MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 db9bde40fa2a5f140366f151060fcd3c3b1f46ac381ebbdbc2c6dfd26d8c6862. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: db9bde40fa2a5f140366f151060fcd3c3b1f46ac381ebbdbc2c6dfd26d8c6862
SHA3-384 hash: 9fa3fd91dd507cb1090f3a8666a50a0579d1930b6b8a42b9072a6e9a01f4f2b7de08263afaf26238117434cbdab44caa
SHA1 hash: 2b7122d3eb4e941d3dbad424587b878ceac94ae4
MD5 hash: a0cab8a6e36ffc45f96d83c1ce96feb2
humanhash: finch-eleven-mexico-twelve
File name:k.php
Download: download sample
File size:19'491 bytes
First seen:2026-03-12 08:13:10 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:5JncuxOLnVYMStzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:5yuQL+tzsP4cbddr7zsP4cbddrk
TLSH T19C924CB506497C79BBC0CE799F3C7F0CAEE482C42129E39DBA1F3A705A2065DC609359
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Gathering data
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=ae2a92fc-1600-0000-05df-ff9c200e0000 pid=3616 /usr/bin/sudo guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628 /tmp/sample.bin guuid=ae2a92fc-1600-0000-05df-ff9c200e0000 pid=3616->guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628 execve guuid=2e38ee00-1700-0000-05df-ff9c2e0e0000 pid=3630 /usr/bin/bash guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=2e38ee00-1700-0000-05df-ff9c2e0e0000 pid=3630 clone guuid=9025fd00-1700-0000-05df-ff9c300e0000 pid=3632 /usr/bin/bash guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=9025fd00-1700-0000-05df-ff9c300e0000 pid=3632 clone guuid=14dc3201-1700-0000-05df-ff9c310e0000 pid=3633 /usr/bin/mkdir guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=14dc3201-1700-0000-05df-ff9c310e0000 pid=3633 execve guuid=eb04b101-1700-0000-05df-ff9c330e0000 pid=3635 /usr/bin/mkdir guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=eb04b101-1700-0000-05df-ff9c330e0000 pid=3635 execve guuid=c7b51b02-1700-0000-05df-ff9c340e0000 pid=3636 /usr/bin/mkdir guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=c7b51b02-1700-0000-05df-ff9c340e0000 pid=3636 execve guuid=d09b8802-1700-0000-05df-ff9c380e0000 pid=3640 /usr/bin/mkdir guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=d09b8802-1700-0000-05df-ff9c380e0000 pid=3640 execve guuid=b0dd0103-1700-0000-05df-ff9c3c0e0000 pid=3644 /usr/bin/mkdir guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=b0dd0103-1700-0000-05df-ff9c3c0e0000 pid=3644 execve guuid=ca407503-1700-0000-05df-ff9c3e0e0000 pid=3646 /usr/bin/mkdir guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=ca407503-1700-0000-05df-ff9c3e0e0000 pid=3646 execve guuid=b4c3de03-1700-0000-05df-ff9c400e0000 pid=3648 /usr/bin/mkdir guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=b4c3de03-1700-0000-05df-ff9c400e0000 pid=3648 execve guuid=37b04804-1700-0000-05df-ff9c430e0000 pid=3651 /usr/bin/cp guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=37b04804-1700-0000-05df-ff9c430e0000 pid=3651 execve guuid=6258e404-1700-0000-05df-ff9c460e0000 pid=3654 /usr/bin/cp guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=6258e404-1700-0000-05df-ff9c460e0000 pid=3654 execve guuid=51808105-1700-0000-05df-ff9c490e0000 pid=3657 /usr/bin/cp guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=51808105-1700-0000-05df-ff9c490e0000 pid=3657 execve guuid=b8571906-1700-0000-05df-ff9c4d0e0000 pid=3661 /usr/bin/cp guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=b8571906-1700-0000-05df-ff9c4d0e0000 pid=3661 execve guuid=9707bc06-1700-0000-05df-ff9c4e0e0000 pid=3662 /usr/bin/cp guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=9707bc06-1700-0000-05df-ff9c4e0e0000 pid=3662 execve guuid=2e347307-1700-0000-05df-ff9c520e0000 pid=3666 /usr/bin/cp guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=2e347307-1700-0000-05df-ff9c520e0000 pid=3666 execve guuid=12f6fa07-1700-0000-05df-ff9c540e0000 pid=3668 /usr/bin/cp guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=12f6fa07-1700-0000-05df-ff9c540e0000 pid=3668 execve guuid=7fd17808-1700-0000-05df-ff9c560e0000 pid=3670 /usr/bin/cp guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=7fd17808-1700-0000-05df-ff9c560e0000 pid=3670 execve guuid=6ab2f708-1700-0000-05df-ff9c590e0000 pid=3673 /usr/bin/cp guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=6ab2f708-1700-0000-05df-ff9c590e0000 pid=3673 execve guuid=dc2f9009-1700-0000-05df-ff9c5b0e0000 pid=3675 /usr/bin/cp guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=dc2f9009-1700-0000-05df-ff9c5b0e0000 pid=3675 execve guuid=e7741f0a-1700-0000-05df-ff9c5d0e0000 pid=3677 /usr/bin/cp guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=e7741f0a-1700-0000-05df-ff9c5d0e0000 pid=3677 execve guuid=6728b20a-1700-0000-05df-ff9c5e0e0000 pid=3678 /usr/bin/cp guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=6728b20a-1700-0000-05df-ff9c5e0e0000 pid=3678 execve guuid=81b04f0b-1700-0000-05df-ff9c5f0e0000 pid=3679 /usr/bin/cp guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=81b04f0b-1700-0000-05df-ff9c5f0e0000 pid=3679 execve guuid=fe6be20b-1700-0000-05df-ff9c600e0000 pid=3680 /usr/bin/cp guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=fe6be20b-1700-0000-05df-ff9c600e0000 pid=3680 execve guuid=619a870c-1700-0000-05df-ff9c610e0000 pid=3681 /usr/bin/cp guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=619a870c-1700-0000-05df-ff9c610e0000 pid=3681 execve guuid=584c250d-1700-0000-05df-ff9c650e0000 pid=3685 /usr/bin/touch guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=584c250d-1700-0000-05df-ff9c650e0000 pid=3685 execve guuid=5f45a10d-1700-0000-05df-ff9c660e0000 pid=3686 /usr/bin/bash guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=5f45a10d-1700-0000-05df-ff9c660e0000 pid=3686 clone guuid=1c12a90d-1700-0000-05df-ff9c670e0000 pid=3687 /usr/bin/bash guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=1c12a90d-1700-0000-05df-ff9c670e0000 pid=3687 clone guuid=7da9de0d-1700-0000-05df-ff9c6b0e0000 pid=3691 /usr/bin/bash guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=7da9de0d-1700-0000-05df-ff9c6b0e0000 pid=3691 clone guuid=904ae60d-1700-0000-05df-ff9c6c0e0000 pid=3692 /usr/bin/base64 write-file guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=904ae60d-1700-0000-05df-ff9c6c0e0000 pid=3692 execve guuid=2469bc0e-1700-0000-05df-ff9c6e0e0000 pid=3694 /usr/bin/bash guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=2469bc0e-1700-0000-05df-ff9c6e0e0000 pid=3694 execve guuid=b43a6f16-1700-0000-05df-ff9c900e0000 pid=3728 /usr/bin/rm delete-file guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=b43a6f16-1700-0000-05df-ff9c900e0000 pid=3728 execve guuid=bfc8ce16-1700-0000-05df-ff9c920e0000 pid=3730 /usr/bin/bash guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=bfc8ce16-1700-0000-05df-ff9c920e0000 pid=3730 clone guuid=ba38d716-1700-0000-05df-ff9c930e0000 pid=3731 /usr/bin/bash guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=ba38d716-1700-0000-05df-ff9c930e0000 pid=3731 clone guuid=84231617-1700-0000-05df-ff9c950e0000 pid=3733 /usr/bin/bash guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=84231617-1700-0000-05df-ff9c950e0000 pid=3733 execve guuid=63908a17-1700-0000-05df-ff9c960e0000 pid=3734 /usr/bin/rm guuid=7c155f00-1700-0000-05df-ff9c2c0e0000 pid=3628->guuid=63908a17-1700-0000-05df-ff9c960e0000 pid=3734 execve guuid=7bc02c0f-1700-0000-05df-ff9c710e0000 pid=3697 /usr/bin/bash guuid=2469bc0e-1700-0000-05df-ff9c6e0e0000 pid=3694->guuid=7bc02c0f-1700-0000-05df-ff9c710e0000 pid=3697 clone guuid=1fe2500f-1700-0000-05df-ff9c720e0000 pid=3698 /usr/bin/bash guuid=2469bc0e-1700-0000-05df-ff9c6e0e0000 pid=3694->guuid=1fe2500f-1700-0000-05df-ff9c720e0000 pid=3698 clone guuid=fe0dd80f-1700-0000-05df-ff9c750e0000 pid=3701 /usr/bin/ls guuid=2469bc0e-1700-0000-05df-ff9c6e0e0000 pid=3694->guuid=fe0dd80f-1700-0000-05df-ff9c750e0000 pid=3701 execve guuid=bcf47610-1700-0000-05df-ff9c770e0000 pid=3703 /usr/bin/cat guuid=2469bc0e-1700-0000-05df-ff9c6e0e0000 pid=3694->guuid=bcf47610-1700-0000-05df-ff9c770e0000 pid=3703 execve guuid=b87ae610-1700-0000-05df-ff9c780e0000 pid=3704 /usr/bin/ls guuid=2469bc0e-1700-0000-05df-ff9c6e0e0000 pid=3694->guuid=b87ae610-1700-0000-05df-ff9c780e0000 pid=3704 execve guuid=55b28311-1700-0000-05df-ff9c790e0000 pid=3705 /usr/bin/mkdir guuid=2469bc0e-1700-0000-05df-ff9c6e0e0000 pid=3694->guuid=55b28311-1700-0000-05df-ff9c790e0000 pid=3705 execve guuid=f00c0612-1700-0000-05df-ff9c7a0e0000 pid=3706 /usr/bin/mv guuid=2469bc0e-1700-0000-05df-ff9c6e0e0000 pid=3694->guuid=f00c0612-1700-0000-05df-ff9c7a0e0000 pid=3706 execve guuid=aca1ab12-1700-0000-05df-ff9c7b0e0000 pid=3707 /usr/bin/bash guuid=2469bc0e-1700-0000-05df-ff9c6e0e0000 pid=3694->guuid=aca1ab12-1700-0000-05df-ff9c7b0e0000 pid=3707 clone guuid=3815b312-1700-0000-05df-ff9c7c0e0000 pid=3708 /usr/bin/base64 write-file guuid=2469bc0e-1700-0000-05df-ff9c6e0e0000 pid=3694->guuid=3815b312-1700-0000-05df-ff9c7c0e0000 pid=3708 execve guuid=05044c13-1700-0000-05df-ff9c800e0000 pid=3712 /usr/bin/rm delete-file guuid=2469bc0e-1700-0000-05df-ff9c6e0e0000 pid=3694->guuid=05044c13-1700-0000-05df-ff9c800e0000 pid=3712 execve guuid=0345d313-1700-0000-05df-ff9c810e0000 pid=3713 /usr/bin/ls guuid=2469bc0e-1700-0000-05df-ff9c6e0e0000 pid=3694->guuid=0345d313-1700-0000-05df-ff9c810e0000 pid=3713 execve guuid=80f56514-1700-0000-05df-ff9c850e0000 pid=3717 /usr/bin/bash guuid=2469bc0e-1700-0000-05df-ff9c6e0e0000 pid=3694->guuid=80f56514-1700-0000-05df-ff9c850e0000 pid=3717 clone guuid=0d2c6e14-1700-0000-05df-ff9c860e0000 pid=3718 /usr/bin/base64 write-file guuid=2469bc0e-1700-0000-05df-ff9c6e0e0000 pid=3694->guuid=0d2c6e14-1700-0000-05df-ff9c860e0000 pid=3718 execve guuid=0de2e114-1700-0000-05df-ff9c880e0000 pid=3720 /usr/bin/ls guuid=2469bc0e-1700-0000-05df-ff9c6e0e0000 pid=3694->guuid=0de2e114-1700-0000-05df-ff9c880e0000 pid=3720 execve guuid=c64c6d15-1700-0000-05df-ff9c8b0e0000 pid=3723 /usr/bin/cat guuid=2469bc0e-1700-0000-05df-ff9c6e0e0000 pid=3694->guuid=c64c6d15-1700-0000-05df-ff9c8b0e0000 pid=3723 execve guuid=a524ca15-1700-0000-05df-ff9c8d0e0000 pid=3725 /usr/bin/ls guuid=2469bc0e-1700-0000-05df-ff9c6e0e0000 pid=3694->guuid=a524ca15-1700-0000-05df-ff9c8d0e0000 pid=3725 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-12 08:13:30 UTC
File Type:
Text (Shell)
AV detection:
10 of 23 (43.48%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh db9bde40fa2a5f140366f151060fcd3c3b1f46ac381ebbdbc2c6dfd26d8c6862

(this sample)

  
Delivery method
Distributed via web download

Comments