve guuid=880bcbc6-1600-0000-c653-4fca0d0d0000 pid=3341 /usr/bin/bash guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=880bcbc6-1600-0000-c653-4fca0d0d0000 pid=3341 execve guuid=a7bd1ecd-1600-0000-c653-4fca290d0000 pid=3369 /usr/bin/rm delete-file guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=a7bd1ecd-1600-0000-c653-4fca290d0000 pid=3369 execve guuid=9a0a86cd-1600-0000-c653-4fca2a0d0000 pid=3370 /usr/bin/bash guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=9a0a86cd-1600-0000-c653-4fca2a0d0000 pid=3370 clone guuid=6d4f92cd-1600-0000-c653-4fca2b0d0000 pid=3371 /usr/bin/bash guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=6d4f92cd-1600-0000-c653-4fca2b0d0000 pid=3371 clone guuid=2a6ad3cd-1600-0000-c653-4fca2c0d0000 pid=3372 /usr/bin/bash guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=2a6ad3cd-1600-0000-c653-4fca2c0d0000 pid=3372 execve guuid=e21e8cce-1600-0000-c653-4fca2d0d0000 pid=3373 /usr/bin/rm guuid=254aa5bb-1600-0000-c653-4fcad30c0000 pid=3283->guuid=e21e8cce-1600-0000-c653-4fca2d0d0000 pid=3373 execve guuid=7cbd41c7-1600-0000-c653-4fca100d0000 pid=3344 /usr/bin/bash guuid=880bcbc6-1600-0000-c653-4fca0d0d0000 pid=3341->guuid=7cbd41c7-1600-0000-c653-4fca100d0000 pid=3344 clone guuid=83e94dc7-1600-0000-c653-4fca110d0000 pid=3345 /usr/bin/bash guuid=880bcbc6-1600-0000-c653-4fca0d0d0000 pid=3341->guuid=83e94dc7-1600-0000-c653-4fca110d0000 pid=3345 clone guuid=ba746dc7-1600-0000-c653-4fca120d0000 pid=3346 /usr/bin/ls guuid=880bcbc6-1600-0000-c653-4fca0d0d0000 pid=3341->guuid=ba746dc7-1600-0000-c653-4fca120d0000 pid=3346 execve guuid=0f54dac7-1600-0000-c653-4fca150d0000 pid=3349 /usr/bin/cat guuid=880bcbc6-1600-0000-c653-4fca0d0d0000 pid=3341->guuid=0f54dac7-1600-0000-c653-4fca150d0000 pid=3349 execve guuid=9f572fc8-1600-0000-c653-4fca160d0000 pid=3350 /usr/bin/ls guuid=880bcbc6-1600-0000-c653-4fca0d0d0000 pid=3341->guuid=9f572fc8-1600-0000-c653-4fca160d0000 pid=3350 execve guuid=4982a8c8-1600-0000-c653-4fca180d0000 pid=3352 /usr/bin/mkdir guuid=880bcbc6-1600-0000-c653-4fca0d0d0000 pid=3341->guuid=4982a8c8-1600-0000-c653-4fca180d0000 pid=3352 execve guuid=3ec5f9c8-1600-0000-c653-4fca190d0000 pid=3353 /usr/bin/mv guuid=880bcbc6-1600-0000-c653-4fca0d0d0000 pid=3341->guuid=3ec5f9c8-1600-0000-c653-4fca190d0000 pid=3353 execve guuid=485561c9-1600-0000-c653-4fca1b0d0000 pid=3355 /usr/bin/bash guuid=880bcbc6-1600-0000-c653-4fca0d0d0000 pid=3341->guuid=485561c9-1600-0000-c653-4fca1b0d0000 pid=3355 clone guuid=46326fc9-1600-0000-c653-4fca1c0d0000 pid=3356 /usr/bin/base64 write-file guuid=880bcbc6-1600-0000-c653-4fca0d0d0000 pid=3341->guuid=46326fc9-1600-0000-c653-4fca1c0d0000 pid=3356 execve guuid=e54bb9c9-1600-0000-c653-4fca1f0d0000 pid=3359 /usr/bin/rm delete-file guuid=880bcbc6-1600-0000-c653-4fca0d0d0000 pid=3341->guuid=e54bb9c9-1600-0000-c653-4fca1f0d0000 pid=3359 execve guuid=edb717ca-1600-0000-c653-4fca210d0000 pid=3361 /usr/bin/ls guuid=880bcbc6-1600-0000-c653-4fca0d0d0000 pid=3341->guuid=edb717ca-1600-0000-c653-4fca210d0000 pid=3361 execve guuid=c13c7cca-1600-0000-c653-4fca240d0000 pid=3364 /usr/bin/bash guuid=880bcbc6-1600-0000-c653-4fca0d0d0000 pid=3341->guuid=c13c7cca-1600-0000-c653-4fca240d0000 pid=3364 clone guuid=d6828aca-1600-0000-c653-4fca250d0000 pid=3365 /usr/bin/base64 write-file guuid=880bcbc6-1600-0000-c653-4fca0d0d0000 pid=3341->guuid=d6828aca-1600-0000-c653-4fca250d0000 pid=3365 execve guuid=6e8831cb-1600-0000-c653-4fca260d0000 pid=3366 /usr/bin/ls guuid=880bcbc6-1600-0000-c653-4fca0d0d0000 pid=3341->guuid=6e8831cb-1600-0000-c653-4fca260d0000 pid=3366 execve guuid=ba60bbcb-1600-0000-c653-4fca270d0000 pid=3367 /usr/bin/cat guuid=880bcbc6-1600-0000-c653-4fca0d0d0000 pid=3341->guuid=ba60bbcb-1600-0000-c653-4fca270d0000 pid=3367 execve guuid=20353ecc-1600-0000-c653-4fca280d0000 pid=3368 /usr/bin/ls guuid=880bcbc6-1600-0000-c653-4fca0d0d0000 pid=3341->guuid=20353ecc-1600-0000-c653-4fca280d0000 pid=3368 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Heuristic
Status:
Malicious
First seen:
2026-03-18 14:29:25 UTC
File Type:
Text (Shell)
AV detection:
14 of 36 (38.89%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh d5202780fa8879955093dd41dcd0617e5a36e0937be8d3bddc9677142491802f

(this sample)

  
Delivery method
Distributed via web download

Comments