MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d97f4dc437525fd5a20043f03f5b9be19d5c9781d060e477e6b6e6da2e925fac. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: d97f4dc437525fd5a20043f03f5b9be19d5c9781d060e477e6b6e6da2e925fac
SHA3-384 hash: 8f8cde3e18b3d1423e34abbaafa758e2788ca5e56bf2aedeaee3e9021760fab0b7fbc1c5f17d860f04b2215a8c3ec66b
SHA1 hash: 69346922b6153c8f9d651d365b4b3c4cda6de668
MD5 hash: 0b68c8d6f22471371e0395b20098764a
humanhash: saturn-avocado-white-cat
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-19 21:27:38 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:TFcuQpWx+BL0SWL0gczsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:TF8i+BL0SI0vzsP4cbddr7zsP4cbddrk
TLSH T1C8925DB512896C79FBD1CE399F3C6F4CADE8C2C42124B3ACBA0F39205A1166DC705349
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
55
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=e69e731b-1700-0000-2ed1-2cb7550e0000 pid=3669 /usr/bin/sudo guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678 /tmp/sample.bin guuid=e69e731b-1700-0000-2ed1-2cb7550e0000 pid=3669->guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678 execve guuid=ae64291d-1700-0000-2ed1-2cb7610e0000 pid=3681 /usr/bin/bash guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=ae64291d-1700-0000-2ed1-2cb7610e0000 pid=3681 clone guuid=ec692e1d-1700-0000-2ed1-2cb7620e0000 pid=3682 /usr/bin/bash guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=ec692e1d-1700-0000-2ed1-2cb7620e0000 pid=3682 clone guuid=b8054b1d-1700-0000-2ed1-2cb7630e0000 pid=3683 /usr/bin/mkdir guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=b8054b1d-1700-0000-2ed1-2cb7630e0000 pid=3683 execve guuid=f0809e1d-1700-0000-2ed1-2cb7650e0000 pid=3685 /usr/bin/mkdir guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=f0809e1d-1700-0000-2ed1-2cb7650e0000 pid=3685 execve guuid=2cd5e81d-1700-0000-2ed1-2cb7680e0000 pid=3688 /usr/bin/mkdir guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=2cd5e81d-1700-0000-2ed1-2cb7680e0000 pid=3688 execve guuid=2634341e-1700-0000-2ed1-2cb76a0e0000 pid=3690 /usr/bin/mkdir guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=2634341e-1700-0000-2ed1-2cb76a0e0000 pid=3690 execve guuid=3dcd831e-1700-0000-2ed1-2cb76b0e0000 pid=3691 /usr/bin/mkdir guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=3dcd831e-1700-0000-2ed1-2cb76b0e0000 pid=3691 execve guuid=d9a4d21e-1700-0000-2ed1-2cb76e0e0000 pid=3694 /usr/bin/mkdir guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=d9a4d21e-1700-0000-2ed1-2cb76e0e0000 pid=3694 execve guuid=53d2231f-1700-0000-2ed1-2cb7700e0000 pid=3696 /usr/bin/mkdir guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=53d2231f-1700-0000-2ed1-2cb7700e0000 pid=3696 execve guuid=a0b6731f-1700-0000-2ed1-2cb7720e0000 pid=3698 /usr/bin/cp guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=a0b6731f-1700-0000-2ed1-2cb7720e0000 pid=3698 execve guuid=a2dbcc1f-1700-0000-2ed1-2cb7740e0000 pid=3700 /usr/bin/cp guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=a2dbcc1f-1700-0000-2ed1-2cb7740e0000 pid=3700 execve guuid=3ed82b20-1700-0000-2ed1-2cb7790e0000 pid=3705 /usr/bin/cp guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=3ed82b20-1700-0000-2ed1-2cb7790e0000 pid=3705 execve guuid=00ce9720-1700-0000-2ed1-2cb77a0e0000 pid=3706 /usr/bin/cp guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=00ce9720-1700-0000-2ed1-2cb77a0e0000 pid=3706 execve guuid=8954f320-1700-0000-2ed1-2cb77e0e0000 pid=3710 /usr/bin/cp guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=8954f320-1700-0000-2ed1-2cb77e0e0000 pid=3710 execve guuid=9a0e4b21-1700-0000-2ed1-2cb7820e0000 pid=3714 /usr/bin/cp guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=9a0e4b21-1700-0000-2ed1-2cb7820e0000 pid=3714 execve guuid=1345a621-1700-0000-2ed1-2cb7860e0000 pid=3718 /usr/bin/cp guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=1345a621-1700-0000-2ed1-2cb7860e0000 pid=3718 execve guuid=c10afe21-1700-0000-2ed1-2cb7870e0000 pid=3719 /usr/bin/cp guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=c10afe21-1700-0000-2ed1-2cb7870e0000 pid=3719 execve guuid=9fa85722-1700-0000-2ed1-2cb78b0e0000 pid=3723 /usr/bin/cp guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=9fa85722-1700-0000-2ed1-2cb78b0e0000 pid=3723 execve guuid=d925b722-1700-0000-2ed1-2cb78d0e0000 pid=3725 /usr/bin/cp guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=d925b722-1700-0000-2ed1-2cb78d0e0000 pid=3725 execve guuid=011c1323-1700-0000-2ed1-2cb7920e0000 pid=3730 /usr/bin/cp guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=011c1323-1700-0000-2ed1-2cb7920e0000 pid=3730 execve guuid=588a9623-1700-0000-2ed1-2cb7960e0000 pid=3734 /usr/bin/cp guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=588a9623-1700-0000-2ed1-2cb7960e0000 pid=3734 execve guuid=2c7fea23-1700-0000-2ed1-2cb7980e0000 pid=3736 /usr/bin/cp guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=2c7fea23-1700-0000-2ed1-2cb7980e0000 pid=3736 execve guuid=c2b73d24-1700-0000-2ed1-2cb79a0e0000 pid=3738 /usr/bin/cp guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=c2b73d24-1700-0000-2ed1-2cb79a0e0000 pid=3738 execve guuid=ba62a124-1700-0000-2ed1-2cb79e0e0000 pid=3742 /usr/bin/cp guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=ba62a124-1700-0000-2ed1-2cb79e0e0000 pid=3742 execve guuid=cfc9f024-1700-0000-2ed1-2cb7a20e0000 pid=3746 /usr/bin/touch guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=cfc9f024-1700-0000-2ed1-2cb7a20e0000 pid=3746 execve guuid=8f423e25-1700-0000-2ed1-2cb7a40e0000 pid=3748 /usr/bin/bash guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=8f423e25-1700-0000-2ed1-2cb7a40e0000 pid=3748 clone guuid=c4ee4425-1700-0000-2ed1-2cb7a50e0000 pid=3749 /usr/bin/bash guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=c4ee4425-1700-0000-2ed1-2cb7a50e0000 pid=3749 clone guuid=a2b46025-1700-0000-2ed1-2cb7a70e0000 pid=3751 /usr/bin/bash guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=a2b46025-1700-0000-2ed1-2cb7a70e0000 pid=3751 clone guuid=1ec16725-1700-0000-2ed1-2cb7a80e0000 pid=3752 /usr/bin/base64 write-file guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=1ec16725-1700-0000-2ed1-2cb7a80e0000 pid=3752 execve guuid=81c1ec25-1700-0000-2ed1-2cb7ac0e0000 pid=3756 /usr/bin/bash guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=81c1ec25-1700-0000-2ed1-2cb7ac0e0000 pid=3756 execve guuid=93fccc2a-1700-0000-2ed1-2cb7cf0e0000 pid=3791 /usr/bin/rm delete-file guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=93fccc2a-1700-0000-2ed1-2cb7cf0e0000 pid=3791 execve guuid=4dc4112b-1700-0000-2ed1-2cb7d10e0000 pid=3793 /usr/bin/bash guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=4dc4112b-1700-0000-2ed1-2cb7d10e0000 pid=3793 clone guuid=36dc172b-1700-0000-2ed1-2cb7d20e0000 pid=3794 /usr/bin/bash guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=36dc172b-1700-0000-2ed1-2cb7d20e0000 pid=3794 clone guuid=84cc332b-1700-0000-2ed1-2cb7d30e0000 pid=3795 /usr/bin/bash guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=84cc332b-1700-0000-2ed1-2cb7d30e0000 pid=3795 execve guuid=df837d2b-1700-0000-2ed1-2cb7d50e0000 pid=3797 /usr/bin/rm guuid=8ad0d21c-1700-0000-2ed1-2cb75e0e0000 pid=3678->guuid=df837d2b-1700-0000-2ed1-2cb7d50e0000 pid=3797 execve guuid=6d6f4026-1700-0000-2ed1-2cb7b00e0000 pid=3760 /usr/bin/bash guuid=81c1ec25-1700-0000-2ed1-2cb7ac0e0000 pid=3756->guuid=6d6f4026-1700-0000-2ed1-2cb7b00e0000 pid=3760 clone guuid=25074726-1700-0000-2ed1-2cb7b10e0000 pid=3761 /usr/bin/bash guuid=81c1ec25-1700-0000-2ed1-2cb7ac0e0000 pid=3756->guuid=25074726-1700-0000-2ed1-2cb7b10e0000 pid=3761 clone guuid=6b946426-1700-0000-2ed1-2cb7b30e0000 pid=3763 /usr/bin/ls guuid=81c1ec25-1700-0000-2ed1-2cb7ac0e0000 pid=3756->guuid=6b946426-1700-0000-2ed1-2cb7b30e0000 pid=3763 execve guuid=d6c3c426-1700-0000-2ed1-2cb7b50e0000 pid=3765 /usr/bin/cat guuid=81c1ec25-1700-0000-2ed1-2cb7ac0e0000 pid=3756->guuid=d6c3c426-1700-0000-2ed1-2cb7b50e0000 pid=3765 execve guuid=c76f0c27-1700-0000-2ed1-2cb7b90e0000 pid=3769 /usr/bin/ls guuid=81c1ec25-1700-0000-2ed1-2cb7ac0e0000 pid=3756->guuid=c76f0c27-1700-0000-2ed1-2cb7b90e0000 pid=3769 execve guuid=1016a427-1700-0000-2ed1-2cb7be0e0000 pid=3774 /usr/bin/mkdir guuid=81c1ec25-1700-0000-2ed1-2cb7ac0e0000 pid=3756->guuid=1016a427-1700-0000-2ed1-2cb7be0e0000 pid=3774 execve guuid=bc9ff127-1700-0000-2ed1-2cb7bf0e0000 pid=3775 /usr/bin/mv guuid=81c1ec25-1700-0000-2ed1-2cb7ac0e0000 pid=3756->guuid=bc9ff127-1700-0000-2ed1-2cb7bf0e0000 pid=3775 execve guuid=7b255328-1700-0000-2ed1-2cb7c10e0000 pid=3777 /usr/bin/bash guuid=81c1ec25-1700-0000-2ed1-2cb7ac0e0000 pid=3756->guuid=7b255328-1700-0000-2ed1-2cb7c10e0000 pid=3777 clone guuid=2fa25828-1700-0000-2ed1-2cb7c20e0000 pid=3778 /usr/bin/base64 write-file guuid=81c1ec25-1700-0000-2ed1-2cb7ac0e0000 pid=3756->guuid=2fa25828-1700-0000-2ed1-2cb7c20e0000 pid=3778 execve guuid=acf9a728-1700-0000-2ed1-2cb7c40e0000 pid=3780 /usr/bin/rm delete-file guuid=81c1ec25-1700-0000-2ed1-2cb7ac0e0000 pid=3756->guuid=acf9a728-1700-0000-2ed1-2cb7c40e0000 pid=3780 execve guuid=f727ea28-1700-0000-2ed1-2cb7c50e0000 pid=3781 /usr/bin/ls guuid=81c1ec25-1700-0000-2ed1-2cb7ac0e0000 pid=3756->guuid=f727ea28-1700-0000-2ed1-2cb7c50e0000 pid=3781 execve guuid=0c326729-1700-0000-2ed1-2cb7c70e0000 pid=3783 /usr/bin/bash guuid=81c1ec25-1700-0000-2ed1-2cb7ac0e0000 pid=3756->guuid=0c326729-1700-0000-2ed1-2cb7c70e0000 pid=3783 clone guuid=0e086d29-1700-0000-2ed1-2cb7c80e0000 pid=3784 /usr/bin/base64 write-file guuid=81c1ec25-1700-0000-2ed1-2cb7ac0e0000 pid=3756->guuid=0e086d29-1700-0000-2ed1-2cb7c80e0000 pid=3784 execve guuid=d795c529-1700-0000-2ed1-2cb7ca0e0000 pid=3786 /usr/bin/ls guuid=81c1ec25-1700-0000-2ed1-2cb7ac0e0000 pid=3756->guuid=d795c529-1700-0000-2ed1-2cb7ca0e0000 pid=3786 execve guuid=779d252a-1700-0000-2ed1-2cb7cb0e0000 pid=3787 /usr/bin/cat guuid=81c1ec25-1700-0000-2ed1-2cb7ac0e0000 pid=3756->guuid=779d252a-1700-0000-2ed1-2cb7cb0e0000 pid=3787 execve guuid=4822682a-1700-0000-2ed1-2cb7cd0e0000 pid=3789 /usr/bin/ls guuid=81c1ec25-1700-0000-2ed1-2cb7ac0e0000 pid=3756->guuid=4822682a-1700-0000-2ed1-2cb7cd0e0000 pid=3789 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-19 21:28:27 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh d97f4dc437525fd5a20043f03f5b9be19d5c9781d060e477e6b6e6da2e925fac

(this sample)

  
Delivery method
Distributed via web download

Comments