MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d9a0a0748cec6d9acaaba5178484b6ecc196afd1c1b22567525e22147ae85d47. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: d9a0a0748cec6d9acaaba5178484b6ecc196afd1c1b22567525e22147ae85d47
SHA3-384 hash: d6eca36650015c9f27fd4d6257589dd33970b1901e1683975ce35e4df1b8deda49562d91ac1d0b79daf4995e513a227c
SHA1 hash: e2604dafb38c751ddbaad2cba38945dab885fe08
MD5 hash: 94941daac5900296d32a9b5a3eda6c4e
humanhash: edward-michigan-blue-potato
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-20 04:25:29 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:bFcuQpWx+BL0SWL0grzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:bF8i+BL0SI08zsP4cbddr7zsP4cbddrk
TLSH T126925DB512896C79FBD1CE39AF3C6F4CADE8C2C42124A3ACBA4F39215A1166DC70535D
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=8e38a8cd-1600-0000-3962-f88dc20d0000 pid=3522 /usr/bin/sudo guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524 /tmp/sample.bin guuid=8e38a8cd-1600-0000-3962-f88dc20d0000 pid=3522->guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524 execve guuid=2e5124d0-1600-0000-3962-f88dc50d0000 pid=3525 /usr/bin/bash guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=2e5124d0-1600-0000-3962-f88dc50d0000 pid=3525 clone guuid=7e822cd0-1600-0000-3962-f88dc60d0000 pid=3526 /usr/bin/bash guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=7e822cd0-1600-0000-3962-f88dc60d0000 pid=3526 clone guuid=654f66d0-1600-0000-3962-f88dc70d0000 pid=3527 /usr/bin/mkdir guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=654f66d0-1600-0000-3962-f88dc70d0000 pid=3527 execve guuid=f41ac3d0-1600-0000-3962-f88dc80d0000 pid=3528 /usr/bin/mkdir guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=f41ac3d0-1600-0000-3962-f88dc80d0000 pid=3528 execve guuid=019311d1-1600-0000-3962-f88dca0d0000 pid=3530 /usr/bin/mkdir guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=019311d1-1600-0000-3962-f88dca0d0000 pid=3530 execve guuid=b1bd5bd1-1600-0000-3962-f88dcc0d0000 pid=3532 /usr/bin/mkdir guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=b1bd5bd1-1600-0000-3962-f88dcc0d0000 pid=3532 execve guuid=c2e5add1-1600-0000-3962-f88dcf0d0000 pid=3535 /usr/bin/mkdir guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=c2e5add1-1600-0000-3962-f88dcf0d0000 pid=3535 execve guuid=305707d2-1600-0000-3962-f88dd10d0000 pid=3537 /usr/bin/mkdir guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=305707d2-1600-0000-3962-f88dd10d0000 pid=3537 execve guuid=034563d2-1600-0000-3962-f88dd30d0000 pid=3539 /usr/bin/mkdir guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=034563d2-1600-0000-3962-f88dd30d0000 pid=3539 execve guuid=a4aec0d2-1600-0000-3962-f88dd50d0000 pid=3541 /usr/bin/cp guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=a4aec0d2-1600-0000-3962-f88dd50d0000 pid=3541 execve guuid=287a2fd3-1600-0000-3962-f88dd70d0000 pid=3543 /usr/bin/cp guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=287a2fd3-1600-0000-3962-f88dd70d0000 pid=3543 execve guuid=e32894d3-1600-0000-3962-f88dd80d0000 pid=3544 /usr/bin/cp guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=e32894d3-1600-0000-3962-f88dd80d0000 pid=3544 execve guuid=6fedf2d3-1600-0000-3962-f88dda0d0000 pid=3546 /usr/bin/cp guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=6fedf2d3-1600-0000-3962-f88dda0d0000 pid=3546 execve guuid=1af74cd4-1600-0000-3962-f88ddc0d0000 pid=3548 /usr/bin/cp guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=1af74cd4-1600-0000-3962-f88ddc0d0000 pid=3548 execve guuid=a913a3d4-1600-0000-3962-f88dde0d0000 pid=3550 /usr/bin/cp guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=a913a3d4-1600-0000-3962-f88dde0d0000 pid=3550 execve guuid=8e3e03d5-1600-0000-3962-f88de00d0000 pid=3552 /usr/bin/cp guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=8e3e03d5-1600-0000-3962-f88de00d0000 pid=3552 execve guuid=584353d5-1600-0000-3962-f88de20d0000 pid=3554 /usr/bin/cp guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=584353d5-1600-0000-3962-f88de20d0000 pid=3554 execve guuid=042da7d5-1600-0000-3962-f88de40d0000 pid=3556 /usr/bin/cp guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=042da7d5-1600-0000-3962-f88de40d0000 pid=3556 execve guuid=a7a81dd6-1600-0000-3962-f88de70d0000 pid=3559 /usr/bin/cp guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=a7a81dd6-1600-0000-3962-f88de70d0000 pid=3559 execve guuid=bc566fd6-1600-0000-3962-f88de90d0000 pid=3561 /usr/bin/cp guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=bc566fd6-1600-0000-3962-f88de90d0000 pid=3561 execve guuid=433aead6-1600-0000-3962-f88dec0d0000 pid=3564 /usr/bin/cp guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=433aead6-1600-0000-3962-f88dec0d0000 pid=3564 execve guuid=27c668d7-1600-0000-3962-f88def0d0000 pid=3567 /usr/bin/cp guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=27c668d7-1600-0000-3962-f88def0d0000 pid=3567 execve guuid=2ea8dcd7-1600-0000-3962-f88df10d0000 pid=3569 /usr/bin/cp guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=2ea8dcd7-1600-0000-3962-f88df10d0000 pid=3569 execve guuid=ff6937d8-1600-0000-3962-f88df40d0000 pid=3572 /usr/bin/cp guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=ff6937d8-1600-0000-3962-f88df40d0000 pid=3572 execve guuid=681eb1d8-1600-0000-3962-f88df70d0000 pid=3575 /usr/bin/touch guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=681eb1d8-1600-0000-3962-f88df70d0000 pid=3575 execve guuid=784500d9-1600-0000-3962-f88df90d0000 pid=3577 /usr/bin/bash guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=784500d9-1600-0000-3962-f88df90d0000 pid=3577 clone guuid=40b906d9-1600-0000-3962-f88dfa0d0000 pid=3578 /usr/bin/bash guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=40b906d9-1600-0000-3962-f88dfa0d0000 pid=3578 clone guuid=e81b28d9-1600-0000-3962-f88dfb0d0000 pid=3579 /usr/bin/bash guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=e81b28d9-1600-0000-3962-f88dfb0d0000 pid=3579 clone guuid=b2852ed9-1600-0000-3962-f88dfd0d0000 pid=3581 /usr/bin/base64 write-file guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=b2852ed9-1600-0000-3962-f88dfd0d0000 pid=3581 execve guuid=21c7d5d9-1600-0000-3962-f88d020e0000 pid=3586 /usr/bin/bash guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=21c7d5d9-1600-0000-3962-f88d020e0000 pid=3586 execve guuid=a3f2d5de-1600-0000-3962-f88d200e0000 pid=3616 /usr/bin/rm delete-file guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=a3f2d5de-1600-0000-3962-f88d200e0000 pid=3616 execve guuid=28c81edf-1600-0000-3962-f88d230e0000 pid=3619 /usr/bin/bash guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=28c81edf-1600-0000-3962-f88d230e0000 pid=3619 clone guuid=2d5524df-1600-0000-3962-f88d240e0000 pid=3620 /usr/bin/bash guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=2d5524df-1600-0000-3962-f88d240e0000 pid=3620 clone guuid=618b41df-1600-0000-3962-f88d250e0000 pid=3621 /usr/bin/bash guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=618b41df-1600-0000-3962-f88d250e0000 pid=3621 execve guuid=a67e8edf-1600-0000-3962-f88d270e0000 pid=3623 /usr/bin/rm guuid=18feb7cf-1600-0000-3962-f88dc40d0000 pid=3524->guuid=a67e8edf-1600-0000-3962-f88d270e0000 pid=3623 execve guuid=93532fda-1600-0000-3962-f88d040e0000 pid=3588 /usr/bin/bash guuid=21c7d5d9-1600-0000-3962-f88d020e0000 pid=3586->guuid=93532fda-1600-0000-3962-f88d040e0000 pid=3588 clone guuid=da8c35da-1600-0000-3962-f88d050e0000 pid=3589 /usr/bin/bash guuid=21c7d5d9-1600-0000-3962-f88d020e0000 pid=3586->guuid=da8c35da-1600-0000-3962-f88d050e0000 pid=3589 clone guuid=dfb84dda-1600-0000-3962-f88d060e0000 pid=3590 /usr/bin/ls guuid=21c7d5d9-1600-0000-3962-f88d020e0000 pid=3586->guuid=dfb84dda-1600-0000-3962-f88d060e0000 pid=3590 execve guuid=845bbcda-1600-0000-3962-f88d080e0000 pid=3592 /usr/bin/cat guuid=21c7d5d9-1600-0000-3962-f88d020e0000 pid=3586->guuid=845bbcda-1600-0000-3962-f88d080e0000 pid=3592 execve guuid=0abf07db-1600-0000-3962-f88d090e0000 pid=3593 /usr/bin/ls guuid=21c7d5d9-1600-0000-3962-f88d020e0000 pid=3586->guuid=0abf07db-1600-0000-3962-f88d090e0000 pid=3593 execve guuid=46c781db-1600-0000-3962-f88d0c0e0000 pid=3596 /usr/bin/mkdir guuid=21c7d5d9-1600-0000-3962-f88d020e0000 pid=3586->guuid=46c781db-1600-0000-3962-f88d0c0e0000 pid=3596 execve guuid=2399eddb-1600-0000-3962-f88d0e0e0000 pid=3598 /usr/bin/mv guuid=21c7d5d9-1600-0000-3962-f88d020e0000 pid=3586->guuid=2399eddb-1600-0000-3962-f88d0e0e0000 pid=3598 execve guuid=d36856dc-1600-0000-3962-f88d100e0000 pid=3600 /usr/bin/bash guuid=21c7d5d9-1600-0000-3962-f88d020e0000 pid=3586->guuid=d36856dc-1600-0000-3962-f88d100e0000 pid=3600 clone guuid=d2ab5ddc-1600-0000-3962-f88d110e0000 pid=3601 /usr/bin/base64 write-file guuid=21c7d5d9-1600-0000-3962-f88d020e0000 pid=3586->guuid=d2ab5ddc-1600-0000-3962-f88d110e0000 pid=3601 execve guuid=9979b2dc-1600-0000-3962-f88d130e0000 pid=3603 /usr/bin/rm delete-file guuid=21c7d5d9-1600-0000-3962-f88d020e0000 pid=3586->guuid=9979b2dc-1600-0000-3962-f88d130e0000 pid=3603 execve guuid=fa39fadc-1600-0000-3962-f88d150e0000 pid=3605 /usr/bin/ls guuid=21c7d5d9-1600-0000-3962-f88d020e0000 pid=3586->guuid=fa39fadc-1600-0000-3962-f88d150e0000 pid=3605 execve guuid=577e5add-1600-0000-3962-f88d170e0000 pid=3607 /usr/bin/bash guuid=21c7d5d9-1600-0000-3962-f88d020e0000 pid=3586->guuid=577e5add-1600-0000-3962-f88d170e0000 pid=3607 clone guuid=8fb361dd-1600-0000-3962-f88d180e0000 pid=3608 /usr/bin/base64 write-file guuid=21c7d5d9-1600-0000-3962-f88d020e0000 pid=3586->guuid=8fb361dd-1600-0000-3962-f88d180e0000 pid=3608 execve guuid=ffc3b2dd-1600-0000-3962-f88d1a0e0000 pid=3610 /usr/bin/ls guuid=21c7d5d9-1600-0000-3962-f88d020e0000 pid=3586->guuid=ffc3b2dd-1600-0000-3962-f88d1a0e0000 pid=3610 execve guuid=2c4b0ede-1600-0000-3962-f88d1c0e0000 pid=3612 /usr/bin/cat guuid=21c7d5d9-1600-0000-3962-f88d020e0000 pid=3586->guuid=2c4b0ede-1600-0000-3962-f88d1c0e0000 pid=3612 execve guuid=56e25cde-1600-0000-3962-f88d1f0e0000 pid=3615 /usr/bin/ls guuid=21c7d5d9-1600-0000-3962-f88d020e0000 pid=3586->guuid=56e25cde-1600-0000-3962-f88d1f0e0000 pid=3615 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-20 04:26:22 UTC
File Type:
Text (Shell)
AV detection:
12 of 23 (52.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh d9a0a0748cec6d9acaaba5178484b6ecc196afd1c1b22567525e22147ae85d47

(this sample)

  
Delivery method
Distributed via web download

Comments