MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ea220eb097e92e797b40aa8146a01dd814566065981abd023a1e023915c2b0df. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: ea220eb097e92e797b40aa8146a01dd814566065981abd023a1e023915c2b0df
SHA3-384 hash: 0c49368d2495c08eacc8ef65858c3fab7dff323d3f488ad5c97755ca5a7bbf0d97df7f5facc1baf38e167363d3ae37bf
SHA1 hash: 8aa8975176a6afb804575a6dc61d47841f791d28
MD5 hash: 51ca6a69411c1572b09e98ba5154faf0
humanhash: hotel-diet-lion-oregon
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-16 08:16:24 UTC
Last seen:2026-03-16 08:39:07 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 384:coFcuQpWx+BL0SWL0gzzsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:coF8i+BL0SI00zsP4cbddr7zsP4cbddo
TLSH T1CE925CB512896C79FBD0CE399F3C6F4DADE8C2C42124A3ACBA4F39215A1166DC70535A
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
2
# of downloads :
82
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Gathering data
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=5f4a9b22-1700-0000-900a-c366c30d0000 pid=3523 /usr/bin/sudo guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528 /tmp/sample.bin guuid=5f4a9b22-1700-0000-900a-c366c30d0000 pid=3523->guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528 execve guuid=bbc9be24-1700-0000-900a-c366ca0d0000 pid=3530 /usr/bin/bash guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=bbc9be24-1700-0000-900a-c366ca0d0000 pid=3530 clone guuid=af5cc424-1700-0000-900a-c366cc0d0000 pid=3532 /usr/bin/bash guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=af5cc424-1700-0000-900a-c366cc0d0000 pid=3532 clone guuid=7876db24-1700-0000-900a-c366cd0d0000 pid=3533 /usr/bin/mkdir guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=7876db24-1700-0000-900a-c366cd0d0000 pid=3533 execve guuid=07b53625-1700-0000-900a-c366cf0d0000 pid=3535 /usr/bin/mkdir guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=07b53625-1700-0000-900a-c366cf0d0000 pid=3535 execve guuid=98749025-1700-0000-900a-c366d20d0000 pid=3538 /usr/bin/mkdir guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=98749025-1700-0000-900a-c366d20d0000 pid=3538 execve guuid=ad6fdf25-1700-0000-900a-c366d40d0000 pid=3540 /usr/bin/mkdir guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=ad6fdf25-1700-0000-900a-c366d40d0000 pid=3540 execve guuid=e65e2c26-1700-0000-900a-c366d60d0000 pid=3542 /usr/bin/mkdir guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=e65e2c26-1700-0000-900a-c366d60d0000 pid=3542 execve guuid=7a8a7e26-1700-0000-900a-c366d80d0000 pid=3544 /usr/bin/mkdir guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=7a8a7e26-1700-0000-900a-c366d80d0000 pid=3544 execve guuid=db1dd126-1700-0000-900a-c366da0d0000 pid=3546 /usr/bin/mkdir guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=db1dd126-1700-0000-900a-c366da0d0000 pid=3546 execve guuid=a03a2d27-1700-0000-900a-c366dd0d0000 pid=3549 /usr/bin/cp guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=a03a2d27-1700-0000-900a-c366dd0d0000 pid=3549 execve guuid=5b6a8d27-1700-0000-900a-c366df0d0000 pid=3551 /usr/bin/cp guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=5b6a8d27-1700-0000-900a-c366df0d0000 pid=3551 execve guuid=d48bf727-1700-0000-900a-c366e20d0000 pid=3554 /usr/bin/cp guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=d48bf727-1700-0000-900a-c366e20d0000 pid=3554 execve guuid=32d85728-1700-0000-900a-c366e40d0000 pid=3556 /usr/bin/cp guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=32d85728-1700-0000-900a-c366e40d0000 pid=3556 execve guuid=7661b528-1700-0000-900a-c366e60d0000 pid=3558 /usr/bin/cp guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=7661b528-1700-0000-900a-c366e60d0000 pid=3558 execve guuid=6ae71229-1700-0000-900a-c366e80d0000 pid=3560 /usr/bin/cp guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=6ae71229-1700-0000-900a-c366e80d0000 pid=3560 execve guuid=88998529-1700-0000-900a-c366eb0d0000 pid=3563 /usr/bin/cp guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=88998529-1700-0000-900a-c366eb0d0000 pid=3563 execve guuid=0264e729-1700-0000-900a-c366ed0d0000 pid=3565 /usr/bin/cp guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=0264e729-1700-0000-900a-c366ed0d0000 pid=3565 execve guuid=e03d4a2a-1700-0000-900a-c366ef0d0000 pid=3567 /usr/bin/cp guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=e03d4a2a-1700-0000-900a-c366ef0d0000 pid=3567 execve guuid=06e8b02a-1700-0000-900a-c366f20d0000 pid=3570 /usr/bin/cp guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=06e8b02a-1700-0000-900a-c366f20d0000 pid=3570 execve guuid=5c9d0d2b-1700-0000-900a-c366f40d0000 pid=3572 /usr/bin/cp guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=5c9d0d2b-1700-0000-900a-c366f40d0000 pid=3572 execve guuid=3567782b-1700-0000-900a-c366fa0d0000 pid=3578 /usr/bin/cp guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=3567782b-1700-0000-900a-c366fa0d0000 pid=3578 execve guuid=cfc1cf2b-1700-0000-900a-c366fb0d0000 pid=3579 /usr/bin/cp guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=cfc1cf2b-1700-0000-900a-c366fb0d0000 pid=3579 execve guuid=0f91252c-1700-0000-900a-c366fd0d0000 pid=3581 /usr/bin/cp guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=0f91252c-1700-0000-900a-c366fd0d0000 pid=3581 execve guuid=48617c2c-1700-0000-900a-c366ff0d0000 pid=3583 /usr/bin/cp guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=48617c2c-1700-0000-900a-c366ff0d0000 pid=3583 execve guuid=65e2cb2c-1700-0000-900a-c366000e0000 pid=3584 /usr/bin/touch guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=65e2cb2c-1700-0000-900a-c366000e0000 pid=3584 execve guuid=af80142d-1700-0000-900a-c366020e0000 pid=3586 /usr/bin/bash guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=af80142d-1700-0000-900a-c366020e0000 pid=3586 clone guuid=70731b2d-1700-0000-900a-c366030e0000 pid=3587 /usr/bin/bash guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=70731b2d-1700-0000-900a-c366030e0000 pid=3587 clone guuid=0f9a342d-1700-0000-900a-c366040e0000 pid=3588 /usr/bin/bash guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=0f9a342d-1700-0000-900a-c366040e0000 pid=3588 clone guuid=eb153a2d-1700-0000-900a-c366050e0000 pid=3589 /usr/bin/base64 write-file guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=eb153a2d-1700-0000-900a-c366050e0000 pid=3589 execve guuid=2adeb22d-1700-0000-900a-c366080e0000 pid=3592 /usr/bin/bash guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=2adeb22d-1700-0000-900a-c366080e0000 pid=3592 execve guuid=f0768032-1700-0000-900a-c366290e0000 pid=3625 /usr/bin/rm delete-file guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=f0768032-1700-0000-900a-c366290e0000 pid=3625 execve guuid=96b2c832-1700-0000-900a-c3662b0e0000 pid=3627 /usr/bin/bash guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=96b2c832-1700-0000-900a-c3662b0e0000 pid=3627 clone guuid=e875d032-1700-0000-900a-c3662c0e0000 pid=3628 /usr/bin/bash guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=e875d032-1700-0000-900a-c3662c0e0000 pid=3628 clone guuid=4cecf132-1700-0000-900a-c3662d0e0000 pid=3629 /usr/bin/bash guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=4cecf132-1700-0000-900a-c3662d0e0000 pid=3629 execve guuid=09174633-1700-0000-900a-c366300e0000 pid=3632 /usr/bin/rm guuid=f9035824-1700-0000-900a-c366c80d0000 pid=3528->guuid=09174633-1700-0000-900a-c366300e0000 pid=3632 execve guuid=3a96fb2d-1700-0000-900a-c3660a0e0000 pid=3594 /usr/bin/bash guuid=2adeb22d-1700-0000-900a-c366080e0000 pid=3592->guuid=3a96fb2d-1700-0000-900a-c3660a0e0000 pid=3594 clone guuid=d3f3032e-1700-0000-900a-c3660b0e0000 pid=3595 /usr/bin/bash guuid=2adeb22d-1700-0000-900a-c366080e0000 pid=3592->guuid=d3f3032e-1700-0000-900a-c3660b0e0000 pid=3595 clone guuid=13e11e2e-1700-0000-900a-c3660d0e0000 pid=3597 /usr/bin/ls guuid=2adeb22d-1700-0000-900a-c366080e0000 pid=3592->guuid=13e11e2e-1700-0000-900a-c3660d0e0000 pid=3597 execve guuid=a34d822e-1700-0000-900a-c3660f0e0000 pid=3599 /usr/bin/cat guuid=2adeb22d-1700-0000-900a-c366080e0000 pid=3592->guuid=a34d822e-1700-0000-900a-c3660f0e0000 pid=3599 execve guuid=e4aec42e-1700-0000-900a-c366110e0000 pid=3601 /usr/bin/ls guuid=2adeb22d-1700-0000-900a-c366080e0000 pid=3592->guuid=e4aec42e-1700-0000-900a-c366110e0000 pid=3601 execve guuid=87d21b2f-1700-0000-900a-c366130e0000 pid=3603 /usr/bin/mkdir guuid=2adeb22d-1700-0000-900a-c366080e0000 pid=3592->guuid=87d21b2f-1700-0000-900a-c366130e0000 pid=3603 execve guuid=a0ca722f-1700-0000-900a-c366150e0000 pid=3605 /usr/bin/mv guuid=2adeb22d-1700-0000-900a-c366080e0000 pid=3592->guuid=a0ca722f-1700-0000-900a-c366150e0000 pid=3605 execve guuid=6e1ad32f-1700-0000-900a-c366170e0000 pid=3607 /usr/bin/bash guuid=2adeb22d-1700-0000-900a-c366080e0000 pid=3592->guuid=6e1ad32f-1700-0000-900a-c366170e0000 pid=3607 clone guuid=61cdd82f-1700-0000-900a-c366190e0000 pid=3609 /usr/bin/base64 write-file guuid=2adeb22d-1700-0000-900a-c366080e0000 pid=3592->guuid=61cdd82f-1700-0000-900a-c366190e0000 pid=3609 execve guuid=a41f1f30-1700-0000-900a-c3661a0e0000 pid=3610 /usr/bin/rm delete-file guuid=2adeb22d-1700-0000-900a-c366080e0000 pid=3592->guuid=a41f1f30-1700-0000-900a-c3661a0e0000 pid=3610 execve guuid=69056a30-1700-0000-900a-c3661c0e0000 pid=3612 /usr/bin/ls guuid=2adeb22d-1700-0000-900a-c366080e0000 pid=3592->guuid=69056a30-1700-0000-900a-c3661c0e0000 pid=3612 execve guuid=9edcdb30-1700-0000-900a-c3661f0e0000 pid=3615 /usr/bin/bash guuid=2adeb22d-1700-0000-900a-c366080e0000 pid=3592->guuid=9edcdb30-1700-0000-900a-c3661f0e0000 pid=3615 clone guuid=8563e430-1700-0000-900a-c366200e0000 pid=3616 /usr/bin/base64 write-file guuid=2adeb22d-1700-0000-900a-c366080e0000 pid=3592->guuid=8563e430-1700-0000-900a-c366200e0000 pid=3616 execve guuid=fd6d3231-1700-0000-900a-c366220e0000 pid=3618 /usr/bin/ls guuid=2adeb22d-1700-0000-900a-c366080e0000 pid=3592->guuid=fd6d3231-1700-0000-900a-c366220e0000 pid=3618 execve guuid=4d51a231-1700-0000-900a-c366240e0000 pid=3620 /usr/bin/cat guuid=2adeb22d-1700-0000-900a-c366080e0000 pid=3592->guuid=4d51a231-1700-0000-900a-c366240e0000 pid=3620 execve guuid=7ac4f231-1700-0000-900a-c366260e0000 pid=3622 /usr/bin/ls guuid=2adeb22d-1700-0000-900a-c366080e0000 pid=3592->guuid=7ac4f231-1700-0000-900a-c366260e0000 pid=3622 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-16 08:17:47 UTC
File Type:
Text (Shell)
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh ea220eb097e92e797b40aa8146a01dd814566065981abd023a1e023915c2b0df

(this sample)

  
Delivery method
Distributed via web download

Comments