MB-f23afaa55b5f8711942f04dac1ac4993ea52833f67e3ae023fdc48bf643ee631
high
📛 Threat Title
Unknown: k.php
Description
File type: sh. Size: 45518 bytes. Tags: sh. Reporter: abuse_ch. First seen: 2026-05-15 06:54:39.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
k.php
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/k.php
IOC database
- Type
- domain
- Value
k.php- First seen
- Last seen
- Attached to this threat
- Appears in
- 14 threats
- Description
- Extracted from Threat MB-8cbc78702771f69eb7942d6476a214673d8f36ae1055d6610af0c48137af30c0
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/k.php
hash_sha256
f23afaa55b5f8711942f04dac1ac4993ea52833f67e3ae023fdc48bf643ee631
VT 29 / 74
1 feed
IOC database
- Type
- hash_sha256
- Value
f23afaa55b5f8711942f04dac1ac4993ea52833f67e3ae023fdc48bf643ee631- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Unknown
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 29 of 74 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Trojan[downloader]:Linux/Malgent.SS#2XGB |
| ALYac | malicious | Trojan.GenericKDZ.116929 |
| Arcabit | malicious | Trojan.Generic.D1C8C1 |
| Avast | malicious | BV:Agent-CEL [Trj] |
| AVG | malicious | BV:Agent-CEL [Trj] |
| Avira | malicious | TR/BAT.Agent.CEL |
| BitDefender | malicious | Trojan.GenericKDZ.116929 |
| CTX | malicious | shell.trojan.generickdz |
| Cynet | malicious | Malicious (score: 99) |
| Emsisoft | malicious | Trojan.GenericKDZ.116929 (B) |
| ESET-NOD32 | malicious | Linux/Agent.AOF trojan |
| F-Secure | malicious | Trojan.TR/BAT.Agent.CEL |
| Fortinet | malicious | BASH/Agent.AOF!tr |
| GData | malicious | Trojan.GenericKDZ.116929 |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Agent.as |
| Kaspersky | malicious | HEUR:Trojan-Downloader.Shell.Agent.bc |
| Lionic | malicious | Trojan.Script.Agent.a!c |
| McAfeeD | malicious | ti!F23AFAA55B5F |
| Microsoft | malicious | TrojanDownloader:Script/Malgent.STD!MSR |
| MicroWorld-eScan | malicious | Trojan.GenericKDZ.116929 |
| NANO-Antivirus | malicious | Trojan.Script.Dropper.kpvdnu |
| Rising | malicious | Downloader.Agent/BASH!9.67894 (XSE:WFNFX0JBVDpwI8rwbtqUkZys8ZR/P1vy) |
| Skyhigh | malicious | Linux/Downloader.mu |
| Symantec | malicious | Trojan.Gen.MBT |
| Tencent | malicious | Trojan-DL.Linux.Agent.505004 |
| TrellixENS | malicious | Linux/Downloader.mu |
| Varist | malicious | Unix/Agent.VA |
| VIPRE | malicious | Trojan.GenericKDZ.116929 |
Details From VirusTotal
Basic Properties
| MD5 | 6115adcf0e69c6cae75b58fbda54e8c3 |
| SHA-1 | f3be6a971fae437b9b052491a5cf290c8c579f96 |
| SHA-256 | f23afaa55b5f8711942f04dac1ac4993ea52833f67e3ae023fdc48bf643ee631 |
| SSDEEP | 768:bf+z9GKYpr9GKYp82fkR4nnA9GKYpr9GKYp82fkR4nnx:bf+Uco |
| TLSH | T1EC137D6966857C24AE99883B1C7E2F0CB9A983E1310451DDBFCB3CF58C19A9CD21971D |
| File type | Shell script |
| File type tag | shell |
| File extension | sh |
| Magic | Bourne-Again shell script, ASCII text executable, with very long lines (17446u) |
| File size | 44.5 KB |
History
| First seen on VirusTotal | 2026-05-15 07:00 UTC |
| Last submission | 2026-05-15 07:00 UTC |
| Last analysis | 2026-05-15 12:02 UTC |
| Last modified on VirusTotal | 2026-05-22 12:02 UTC |
Known Names
_f23afaa55b5f8711942f04dac1ac4993ea52833f67e3ae023fdc48bf643ee631.sh
hash_sha1
f3be6a971fae437b9b052491a5cf290c8c579f96
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/f3be6a971fae437b9b052491a5cf290c8c579f96
1 feed
IOC database
- Type
- hash_sha1
- Value
f3be6a971fae437b9b052491a5cf290c8c579f96- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/f3be6a971fae437b9b052491a5cf290c8c579f96
hash_md5
6115adcf0e69c6cae75b58fbda54e8c3
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/6115adcf0e69c6cae75b58fbda54e8c3
1 feed
IOC database
- Type
- hash_md5
- Value
6115adcf0e69c6cae75b58fbda54e8c3- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/6115adcf0e69c6cae75b58fbda54e8c3
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: sh. Size: 45518 bytes. Tags: sh. Reporter: abuse_ch. First seen: 2026-05-15 06:54:39.
Remediations (10)
-
web:community.freepbx.org
If you were impacted by the restapps security regression a week or two ago, it is possible you were hit with a php script that is currently labeled " k.php " If you want to see if you were compromised by this script, I've included some content below that you can check. I do not claim to have identified everything, but I'm hoping this might help someone. Anyways, here are the places you ...
-
web:cyrisk.com
Addressing PHP Vulnerabilities in Common Technologies In the ever-evolving landscape of cybersecurity, keeping software up to date is crucial for maintaining the security and functionality of your systems. A common issue faced by many organizations is outdated PHP installations, which can leave systems vulnerable to security risks. This article provides remediation instructions for upgrading ...
-
web:dipsylala.github.io
CWE-522: Insufficiently Protected Credentials - PHP Overview Insufficiently protected credentials in PHP commonly appear as database passwords or API keys hardcoded directly in config.php, committed .env files, or credentials embedded in source code committed to version control.
-
web:security.stackexchange.com
Use the Runkit extension This allows you to redefine functions, including PHP's builtin ones. Note that the runkit sandbox is not intended to provide much isolation - it does allow you to programmatically interact with PHP code running in a different thread / environment.
-
web:www.8isoft.com
For a step-by-step guide on PHP remediation using 8iSoft YODA, don't miss our exclusive tutorial. Click here to watch the video and enhance your understanding of effective vulnerability management.
-
web:www.bleepingcomputer.com
Threat intelligence company GreyNoise warns that a critical PHP remote code execution vulnerability that impacts Windows systems is now under mass exploitation.
-
web:www.netsolutions.com
In this blow, we discuss PHP vulnerabilities like SQL injection attacks, cross-site scripting, session hijacking and how to fix them.
-
web:www.siteguarding.com
Detecting and Removing PHP Webshells: Tools, Indicators & Real Case Studies Compromised PHP sites often hide webshells - small scripts that give attackers remote command execution, file management, database access, and persistence.
-
web:www.vicarius.io
CVE-2026-40176 - Remediation Script for PHP Composer Command Injection Workaround. .DESCRIPTION This script implements a non-patch workaround to mitigate CVE-2026-40176, a command injection vulnerability in PHP Composer 's Perforce VCS driver. Since the vulnerability is triggered when Composer processes Perforce repository declarations in ...
-
web:www.wiz.io
Understand the critical aspects of CVE-2025-1861 with a detailed vulnerability assessment, exploitation potential, affected technologies, and remediation guidance.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.