MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e1807de83ae2a00c2f641cfa2a8ba781e16a6d5a2fa496c2ba6975abf9bd2631. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: e1807de83ae2a00c2f641cfa2a8ba781e16a6d5a2fa496c2ba6975abf9bd2631
SHA3-384 hash: c2c826e16989f94f5bd1a3779c9dabe41f4ef8a1aa6ca9d4bfd5dd37dfd254a937b8f25c9213836ef06e656df314274f
SHA1 hash: 4aa97d14455bdcc1504dd4a35906a7f29e67ffef
MD5 hash: 4ff87860b8bc5919e448b4632d45c84c
humanhash: magnesium-colorado-india-hot
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-23 08:58:00 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:3FcuQpWx+BL0SWL0gCzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:3F8i+BL0SI0NzsP4cbddr7zsP4cbddrk
TLSH T145925CB512896C79FBD0CE39AF3C6F4DADE8C2C42124E3ACBA4F39215A1166DC705359
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Gathering data
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=f34ab04c-1800-0000-f8ea-0885950c0000 pid=3221 /usr/bin/sudo guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224 /tmp/sample.bin guuid=f34ab04c-1800-0000-f8ea-0885950c0000 pid=3221->guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224 execve guuid=d9df854f-1800-0000-f8ea-0885990c0000 pid=3225 /usr/bin/bash guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=d9df854f-1800-0000-f8ea-0885990c0000 pid=3225 clone guuid=e0618d4f-1800-0000-f8ea-08859a0c0000 pid=3226 /usr/bin/bash guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=e0618d4f-1800-0000-f8ea-08859a0c0000 pid=3226 clone guuid=33b6b34f-1800-0000-f8ea-08859c0c0000 pid=3228 /usr/bin/mkdir guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=33b6b34f-1800-0000-f8ea-08859c0c0000 pid=3228 execve guuid=f3f21f50-1800-0000-f8ea-08859e0c0000 pid=3230 /usr/bin/mkdir guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=f3f21f50-1800-0000-f8ea-08859e0c0000 pid=3230 execve guuid=aa617f50-1800-0000-f8ea-0885a00c0000 pid=3232 /usr/bin/mkdir guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=aa617f50-1800-0000-f8ea-0885a00c0000 pid=3232 execve guuid=c72ce350-1800-0000-f8ea-0885a20c0000 pid=3234 /usr/bin/mkdir guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=c72ce350-1800-0000-f8ea-0885a20c0000 pid=3234 execve guuid=b2164e51-1800-0000-f8ea-0885a40c0000 pid=3236 /usr/bin/mkdir guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=b2164e51-1800-0000-f8ea-0885a40c0000 pid=3236 execve guuid=94d9d851-1800-0000-f8ea-0885a60c0000 pid=3238 /usr/bin/mkdir guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=94d9d851-1800-0000-f8ea-0885a60c0000 pid=3238 execve guuid=d1156f52-1800-0000-f8ea-0885a70c0000 pid=3239 /usr/bin/mkdir guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=d1156f52-1800-0000-f8ea-0885a70c0000 pid=3239 execve guuid=04482153-1800-0000-f8ea-0885a80c0000 pid=3240 /usr/bin/cp guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=04482153-1800-0000-f8ea-0885a80c0000 pid=3240 execve guuid=f5a9d253-1800-0000-f8ea-0885a90c0000 pid=3241 /usr/bin/cp guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=f5a9d253-1800-0000-f8ea-0885a90c0000 pid=3241 execve guuid=a13d4954-1800-0000-f8ea-0885aa0c0000 pid=3242 /usr/bin/cp guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=a13d4954-1800-0000-f8ea-0885aa0c0000 pid=3242 execve guuid=3acb0e55-1800-0000-f8ea-0885ab0c0000 pid=3243 /usr/bin/cp guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=3acb0e55-1800-0000-f8ea-0885ab0c0000 pid=3243 execve guuid=ab5cae55-1800-0000-f8ea-0885ac0c0000 pid=3244 /usr/bin/cp guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=ab5cae55-1800-0000-f8ea-0885ac0c0000 pid=3244 execve guuid=9dc24e56-1800-0000-f8ea-0885ad0c0000 pid=3245 /usr/bin/cp guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=9dc24e56-1800-0000-f8ea-0885ad0c0000 pid=3245 execve guuid=ec9adf56-1800-0000-f8ea-0885ae0c0000 pid=3246 /usr/bin/cp guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=ec9adf56-1800-0000-f8ea-0885ae0c0000 pid=3246 execve guuid=55167457-1800-0000-f8ea-0885af0c0000 pid=3247 /usr/bin/cp guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=55167457-1800-0000-f8ea-0885af0c0000 pid=3247 execve guuid=4e7c0e58-1800-0000-f8ea-0885b00c0000 pid=3248 /usr/bin/cp guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=4e7c0e58-1800-0000-f8ea-0885b00c0000 pid=3248 execve guuid=c03fa258-1800-0000-f8ea-0885b10c0000 pid=3249 /usr/bin/cp guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=c03fa258-1800-0000-f8ea-0885b10c0000 pid=3249 execve guuid=f2312159-1800-0000-f8ea-0885b20c0000 pid=3250 /usr/bin/cp guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=f2312159-1800-0000-f8ea-0885b20c0000 pid=3250 execve guuid=abf29059-1800-0000-f8ea-0885b40c0000 pid=3252 /usr/bin/cp guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=abf29059-1800-0000-f8ea-0885b40c0000 pid=3252 execve guuid=5f5c035a-1800-0000-f8ea-0885b50c0000 pid=3253 /usr/bin/cp guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=5f5c035a-1800-0000-f8ea-0885b50c0000 pid=3253 execve guuid=2c21785a-1800-0000-f8ea-0885b60c0000 pid=3254 /usr/bin/cp guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=2c21785a-1800-0000-f8ea-0885b60c0000 pid=3254 execve guuid=789af65a-1800-0000-f8ea-0885b70c0000 pid=3255 /usr/bin/cp guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=789af65a-1800-0000-f8ea-0885b70c0000 pid=3255 execve guuid=d5f2695b-1800-0000-f8ea-0885b80c0000 pid=3256 /usr/bin/touch guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=d5f2695b-1800-0000-f8ea-0885b80c0000 pid=3256 execve guuid=679fcb5b-1800-0000-f8ea-0885b90c0000 pid=3257 /usr/bin/bash guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=679fcb5b-1800-0000-f8ea-0885b90c0000 pid=3257 clone guuid=50e4db5b-1800-0000-f8ea-0885ba0c0000 pid=3258 /usr/bin/bash guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=50e4db5b-1800-0000-f8ea-0885ba0c0000 pid=3258 clone guuid=794ff95b-1800-0000-f8ea-0885bc0c0000 pid=3260 /usr/bin/bash guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=794ff95b-1800-0000-f8ea-0885bc0c0000 pid=3260 clone guuid=6c10ff5b-1800-0000-f8ea-0885bd0c0000 pid=3261 /usr/bin/base64 write-file guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=6c10ff5b-1800-0000-f8ea-0885bd0c0000 pid=3261 execve guuid=d95c815c-1800-0000-f8ea-0885bf0c0000 pid=3263 /usr/bin/bash guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=d95c815c-1800-0000-f8ea-0885bf0c0000 pid=3263 execve guuid=3a173962-1800-0000-f8ea-0885db0c0000 pid=3291 /usr/bin/rm delete-file guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=3a173962-1800-0000-f8ea-0885db0c0000 pid=3291 execve guuid=9aa1af62-1800-0000-f8ea-0885dd0c0000 pid=3293 /usr/bin/bash guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=9aa1af62-1800-0000-f8ea-0885dd0c0000 pid=3293 clone guuid=d451b862-1800-0000-f8ea-0885de0c0000 pid=3294 /usr/bin/bash guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=d451b862-1800-0000-f8ea-0885de0c0000 pid=3294 clone guuid=eec1f562-1800-0000-f8ea-0885df0c0000 pid=3295 /usr/bin/bash guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=eec1f562-1800-0000-f8ea-0885df0c0000 pid=3295 execve guuid=a00e8e63-1800-0000-f8ea-0885e00c0000 pid=3296 /usr/bin/rm guuid=abd7df4e-1800-0000-f8ea-0885980c0000 pid=3224->guuid=a00e8e63-1800-0000-f8ea-0885e00c0000 pid=3296 execve guuid=a297d25c-1800-0000-f8ea-0885c10c0000 pid=3265 /usr/bin/bash guuid=d95c815c-1800-0000-f8ea-0885bf0c0000 pid=3263->guuid=a297d25c-1800-0000-f8ea-0885c10c0000 pid=3265 clone guuid=f720da5c-1800-0000-f8ea-0885c20c0000 pid=3266 /usr/bin/bash guuid=d95c815c-1800-0000-f8ea-0885bf0c0000 pid=3263->guuid=f720da5c-1800-0000-f8ea-0885c20c0000 pid=3266 clone guuid=b01dfc5c-1800-0000-f8ea-0885c30c0000 pid=3267 /usr/bin/ls guuid=d95c815c-1800-0000-f8ea-0885bf0c0000 pid=3263->guuid=b01dfc5c-1800-0000-f8ea-0885c30c0000 pid=3267 execve guuid=a4e8745d-1800-0000-f8ea-0885c50c0000 pid=3269 /usr/bin/cat guuid=d95c815c-1800-0000-f8ea-0885bf0c0000 pid=3263->guuid=a4e8745d-1800-0000-f8ea-0885c50c0000 pid=3269 execve guuid=63f9b75d-1800-0000-f8ea-0885c70c0000 pid=3271 /usr/bin/ls guuid=d95c815c-1800-0000-f8ea-0885bf0c0000 pid=3263->guuid=63f9b75d-1800-0000-f8ea-0885c70c0000 pid=3271 execve guuid=b9d44d5e-1800-0000-f8ea-0885c90c0000 pid=3273 /usr/bin/mkdir guuid=d95c815c-1800-0000-f8ea-0885bf0c0000 pid=3263->guuid=b9d44d5e-1800-0000-f8ea-0885c90c0000 pid=3273 execve guuid=0ce2ae5e-1800-0000-f8ea-0885cb0c0000 pid=3275 /usr/bin/mv guuid=d95c815c-1800-0000-f8ea-0885bf0c0000 pid=3263->guuid=0ce2ae5e-1800-0000-f8ea-0885cb0c0000 pid=3275 execve guuid=509a285f-1800-0000-f8ea-0885cc0c0000 pid=3276 /usr/bin/bash guuid=d95c815c-1800-0000-f8ea-0885bf0c0000 pid=3263->guuid=509a285f-1800-0000-f8ea-0885cc0c0000 pid=3276 clone guuid=8543345f-1800-0000-f8ea-0885cd0c0000 pid=3277 /usr/bin/base64 write-file guuid=d95c815c-1800-0000-f8ea-0885bf0c0000 pid=3263->guuid=8543345f-1800-0000-f8ea-0885cd0c0000 pid=3277 execve guuid=18a1a15f-1800-0000-f8ea-0885ce0c0000 pid=3278 /usr/bin/rm delete-file guuid=d95c815c-1800-0000-f8ea-0885bf0c0000 pid=3263->guuid=18a1a15f-1800-0000-f8ea-0885ce0c0000 pid=3278 execve guuid=4f21ee5f-1800-0000-f8ea-0885d00c0000 pid=3280 /usr/bin/ls guuid=d95c815c-1800-0000-f8ea-0885bf0c0000 pid=3263->guuid=4f21ee5f-1800-0000-f8ea-0885d00c0000 pid=3280 execve guuid=08cb9060-1800-0000-f8ea-0885d30c0000 pid=3283 /usr/bin/bash guuid=d95c815c-1800-0000-f8ea-0885bf0c0000 pid=3263->guuid=08cb9060-1800-0000-f8ea-0885d30c0000 pid=3283 clone guuid=0d179860-1800-0000-f8ea-0885d40c0000 pid=3284 /usr/bin/base64 write-file guuid=d95c815c-1800-0000-f8ea-0885bf0c0000 pid=3263->guuid=0d179860-1800-0000-f8ea-0885d40c0000 pid=3284 execve guuid=fab5ea60-1800-0000-f8ea-0885d60c0000 pid=3286 /usr/bin/ls guuid=d95c815c-1800-0000-f8ea-0885bf0c0000 pid=3263->guuid=fab5ea60-1800-0000-f8ea-0885d60c0000 pid=3286 execve guuid=8e444c61-1800-0000-f8ea-0885d80c0000 pid=3288 /usr/bin/cat guuid=d95c815c-1800-0000-f8ea-0885bf0c0000 pid=3263->guuid=8e444c61-1800-0000-f8ea-0885d80c0000 pid=3288 execve guuid=f660a861-1800-0000-f8ea-0885da0c0000 pid=3290 /usr/bin/ls guuid=d95c815c-1800-0000-f8ea-0885bf0c0000 pid=3263->guuid=f660a861-1800-0000-f8ea-0885da0c0000 pid=3290 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-23 08:58:25 UTC
File Type:
Text (Shell)
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh e1807de83ae2a00c2f641cfa2a8ba781e16a6d5a2fa496c2ba6975abf9bd2631

(this sample)

  
Delivery method
Distributed via web download

Comments