MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ff5547d9ed54b2b43b4677d3785aa44eafd8cc8d91340a56c5a3dae24d3a4098. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: ff5547d9ed54b2b43b4677d3785aa44eafd8cc8d91340a56c5a3dae24d3a4098
SHA3-384 hash: bb5ce27953bc188a47832160a1688a5d573a3e891487ca058e525dab209546dd184614bd6402573d6bdebb70ad8a27fd
SHA1 hash: f4fbbd9568fb98533067ccad9961f9b226990b35
MD5 hash: b24dab2bfbd7295358b5e5cec56875e3
humanhash: minnesota-bakerloo-south-washington
File name:k.php
Download: download sample
File size:19'499 bytes
First seen:2026-03-22 03:55:11 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:A/0M3vgRjGlsaq7czsO9a4cbddrME8jyfzsO9a4cbddrME8jy4:ArmjfgzsP4cbddr7zsP4cbddrk
TLSH T1B7925CA916496C79BBC0DE7D9F3C7F0CADE4C1C02218A3ACBA4F39714A2069DDA0535D
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=85e1fefb-1600-0000-bb0f-c903f00d0000 pid=3568 /usr/bin/sudo guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576 /tmp/sample.bin guuid=85e1fefb-1600-0000-bb0f-c903f00d0000 pid=3568->guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576 execve guuid=34761400-1700-0000-bb0f-c903fb0d0000 pid=3579 /usr/bin/bash guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=34761400-1700-0000-bb0f-c903fb0d0000 pid=3579 clone guuid=5db92400-1700-0000-bb0f-c903fd0d0000 pid=3581 /usr/bin/bash guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=5db92400-1700-0000-bb0f-c903fd0d0000 pid=3581 clone guuid=c7465500-1700-0000-bb0f-c903fe0d0000 pid=3582 /usr/bin/mkdir guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=c7465500-1700-0000-bb0f-c903fe0d0000 pid=3582 execve guuid=640a2401-1700-0000-bb0f-c903000e0000 pid=3584 /usr/bin/mkdir guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=640a2401-1700-0000-bb0f-c903000e0000 pid=3584 execve guuid=e2649201-1700-0000-bb0f-c903030e0000 pid=3587 /usr/bin/mkdir guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=e2649201-1700-0000-bb0f-c903030e0000 pid=3587 execve guuid=43fbf301-1700-0000-bb0f-c903040e0000 pid=3588 /usr/bin/mkdir guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=43fbf301-1700-0000-bb0f-c903040e0000 pid=3588 execve guuid=fd496302-1700-0000-bb0f-c903060e0000 pid=3590 /usr/bin/mkdir guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=fd496302-1700-0000-bb0f-c903060e0000 pid=3590 execve guuid=ab76d002-1700-0000-bb0f-c903090e0000 pid=3593 /usr/bin/mkdir guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=ab76d002-1700-0000-bb0f-c903090e0000 pid=3593 execve guuid=e6833e03-1700-0000-bb0f-c9030b0e0000 pid=3595 /usr/bin/mkdir guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=e6833e03-1700-0000-bb0f-c9030b0e0000 pid=3595 execve guuid=d042b003-1700-0000-bb0f-c9030d0e0000 pid=3597 /usr/bin/cp guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=d042b003-1700-0000-bb0f-c9030d0e0000 pid=3597 execve guuid=ad7a4404-1700-0000-bb0f-c903100e0000 pid=3600 /usr/bin/cp guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=ad7a4404-1700-0000-bb0f-c903100e0000 pid=3600 execve guuid=8feade04-1700-0000-bb0f-c903120e0000 pid=3602 /usr/bin/cp guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=8feade04-1700-0000-bb0f-c903120e0000 pid=3602 execve guuid=92287605-1700-0000-bb0f-c903150e0000 pid=3605 /usr/bin/cp guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=92287605-1700-0000-bb0f-c903150e0000 pid=3605 execve guuid=f75d0c06-1700-0000-bb0f-c903170e0000 pid=3607 /usr/bin/cp guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=f75d0c06-1700-0000-bb0f-c903170e0000 pid=3607 execve guuid=b153a606-1700-0000-bb0f-c9031a0e0000 pid=3610 /usr/bin/cp guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=b153a606-1700-0000-bb0f-c9031a0e0000 pid=3610 execve guuid=6521a407-1700-0000-bb0f-c9031d0e0000 pid=3613 /usr/bin/cp guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=6521a407-1700-0000-bb0f-c9031d0e0000 pid=3613 execve guuid=60792d08-1700-0000-bb0f-c9031e0e0000 pid=3614 /usr/bin/cp guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=60792d08-1700-0000-bb0f-c9031e0e0000 pid=3614 execve guuid=7206b508-1700-0000-bb0f-c903200e0000 pid=3616 /usr/bin/cp guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=7206b508-1700-0000-bb0f-c903200e0000 pid=3616 execve guuid=d6723c09-1700-0000-bb0f-c903230e0000 pid=3619 /usr/bin/cp guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=d6723c09-1700-0000-bb0f-c903230e0000 pid=3619 execve guuid=15a7c009-1700-0000-bb0f-c903260e0000 pid=3622 /usr/bin/cp guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=15a7c009-1700-0000-bb0f-c903260e0000 pid=3622 execve guuid=f6794c0a-1700-0000-bb0f-c903280e0000 pid=3624 /usr/bin/cp guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=f6794c0a-1700-0000-bb0f-c903280e0000 pid=3624 execve guuid=acf2d10a-1700-0000-bb0f-c9032b0e0000 pid=3627 /usr/bin/cp guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=acf2d10a-1700-0000-bb0f-c9032b0e0000 pid=3627 execve guuid=55f4520b-1700-0000-bb0f-c9032e0e0000 pid=3630 /usr/bin/cp guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=55f4520b-1700-0000-bb0f-c9032e0e0000 pid=3630 execve guuid=e87eda0b-1700-0000-bb0f-c903300e0000 pid=3632 /usr/bin/cp guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=e87eda0b-1700-0000-bb0f-c903300e0000 pid=3632 execve guuid=4a32600c-1700-0000-bb0f-c903340e0000 pid=3636 /usr/bin/touch guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=4a32600c-1700-0000-bb0f-c903340e0000 pid=3636 execve guuid=58adce0c-1700-0000-bb0f-c903350e0000 pid=3637 /usr/bin/bash guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=58adce0c-1700-0000-bb0f-c903350e0000 pid=3637 clone guuid=60c8d70c-1700-0000-bb0f-c903360e0000 pid=3638 /usr/bin/bash guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=60c8d70c-1700-0000-bb0f-c903360e0000 pid=3638 clone guuid=fc520c0d-1700-0000-bb0f-c903370e0000 pid=3639 /usr/bin/bash guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=fc520c0d-1700-0000-bb0f-c903370e0000 pid=3639 clone guuid=82f6150d-1700-0000-bb0f-c903380e0000 pid=3640 /usr/bin/base64 write-file guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=82f6150d-1700-0000-bb0f-c903380e0000 pid=3640 execve guuid=4337b50d-1700-0000-bb0f-c9033b0e0000 pid=3643 /usr/bin/bash guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=4337b50d-1700-0000-bb0f-c9033b0e0000 pid=3643 execve guuid=5439ff13-1700-0000-bb0f-c903640e0000 pid=3684 /usr/bin/rm delete-file guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=5439ff13-1700-0000-bb0f-c903640e0000 pid=3684 execve guuid=fbf05414-1700-0000-bb0f-c903660e0000 pid=3686 /usr/bin/bash guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=fbf05414-1700-0000-bb0f-c903660e0000 pid=3686 clone guuid=c2fe5a14-1700-0000-bb0f-c903670e0000 pid=3687 /usr/bin/bash guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=c2fe5a14-1700-0000-bb0f-c903670e0000 pid=3687 clone guuid=45c08c14-1700-0000-bb0f-c903680e0000 pid=3688 /usr/bin/bash guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=45c08c14-1700-0000-bb0f-c903680e0000 pid=3688 execve guuid=83f9f514-1700-0000-bb0f-c9036b0e0000 pid=3691 /usr/bin/rm guuid=8e3fdcfe-1600-0000-bb0f-c903f80d0000 pid=3576->guuid=83f9f514-1700-0000-bb0f-c9036b0e0000 pid=3691 execve guuid=98af330e-1700-0000-bb0f-c903400e0000 pid=3648 /usr/bin/bash guuid=4337b50d-1700-0000-bb0f-c9033b0e0000 pid=3643->guuid=98af330e-1700-0000-bb0f-c903400e0000 pid=3648 clone guuid=97b03b0e-1700-0000-bb0f-c903410e0000 pid=3649 /usr/bin/bash guuid=4337b50d-1700-0000-bb0f-c9033b0e0000 pid=3643->guuid=97b03b0e-1700-0000-bb0f-c903410e0000 pid=3649 clone guuid=a7ff6b0e-1700-0000-bb0f-c903420e0000 pid=3650 /usr/bin/ls guuid=4337b50d-1700-0000-bb0f-c9033b0e0000 pid=3643->guuid=a7ff6b0e-1700-0000-bb0f-c903420e0000 pid=3650 execve guuid=7b57fc0e-1700-0000-bb0f-c903460e0000 pid=3654 /usr/bin/cat guuid=4337b50d-1700-0000-bb0f-c9033b0e0000 pid=3643->guuid=7b57fc0e-1700-0000-bb0f-c903460e0000 pid=3654 execve guuid=5595670f-1700-0000-bb0f-c903480e0000 pid=3656 /usr/bin/ls guuid=4337b50d-1700-0000-bb0f-c9033b0e0000 pid=3643->guuid=5595670f-1700-0000-bb0f-c903480e0000 pid=3656 execve guuid=4999f80f-1700-0000-bb0f-c9034b0e0000 pid=3659 /usr/bin/mkdir guuid=4337b50d-1700-0000-bb0f-c9033b0e0000 pid=3643->guuid=4999f80f-1700-0000-bb0f-c9034b0e0000 pid=3659 execve guuid=032a6810-1700-0000-bb0f-c9034d0e0000 pid=3661 /usr/bin/mv guuid=4337b50d-1700-0000-bb0f-c9033b0e0000 pid=3643->guuid=032a6810-1700-0000-bb0f-c9034d0e0000 pid=3661 execve guuid=8730e910-1700-0000-bb0f-c903500e0000 pid=3664 /usr/bin/bash guuid=4337b50d-1700-0000-bb0f-c9033b0e0000 pid=3643->guuid=8730e910-1700-0000-bb0f-c903500e0000 pid=3664 clone guuid=fa0ef410-1700-0000-bb0f-c903510e0000 pid=3665 /usr/bin/base64 write-file guuid=4337b50d-1700-0000-bb0f-c9033b0e0000 pid=3643->guuid=fa0ef410-1700-0000-bb0f-c903510e0000 pid=3665 execve guuid=aec55b11-1700-0000-bb0f-c903530e0000 pid=3667 /usr/bin/rm delete-file guuid=4337b50d-1700-0000-bb0f-c9033b0e0000 pid=3643->guuid=aec55b11-1700-0000-bb0f-c903530e0000 pid=3667 execve guuid=d658b711-1700-0000-bb0f-c903550e0000 pid=3669 /usr/bin/ls guuid=4337b50d-1700-0000-bb0f-c9033b0e0000 pid=3643->guuid=d658b711-1700-0000-bb0f-c903550e0000 pid=3669 execve guuid=f54b3512-1700-0000-bb0f-c903580e0000 pid=3672 /usr/bin/bash guuid=4337b50d-1700-0000-bb0f-c9033b0e0000 pid=3643->guuid=f54b3512-1700-0000-bb0f-c903580e0000 pid=3672 clone guuid=37393b12-1700-0000-bb0f-c903590e0000 pid=3673 /usr/bin/base64 write-file guuid=4337b50d-1700-0000-bb0f-c9033b0e0000 pid=3643->guuid=37393b12-1700-0000-bb0f-c903590e0000 pid=3673 execve guuid=3f1ca112-1700-0000-bb0f-c9035b0e0000 pid=3675 /usr/bin/ls guuid=4337b50d-1700-0000-bb0f-c9033b0e0000 pid=3643->guuid=3f1ca112-1700-0000-bb0f-c9035b0e0000 pid=3675 execve guuid=8be51813-1700-0000-bb0f-c9035e0e0000 pid=3678 /usr/bin/cat guuid=4337b50d-1700-0000-bb0f-c9033b0e0000 pid=3643->guuid=8be51813-1700-0000-bb0f-c9035e0e0000 pid=3678 execve guuid=88a26d13-1700-0000-bb0f-c903600e0000 pid=3680 /usr/bin/ls guuid=4337b50d-1700-0000-bb0f-c9033b0e0000 pid=3643->guuid=88a26d13-1700-0000-bb0f-c903600e0000 pid=3680 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-22 03:55:33 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh ff5547d9ed54b2b43b4677d3785aa44eafd8cc8d91340a56c5a3dae24d3a4098

(this sample)

  
Delivery method
Distributed via web download

Comments