MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d924b2a40dd826c90a115240bac6eba1edbc725adbea5b2fbe193e0facd90e55. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: d924b2a40dd826c90a115240bac6eba1edbc725adbea5b2fbe193e0facd90e55
SHA3-384 hash: 876204063be15ce6748b609aa5f4092d3978ee37b88bf02a43f7e584dc13823394169f13bdab3e7d5796ee54eb263c61
SHA1 hash: 0aac33584bf4c928d9aa570fe256b66fc9ea5a90
MD5 hash: a5054bd9414e6426dbcea5002dd68c57
humanhash: speaker-enemy-eighteen-red
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-18 02:30:30 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:tz0M3vgRjGlsaq7RzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:tXmjf1zsP4cbddr7zsP4cbddrk
TLSH T14F925C6916496C79BBC0DE7D9F3C7F0CADE8C1C02218A3ACBA4F39715A2069DDA0535D
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Gathering data
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=58139d7a-1a00-0000-ddd2-dda4b10b0000 pid=2993 /usr/bin/sudo guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998 /tmp/sample.bin guuid=58139d7a-1a00-0000-ddd2-dda4b10b0000 pid=2993->guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998 execve guuid=6bbbee7d-1a00-0000-ddd2-dda4b70b0000 pid=2999 /usr/bin/bash guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=6bbbee7d-1a00-0000-ddd2-dda4b70b0000 pid=2999 clone guuid=60b0f97d-1a00-0000-ddd2-dda4b80b0000 pid=3000 /usr/bin/bash guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=60b0f97d-1a00-0000-ddd2-dda4b80b0000 pid=3000 clone guuid=fa2d627e-1a00-0000-ddd2-dda4ba0b0000 pid=3002 /usr/bin/mkdir guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=fa2d627e-1a00-0000-ddd2-dda4ba0b0000 pid=3002 execve guuid=0b0ecf7e-1a00-0000-ddd2-dda4bc0b0000 pid=3004 /usr/bin/mkdir guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=0b0ecf7e-1a00-0000-ddd2-dda4bc0b0000 pid=3004 execve guuid=f879587f-1a00-0000-ddd2-dda4be0b0000 pid=3006 /usr/bin/mkdir guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=f879587f-1a00-0000-ddd2-dda4be0b0000 pid=3006 execve guuid=2378f37f-1a00-0000-ddd2-dda4c00b0000 pid=3008 /usr/bin/mkdir guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=2378f37f-1a00-0000-ddd2-dda4c00b0000 pid=3008 execve guuid=429f7c80-1a00-0000-ddd2-dda4c30b0000 pid=3011 /usr/bin/mkdir guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=429f7c80-1a00-0000-ddd2-dda4c30b0000 pid=3011 execve guuid=4179f880-1a00-0000-ddd2-dda4c50b0000 pid=3013 /usr/bin/mkdir guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=4179f880-1a00-0000-ddd2-dda4c50b0000 pid=3013 execve guuid=b5ae7d81-1a00-0000-ddd2-dda4c60b0000 pid=3014 /usr/bin/mkdir guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=b5ae7d81-1a00-0000-ddd2-dda4c60b0000 pid=3014 execve guuid=15b60882-1a00-0000-ddd2-dda4c70b0000 pid=3015 /usr/bin/cp guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=15b60882-1a00-0000-ddd2-dda4c70b0000 pid=3015 execve guuid=c93daa82-1a00-0000-ddd2-dda4c80b0000 pid=3016 /usr/bin/cp guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=c93daa82-1a00-0000-ddd2-dda4c80b0000 pid=3016 execve guuid=53a52f83-1a00-0000-ddd2-dda4ca0b0000 pid=3018 /usr/bin/cp guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=53a52f83-1a00-0000-ddd2-dda4ca0b0000 pid=3018 execve guuid=2d6c8583-1a00-0000-ddd2-dda4cc0b0000 pid=3020 /usr/bin/cp guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=2d6c8583-1a00-0000-ddd2-dda4cc0b0000 pid=3020 execve guuid=510ea384-1a00-0000-ddd2-dda4d00b0000 pid=3024 /usr/bin/cp guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=510ea384-1a00-0000-ddd2-dda4d00b0000 pid=3024 execve guuid=e27a6685-1a00-0000-ddd2-dda4d30b0000 pid=3027 /usr/bin/cp guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=e27a6685-1a00-0000-ddd2-dda4d30b0000 pid=3027 execve guuid=3e821586-1a00-0000-ddd2-dda4d60b0000 pid=3030 /usr/bin/cp guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=3e821586-1a00-0000-ddd2-dda4d60b0000 pid=3030 execve guuid=c29a7986-1a00-0000-ddd2-dda4d70b0000 pid=3031 /usr/bin/cp guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=c29a7986-1a00-0000-ddd2-dda4d70b0000 pid=3031 execve guuid=3391fe86-1a00-0000-ddd2-dda4d90b0000 pid=3033 /usr/bin/cp guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=3391fe86-1a00-0000-ddd2-dda4d90b0000 pid=3033 execve guuid=19718a87-1a00-0000-ddd2-dda4db0b0000 pid=3035 /usr/bin/cp guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=19718a87-1a00-0000-ddd2-dda4db0b0000 pid=3035 execve guuid=03c82b88-1a00-0000-ddd2-dda4dd0b0000 pid=3037 /usr/bin/cp guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=03c82b88-1a00-0000-ddd2-dda4dd0b0000 pid=3037 execve guuid=7133e488-1a00-0000-ddd2-dda4e00b0000 pid=3040 /usr/bin/cp guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=7133e488-1a00-0000-ddd2-dda4e00b0000 pid=3040 execve guuid=ae86a189-1a00-0000-ddd2-dda4e30b0000 pid=3043 /usr/bin/cp guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=ae86a189-1a00-0000-ddd2-dda4e30b0000 pid=3043 execve guuid=04f11f8a-1a00-0000-ddd2-dda4e50b0000 pid=3045 /usr/bin/cp guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=04f11f8a-1a00-0000-ddd2-dda4e50b0000 pid=3045 execve guuid=21a6c28a-1a00-0000-ddd2-dda4e80b0000 pid=3048 /usr/bin/cp guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=21a6c28a-1a00-0000-ddd2-dda4e80b0000 pid=3048 execve guuid=1452888b-1a00-0000-ddd2-dda4eb0b0000 pid=3051 /usr/bin/touch guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=1452888b-1a00-0000-ddd2-dda4eb0b0000 pid=3051 execve guuid=f320d18b-1a00-0000-ddd2-dda4ed0b0000 pid=3053 /usr/bin/bash guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=f320d18b-1a00-0000-ddd2-dda4ed0b0000 pid=3053 clone guuid=5df1d88b-1a00-0000-ddd2-dda4ee0b0000 pid=3054 /usr/bin/bash guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=5df1d88b-1a00-0000-ddd2-dda4ee0b0000 pid=3054 clone guuid=a6e4f88b-1a00-0000-ddd2-dda4ef0b0000 pid=3055 /usr/bin/bash guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=a6e4f88b-1a00-0000-ddd2-dda4ef0b0000 pid=3055 clone guuid=8b65008c-1a00-0000-ddd2-dda4f00b0000 pid=3056 /usr/bin/base64 write-file guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=8b65008c-1a00-0000-ddd2-dda4f00b0000 pid=3056 execve guuid=4b8bb18c-1a00-0000-ddd2-dda4f30b0000 pid=3059 /usr/bin/bash guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=4b8bb18c-1a00-0000-ddd2-dda4f30b0000 pid=3059 execve guuid=03aacc93-1a00-0000-ddd2-dda4170c0000 pid=3095 /usr/bin/rm delete-file guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=03aacc93-1a00-0000-ddd2-dda4170c0000 pid=3095 execve guuid=92af2994-1a00-0000-ddd2-dda4190c0000 pid=3097 /usr/bin/bash guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=92af2994-1a00-0000-ddd2-dda4190c0000 pid=3097 clone guuid=3cd53594-1a00-0000-ddd2-dda41a0c0000 pid=3098 /usr/bin/bash guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=3cd53594-1a00-0000-ddd2-dda41a0c0000 pid=3098 clone guuid=2da56d94-1a00-0000-ddd2-dda41c0c0000 pid=3100 /usr/bin/bash guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=2da56d94-1a00-0000-ddd2-dda41c0c0000 pid=3100 execve guuid=c4171395-1a00-0000-ddd2-dda41e0c0000 pid=3102 /usr/bin/rm guuid=da207e7d-1a00-0000-ddd2-dda4b60b0000 pid=2998->guuid=c4171395-1a00-0000-ddd2-dda41e0c0000 pid=3102 execve guuid=4f48108d-1a00-0000-ddd2-dda4f50b0000 pid=3061 /usr/bin/bash guuid=4b8bb18c-1a00-0000-ddd2-dda4f30b0000 pid=3059->guuid=4f48108d-1a00-0000-ddd2-dda4f50b0000 pid=3061 clone guuid=19c7208d-1a00-0000-ddd2-dda4f60b0000 pid=3062 /usr/bin/bash guuid=4b8bb18c-1a00-0000-ddd2-dda4f30b0000 pid=3059->guuid=19c7208d-1a00-0000-ddd2-dda4f60b0000 pid=3062 clone guuid=1c18428d-1a00-0000-ddd2-dda4f80b0000 pid=3064 /usr/bin/ls guuid=4b8bb18c-1a00-0000-ddd2-dda4f30b0000 pid=3059->guuid=1c18428d-1a00-0000-ddd2-dda4f80b0000 pid=3064 execve guuid=353f028e-1a00-0000-ddd2-dda4fb0b0000 pid=3067 /usr/bin/cat guuid=4b8bb18c-1a00-0000-ddd2-dda4f30b0000 pid=3059->guuid=353f028e-1a00-0000-ddd2-dda4fb0b0000 pid=3067 execve guuid=0946608e-1a00-0000-ddd2-dda4fd0b0000 pid=3069 /usr/bin/ls guuid=4b8bb18c-1a00-0000-ddd2-dda4f30b0000 pid=3059->guuid=0946608e-1a00-0000-ddd2-dda4fd0b0000 pid=3069 execve guuid=001ced8e-1a00-0000-ddd2-dda4ff0b0000 pid=3071 /usr/bin/mkdir guuid=4b8bb18c-1a00-0000-ddd2-dda4f30b0000 pid=3059->guuid=001ced8e-1a00-0000-ddd2-dda4ff0b0000 pid=3071 execve guuid=f906468f-1a00-0000-ddd2-dda4010c0000 pid=3073 /usr/bin/mv guuid=4b8bb18c-1a00-0000-ddd2-dda4f30b0000 pid=3059->guuid=f906468f-1a00-0000-ddd2-dda4010c0000 pid=3073 execve guuid=75b6d48f-1a00-0000-ddd2-dda4030c0000 pid=3075 /usr/bin/bash guuid=4b8bb18c-1a00-0000-ddd2-dda4f30b0000 pid=3059->guuid=75b6d48f-1a00-0000-ddd2-dda4030c0000 pid=3075 clone guuid=c6fddd8f-1a00-0000-ddd2-dda4050c0000 pid=3077 /usr/bin/base64 write-file guuid=4b8bb18c-1a00-0000-ddd2-dda4f30b0000 pid=3059->guuid=c6fddd8f-1a00-0000-ddd2-dda4050c0000 pid=3077 execve guuid=6291b890-1a00-0000-ddd2-dda4080c0000 pid=3080 /usr/bin/rm delete-file guuid=4b8bb18c-1a00-0000-ddd2-dda4f30b0000 pid=3059->guuid=6291b890-1a00-0000-ddd2-dda4080c0000 pid=3080 execve guuid=33d41c91-1a00-0000-ddd2-dda40a0c0000 pid=3082 /usr/bin/ls guuid=4b8bb18c-1a00-0000-ddd2-dda4f30b0000 pid=3059->guuid=33d41c91-1a00-0000-ddd2-dda40a0c0000 pid=3082 execve guuid=1019b791-1a00-0000-ddd2-dda40c0c0000 pid=3084 /usr/bin/bash guuid=4b8bb18c-1a00-0000-ddd2-dda4f30b0000 pid=3059->guuid=1019b791-1a00-0000-ddd2-dda40c0c0000 pid=3084 clone guuid=bff8c291-1a00-0000-ddd2-dda40d0c0000 pid=3085 /usr/bin/base64 write-file guuid=4b8bb18c-1a00-0000-ddd2-dda4f30b0000 pid=3059->guuid=bff8c291-1a00-0000-ddd2-dda40d0c0000 pid=3085 execve guuid=5a582492-1a00-0000-ddd2-dda4100c0000 pid=3088 /usr/bin/ls guuid=4b8bb18c-1a00-0000-ddd2-dda4f30b0000 pid=3059->guuid=5a582492-1a00-0000-ddd2-dda4100c0000 pid=3088 execve guuid=df19da92-1a00-0000-ddd2-dda4130c0000 pid=3091 /usr/bin/cat guuid=4b8bb18c-1a00-0000-ddd2-dda4f30b0000 pid=3059->guuid=df19da92-1a00-0000-ddd2-dda4130c0000 pid=3091 execve guuid=8b443493-1a00-0000-ddd2-dda4140c0000 pid=3092 /usr/bin/ls guuid=4b8bb18c-1a00-0000-ddd2-dda4f30b0000 pid=3059->guuid=8b443493-1a00-0000-ddd2-dda4140c0000 pid=3092 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Heuristic
Status:
Malicious
First seen:
2026-03-18 02:31:22 UTC
File Type:
Text (Shell)
AV detection:
11 of 36 (30.56%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh d924b2a40dd826c90a115240bac6eba1edbc725adbea5b2fbe193e0facd90e55

(this sample)

  
Delivery method
Distributed via web download

Comments