MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dc9ec8cc29b821abc61d2bb9275febf4237cfcd1b96b08b53796155c2a1c17f5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: dc9ec8cc29b821abc61d2bb9275febf4237cfcd1b96b08b53796155c2a1c17f5
SHA3-384 hash: 4b4c7c2bf9049e433a96c8211619b91c453f3f76a5c05ee6a0915eee520466de8da400dd4b96854b32069dca2e8bfae3
SHA1 hash: 74c00183304b408114e656027946d3ce363c4e97
MD5 hash: f826b2bf8e83d8ce787ecc81daebca36
humanhash: high-cup-butter-eighteen
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-19 02:29:31 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:hFcuQpWx+BL0SWL0gnzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:hF8i+BL0SI0YzsP4cbddr7zsP4cbddrk
TLSH T140925CB512896C79FBD0CE399F3C6F4DADE8C2C42124A3ACBA4F39215A1166DCB0535D
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Gathering data
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=78f66206-1800-0000-a17f-21fa1e0c0000 pid=3102 /usr/bin/sudo guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109 /tmp/sample.bin guuid=78f66206-1800-0000-a17f-21fa1e0c0000 pid=3102->guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109 execve guuid=5f987309-1800-0000-a17f-21fa280c0000 pid=3112 /usr/bin/bash guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=5f987309-1800-0000-a17f-21fa280c0000 pid=3112 clone guuid=db358509-1800-0000-a17f-21fa290c0000 pid=3113 /usr/bin/bash guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=db358509-1800-0000-a17f-21fa290c0000 pid=3113 clone guuid=eecbe709-1800-0000-a17f-21fa2c0c0000 pid=3116 /usr/bin/mkdir guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=eecbe709-1800-0000-a17f-21fa2c0c0000 pid=3116 execve guuid=cf85810a-1800-0000-a17f-21fa2f0c0000 pid=3119 /usr/bin/mkdir guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=cf85810a-1800-0000-a17f-21fa2f0c0000 pid=3119 execve guuid=6b5cea0a-1800-0000-a17f-21fa310c0000 pid=3121 /usr/bin/mkdir guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=6b5cea0a-1800-0000-a17f-21fa310c0000 pid=3121 execve guuid=935b4b0b-1800-0000-a17f-21fa330c0000 pid=3123 /usr/bin/mkdir guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=935b4b0b-1800-0000-a17f-21fa330c0000 pid=3123 execve guuid=30439d0b-1800-0000-a17f-21fa350c0000 pid=3125 /usr/bin/mkdir guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=30439d0b-1800-0000-a17f-21fa350c0000 pid=3125 execve guuid=0038ed0b-1800-0000-a17f-21fa370c0000 pid=3127 /usr/bin/mkdir guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=0038ed0b-1800-0000-a17f-21fa370c0000 pid=3127 execve guuid=c67c3d0c-1800-0000-a17f-21fa390c0000 pid=3129 /usr/bin/mkdir guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=c67c3d0c-1800-0000-a17f-21fa390c0000 pid=3129 execve guuid=6322950c-1800-0000-a17f-21fa3b0c0000 pid=3131 /usr/bin/cp guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=6322950c-1800-0000-a17f-21fa3b0c0000 pid=3131 execve guuid=a86ef10c-1800-0000-a17f-21fa3e0c0000 pid=3134 /usr/bin/cp guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=a86ef10c-1800-0000-a17f-21fa3e0c0000 pid=3134 execve guuid=6664500d-1800-0000-a17f-21fa400c0000 pid=3136 /usr/bin/cp guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=6664500d-1800-0000-a17f-21fa400c0000 pid=3136 execve guuid=eb09de0d-1800-0000-a17f-21fa430c0000 pid=3139 /usr/bin/cp guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=eb09de0d-1800-0000-a17f-21fa430c0000 pid=3139 execve guuid=c15b3b0e-1800-0000-a17f-21fa450c0000 pid=3141 /usr/bin/cp guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=c15b3b0e-1800-0000-a17f-21fa450c0000 pid=3141 execve guuid=ab62900e-1800-0000-a17f-21fa470c0000 pid=3143 /usr/bin/cp guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=ab62900e-1800-0000-a17f-21fa470c0000 pid=3143 execve guuid=fc01e80e-1800-0000-a17f-21fa4a0c0000 pid=3146 /usr/bin/cp guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=fc01e80e-1800-0000-a17f-21fa4a0c0000 pid=3146 execve guuid=2dab450f-1800-0000-a17f-21fa4c0c0000 pid=3148 /usr/bin/cp guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=2dab450f-1800-0000-a17f-21fa4c0c0000 pid=3148 execve guuid=92f5a30f-1800-0000-a17f-21fa4f0c0000 pid=3151 /usr/bin/cp guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=92f5a30f-1800-0000-a17f-21fa4f0c0000 pid=3151 execve guuid=85910b10-1800-0000-a17f-21fa510c0000 pid=3153 /usr/bin/cp guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=85910b10-1800-0000-a17f-21fa510c0000 pid=3153 execve guuid=334d9b10-1800-0000-a17f-21fa540c0000 pid=3156 /usr/bin/cp guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=334d9b10-1800-0000-a17f-21fa540c0000 pid=3156 execve guuid=315cf710-1800-0000-a17f-21fa560c0000 pid=3158 /usr/bin/cp guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=315cf710-1800-0000-a17f-21fa560c0000 pid=3158 execve guuid=299d5411-1800-0000-a17f-21fa590c0000 pid=3161 /usr/bin/cp guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=299d5411-1800-0000-a17f-21fa590c0000 pid=3161 execve guuid=9cecaf11-1800-0000-a17f-21fa5d0c0000 pid=3165 /usr/bin/cp guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=9cecaf11-1800-0000-a17f-21fa5d0c0000 pid=3165 execve guuid=7c120812-1800-0000-a17f-21fa5e0c0000 pid=3166 /usr/bin/cp guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=7c120812-1800-0000-a17f-21fa5e0c0000 pid=3166 execve guuid=70657012-1800-0000-a17f-21fa5f0c0000 pid=3167 /usr/bin/touch guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=70657012-1800-0000-a17f-21fa5f0c0000 pid=3167 execve guuid=b16cca12-1800-0000-a17f-21fa610c0000 pid=3169 /usr/bin/bash guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=b16cca12-1800-0000-a17f-21fa610c0000 pid=3169 clone guuid=bd3bf612-1800-0000-a17f-21fa620c0000 pid=3170 /usr/bin/bash guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=bd3bf612-1800-0000-a17f-21fa620c0000 pid=3170 clone guuid=1b0e4f13-1800-0000-a17f-21fa640c0000 pid=3172 /usr/bin/bash guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=1b0e4f13-1800-0000-a17f-21fa640c0000 pid=3172 clone guuid=6b7e5413-1800-0000-a17f-21fa650c0000 pid=3173 /usr/bin/base64 write-file guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=6b7e5413-1800-0000-a17f-21fa650c0000 pid=3173 execve guuid=b001e013-1800-0000-a17f-21fa680c0000 pid=3176 /usr/bin/bash guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=b001e013-1800-0000-a17f-21fa680c0000 pid=3176 execve guuid=12435919-1800-0000-a17f-21fa820c0000 pid=3202 /usr/bin/rm delete-file guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=12435919-1800-0000-a17f-21fa820c0000 pid=3202 execve guuid=dc1fa519-1800-0000-a17f-21fa840c0000 pid=3204 /usr/bin/bash guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=dc1fa519-1800-0000-a17f-21fa840c0000 pid=3204 clone guuid=6e1cb219-1800-0000-a17f-21fa850c0000 pid=3205 /usr/bin/bash guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=6e1cb219-1800-0000-a17f-21fa850c0000 pid=3205 clone guuid=2314d419-1800-0000-a17f-21fa870c0000 pid=3207 /usr/bin/bash guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=2314d419-1800-0000-a17f-21fa870c0000 pid=3207 execve guuid=36322f1a-1800-0000-a17f-21fa880c0000 pid=3208 /usr/bin/rm guuid=decc6a08-1800-0000-a17f-21fa250c0000 pid=3109->guuid=36322f1a-1800-0000-a17f-21fa880c0000 pid=3208 execve guuid=5f3b2e14-1800-0000-a17f-21fa6a0c0000 pid=3178 /usr/bin/bash guuid=b001e013-1800-0000-a17f-21fa680c0000 pid=3176->guuid=5f3b2e14-1800-0000-a17f-21fa6a0c0000 pid=3178 clone guuid=96013714-1800-0000-a17f-21fa6b0c0000 pid=3179 /usr/bin/bash guuid=b001e013-1800-0000-a17f-21fa680c0000 pid=3176->guuid=96013714-1800-0000-a17f-21fa6b0c0000 pid=3179 clone guuid=29145f14-1800-0000-a17f-21fa6c0c0000 pid=3180 /usr/bin/ls guuid=b001e013-1800-0000-a17f-21fa680c0000 pid=3176->guuid=29145f14-1800-0000-a17f-21fa6c0c0000 pid=3180 execve guuid=492ad814-1800-0000-a17f-21fa6f0c0000 pid=3183 /usr/bin/cat guuid=b001e013-1800-0000-a17f-21fa680c0000 pid=3176->guuid=492ad814-1800-0000-a17f-21fa6f0c0000 pid=3183 execve guuid=311f3a15-1800-0000-a17f-21fa710c0000 pid=3185 /usr/bin/ls guuid=b001e013-1800-0000-a17f-21fa680c0000 pid=3176->guuid=311f3a15-1800-0000-a17f-21fa710c0000 pid=3185 execve guuid=7dd3a715-1800-0000-a17f-21fa730c0000 pid=3187 /usr/bin/mkdir guuid=b001e013-1800-0000-a17f-21fa680c0000 pid=3176->guuid=7dd3a715-1800-0000-a17f-21fa730c0000 pid=3187 execve guuid=6bc10116-1800-0000-a17f-21fa750c0000 pid=3189 /usr/bin/mv guuid=b001e013-1800-0000-a17f-21fa680c0000 pid=3176->guuid=6bc10116-1800-0000-a17f-21fa750c0000 pid=3189 execve guuid=ec086e16-1800-0000-a17f-21fa760c0000 pid=3190 /usr/bin/bash guuid=b001e013-1800-0000-a17f-21fa680c0000 pid=3176->guuid=ec086e16-1800-0000-a17f-21fa760c0000 pid=3190 clone guuid=1e6d8116-1800-0000-a17f-21fa770c0000 pid=3191 /usr/bin/base64 write-file guuid=b001e013-1800-0000-a17f-21fa680c0000 pid=3176->guuid=1e6d8116-1800-0000-a17f-21fa770c0000 pid=3191 execve guuid=2d55ed16-1800-0000-a17f-21fa780c0000 pid=3192 /usr/bin/rm delete-file guuid=b001e013-1800-0000-a17f-21fa680c0000 pid=3176->guuid=2d55ed16-1800-0000-a17f-21fa780c0000 pid=3192 execve guuid=3e684b17-1800-0000-a17f-21fa790c0000 pid=3193 /usr/bin/ls guuid=b001e013-1800-0000-a17f-21fa680c0000 pid=3176->guuid=3e684b17-1800-0000-a17f-21fa790c0000 pid=3193 execve guuid=d6dbb117-1800-0000-a17f-21fa7b0c0000 pid=3195 /usr/bin/bash guuid=b001e013-1800-0000-a17f-21fa680c0000 pid=3176->guuid=d6dbb117-1800-0000-a17f-21fa7b0c0000 pid=3195 clone guuid=03d1b917-1800-0000-a17f-21fa7c0c0000 pid=3196 /usr/bin/base64 write-file guuid=b001e013-1800-0000-a17f-21fa680c0000 pid=3176->guuid=03d1b917-1800-0000-a17f-21fa7c0c0000 pid=3196 execve guuid=86ba2418-1800-0000-a17f-21fa7d0c0000 pid=3197 /usr/bin/ls guuid=b001e013-1800-0000-a17f-21fa680c0000 pid=3176->guuid=86ba2418-1800-0000-a17f-21fa7d0c0000 pid=3197 execve guuid=586d9818-1800-0000-a17f-21fa7e0c0000 pid=3198 /usr/bin/cat guuid=b001e013-1800-0000-a17f-21fa680c0000 pid=3176->guuid=586d9818-1800-0000-a17f-21fa7e0c0000 pid=3198 execve guuid=affbed18-1800-0000-a17f-21fa7f0c0000 pid=3199 /usr/bin/ls guuid=b001e013-1800-0000-a17f-21fa680c0000 pid=3176->guuid=affbed18-1800-0000-a17f-21fa7f0c0000 pid=3199 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Heuristic
Status:
Malicious
First seen:
2026-03-19 02:30:28 UTC
File Type:
Text (Shell)
AV detection:
14 of 36 (38.89%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh dc9ec8cc29b821abc61d2bb9275febf4237cfcd1b96b08b53796155c2a1c17f5

(this sample)

  
Delivery method
Distributed via web download

Comments