MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ddb285be2141aefb6414b44dd517e568735ccb57bc694d1b447fd18751e1cec0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: ddb285be2141aefb6414b44dd517e568735ccb57bc694d1b447fd18751e1cec0
SHA3-384 hash: b02c931dc9b04541b061ae0770a7afb07bce565209c3f7bb76c3990a94a26dfc4b3fc83ccf2d995d057d0d6c285adea2
SHA1 hash: 991b3ba714018e5ac1788dd6faeb8fd1ef486905
MD5 hash: 68dbee8fa088ad7d2521cef375a2e807
humanhash: idaho-single-december-stairway
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-22 21:19:22 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:WFcuQpWx+BL0SWL0gQzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:WF8i+BL0SI0HzsP4cbddr7zsP4cbddrk
TLSH T15C925DB512896C79FBD0CE399F3C7F4DADE8C2C42124A3ACBA0F39215A1166DC70534A
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
53
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Gathering data
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=cacd5a8d-1600-0000-c2aa-ef09ef0c0000 pid=3311 /usr/bin/sudo guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315 /tmp/sample.bin guuid=cacd5a8d-1600-0000-c2aa-ef09ef0c0000 pid=3311->guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315 execve guuid=f7713791-1600-0000-c2aa-ef09f50c0000 pid=3317 /usr/bin/bash guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=f7713791-1600-0000-c2aa-ef09f50c0000 pid=3317 clone guuid=99a23e91-1600-0000-c2aa-ef09f60c0000 pid=3318 /usr/bin/bash guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=99a23e91-1600-0000-c2aa-ef09f60c0000 pid=3318 clone guuid=83db7f91-1600-0000-c2aa-ef09f70c0000 pid=3319 /usr/bin/mkdir guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=83db7f91-1600-0000-c2aa-ef09f70c0000 pid=3319 execve guuid=201ad591-1600-0000-c2aa-ef09f90c0000 pid=3321 /usr/bin/mkdir guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=201ad591-1600-0000-c2aa-ef09f90c0000 pid=3321 execve guuid=48c53392-1600-0000-c2aa-ef09fc0c0000 pid=3324 /usr/bin/mkdir guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=48c53392-1600-0000-c2aa-ef09fc0c0000 pid=3324 execve guuid=4cc7a792-1600-0000-c2aa-ef09fe0c0000 pid=3326 /usr/bin/mkdir guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=4cc7a792-1600-0000-c2aa-ef09fe0c0000 pid=3326 execve guuid=5fac1093-1600-0000-c2aa-ef09000d0000 pid=3328 /usr/bin/mkdir guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=5fac1093-1600-0000-c2aa-ef09000d0000 pid=3328 execve guuid=bf9d7593-1600-0000-c2aa-ef09020d0000 pid=3330 /usr/bin/mkdir guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=bf9d7593-1600-0000-c2aa-ef09020d0000 pid=3330 execve guuid=c6d0ca93-1600-0000-c2aa-ef09040d0000 pid=3332 /usr/bin/mkdir guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=c6d0ca93-1600-0000-c2aa-ef09040d0000 pid=3332 execve guuid=75731d94-1600-0000-c2aa-ef09060d0000 pid=3334 /usr/bin/cp guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=75731d94-1600-0000-c2aa-ef09060d0000 pid=3334 execve guuid=842c9a94-1600-0000-c2aa-ef09070d0000 pid=3335 /usr/bin/cp guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=842c9a94-1600-0000-c2aa-ef09070d0000 pid=3335 execve guuid=fa620e95-1600-0000-c2aa-ef09080d0000 pid=3336 /usr/bin/cp guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=fa620e95-1600-0000-c2aa-ef09080d0000 pid=3336 execve guuid=7081c195-1600-0000-c2aa-ef090b0d0000 pid=3339 /usr/bin/cp guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=7081c195-1600-0000-c2aa-ef090b0d0000 pid=3339 execve guuid=25b21f96-1600-0000-c2aa-ef090d0d0000 pid=3341 /usr/bin/cp guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=25b21f96-1600-0000-c2aa-ef090d0d0000 pid=3341 execve guuid=9d2f8596-1600-0000-c2aa-ef090f0d0000 pid=3343 /usr/bin/cp guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=9d2f8596-1600-0000-c2aa-ef090f0d0000 pid=3343 execve guuid=ee52dd96-1600-0000-c2aa-ef09110d0000 pid=3345 /usr/bin/cp guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=ee52dd96-1600-0000-c2aa-ef09110d0000 pid=3345 execve guuid=67893497-1600-0000-c2aa-ef09130d0000 pid=3347 /usr/bin/cp guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=67893497-1600-0000-c2aa-ef09130d0000 pid=3347 execve guuid=88619b97-1600-0000-c2aa-ef09150d0000 pid=3349 /usr/bin/cp guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=88619b97-1600-0000-c2aa-ef09150d0000 pid=3349 execve guuid=a4190098-1600-0000-c2aa-ef09160d0000 pid=3350 /usr/bin/cp guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=a4190098-1600-0000-c2aa-ef09160d0000 pid=3350 execve guuid=5e776698-1600-0000-c2aa-ef09190d0000 pid=3353 /usr/bin/cp guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=5e776698-1600-0000-c2aa-ef09190d0000 pid=3353 execve guuid=4496c798-1600-0000-c2aa-ef091b0d0000 pid=3355 /usr/bin/cp guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=4496c798-1600-0000-c2aa-ef091b0d0000 pid=3355 execve guuid=f3b61d99-1600-0000-c2aa-ef091d0d0000 pid=3357 /usr/bin/cp guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=f3b61d99-1600-0000-c2aa-ef091d0d0000 pid=3357 execve guuid=41de7b99-1600-0000-c2aa-ef09200d0000 pid=3360 /usr/bin/cp guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=41de7b99-1600-0000-c2aa-ef09200d0000 pid=3360 execve guuid=41bfd599-1600-0000-c2aa-ef09210d0000 pid=3361 /usr/bin/cp guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=41bfd599-1600-0000-c2aa-ef09210d0000 pid=3361 execve guuid=e2f63d9a-1600-0000-c2aa-ef09230d0000 pid=3363 /usr/bin/touch guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=e2f63d9a-1600-0000-c2aa-ef09230d0000 pid=3363 execve guuid=a7349a9a-1600-0000-c2aa-ef09240d0000 pid=3364 /usr/bin/bash guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=a7349a9a-1600-0000-c2aa-ef09240d0000 pid=3364 clone guuid=0163a29a-1600-0000-c2aa-ef09250d0000 pid=3365 /usr/bin/bash guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=0163a29a-1600-0000-c2aa-ef09250d0000 pid=3365 clone guuid=18fac79a-1600-0000-c2aa-ef09260d0000 pid=3366 /usr/bin/bash guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=18fac79a-1600-0000-c2aa-ef09260d0000 pid=3366 clone guuid=6085d19a-1600-0000-c2aa-ef09270d0000 pid=3367 /usr/bin/base64 write-file guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=6085d19a-1600-0000-c2aa-ef09270d0000 pid=3367 execve guuid=ebd6659b-1600-0000-c2aa-ef09280d0000 pid=3368 /usr/bin/bash guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=ebd6659b-1600-0000-c2aa-ef09280d0000 pid=3368 execve guuid=271faea0-1600-0000-c2aa-ef09480d0000 pid=3400 /usr/bin/rm delete-file guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=271faea0-1600-0000-c2aa-ef09480d0000 pid=3400 execve guuid=0fa4fea0-1600-0000-c2aa-ef094a0d0000 pid=3402 /usr/bin/bash guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=0fa4fea0-1600-0000-c2aa-ef094a0d0000 pid=3402 clone guuid=becf06a1-1600-0000-c2aa-ef094b0d0000 pid=3403 /usr/bin/bash guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=becf06a1-1600-0000-c2aa-ef094b0d0000 pid=3403 clone guuid=cb102ca1-1600-0000-c2aa-ef094c0d0000 pid=3404 /usr/bin/bash guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=cb102ca1-1600-0000-c2aa-ef094c0d0000 pid=3404 execve guuid=1e7a7ea1-1600-0000-c2aa-ef094e0d0000 pid=3406 /usr/bin/rm guuid=5a2adc90-1600-0000-c2aa-ef09f30c0000 pid=3315->guuid=1e7a7ea1-1600-0000-c2aa-ef094e0d0000 pid=3406 execve guuid=2cd0b79b-1600-0000-c2aa-ef092a0d0000 pid=3370 /usr/bin/bash guuid=ebd6659b-1600-0000-c2aa-ef09280d0000 pid=3368->guuid=2cd0b79b-1600-0000-c2aa-ef092a0d0000 pid=3370 clone guuid=c5d4bd9b-1600-0000-c2aa-ef092b0d0000 pid=3371 /usr/bin/bash guuid=ebd6659b-1600-0000-c2aa-ef09280d0000 pid=3368->guuid=c5d4bd9b-1600-0000-c2aa-ef092b0d0000 pid=3371 clone guuid=349c0a9c-1600-0000-c2aa-ef092d0d0000 pid=3373 /usr/bin/ls guuid=ebd6659b-1600-0000-c2aa-ef09280d0000 pid=3368->guuid=349c0a9c-1600-0000-c2aa-ef092d0d0000 pid=3373 execve guuid=5f569a9c-1600-0000-c2aa-ef09300d0000 pid=3376 /usr/bin/cat guuid=ebd6659b-1600-0000-c2aa-ef09280d0000 pid=3368->guuid=5f569a9c-1600-0000-c2aa-ef09300d0000 pid=3376 execve guuid=362ee19c-1600-0000-c2aa-ef09320d0000 pid=3378 /usr/bin/ls guuid=ebd6659b-1600-0000-c2aa-ef09280d0000 pid=3368->guuid=362ee19c-1600-0000-c2aa-ef09320d0000 pid=3378 execve guuid=31904a9d-1600-0000-c2aa-ef09340d0000 pid=3380 /usr/bin/mkdir guuid=ebd6659b-1600-0000-c2aa-ef09280d0000 pid=3368->guuid=31904a9d-1600-0000-c2aa-ef09340d0000 pid=3380 execve guuid=e5ada09d-1600-0000-c2aa-ef09360d0000 pid=3382 /usr/bin/mv guuid=ebd6659b-1600-0000-c2aa-ef09280d0000 pid=3368->guuid=e5ada09d-1600-0000-c2aa-ef09360d0000 pid=3382 execve guuid=449b039e-1600-0000-c2aa-ef09390d0000 pid=3385 /usr/bin/bash guuid=ebd6659b-1600-0000-c2aa-ef09280d0000 pid=3368->guuid=449b039e-1600-0000-c2aa-ef09390d0000 pid=3385 clone guuid=d4a20a9e-1600-0000-c2aa-ef093a0d0000 pid=3386 /usr/bin/base64 write-file guuid=ebd6659b-1600-0000-c2aa-ef09280d0000 pid=3368->guuid=d4a20a9e-1600-0000-c2aa-ef093a0d0000 pid=3386 execve guuid=939e5c9e-1600-0000-c2aa-ef093c0d0000 pid=3388 /usr/bin/rm delete-file guuid=ebd6659b-1600-0000-c2aa-ef09280d0000 pid=3368->guuid=939e5c9e-1600-0000-c2aa-ef093c0d0000 pid=3388 execve guuid=9a9ba49e-1600-0000-c2aa-ef093e0d0000 pid=3390 /usr/bin/ls guuid=ebd6659b-1600-0000-c2aa-ef09280d0000 pid=3368->guuid=9a9ba49e-1600-0000-c2aa-ef093e0d0000 pid=3390 execve guuid=5a1e249f-1600-0000-c2aa-ef093f0d0000 pid=3391 /usr/bin/bash guuid=ebd6659b-1600-0000-c2aa-ef09280d0000 pid=3368->guuid=5a1e249f-1600-0000-c2aa-ef093f0d0000 pid=3391 clone guuid=a6982c9f-1600-0000-c2aa-ef09400d0000 pid=3392 /usr/bin/base64 write-file guuid=ebd6659b-1600-0000-c2aa-ef09280d0000 pid=3368->guuid=a6982c9f-1600-0000-c2aa-ef09400d0000 pid=3392 execve guuid=c5369b9f-1600-0000-c2aa-ef09420d0000 pid=3394 /usr/bin/ls guuid=ebd6659b-1600-0000-c2aa-ef09280d0000 pid=3368->guuid=c5369b9f-1600-0000-c2aa-ef09420d0000 pid=3394 execve guuid=2892f99f-1600-0000-c2aa-ef09440d0000 pid=3396 /usr/bin/cat guuid=ebd6659b-1600-0000-c2aa-ef09280d0000 pid=3368->guuid=2892f99f-1600-0000-c2aa-ef09440d0000 pid=3396 execve guuid=95c93ea0-1600-0000-c2aa-ef09460d0000 pid=3398 /usr/bin/ls guuid=ebd6659b-1600-0000-c2aa-ef09280d0000 pid=3368->guuid=95c93ea0-1600-0000-c2aa-ef09460d0000 pid=3398 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Heuristic
Status:
Malicious
First seen:
2026-03-22 21:20:25 UTC
File Type:
Text (Shell)
AV detection:
14 of 36 (38.89%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh ddb285be2141aefb6414b44dd517e568735ccb57bc694d1b447fd18751e1cec0

(this sample)

  
Delivery method
Distributed via web download

Comments