s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-1c2a32a448a3cbf99e2d69f6a4671fce90753808cdf29e441277d20832129365 high

📛 Threat Title

Unknown: k.php

Category: Unknown First seen: Last updated: Source: Abuse.ch

Description

File type: sh. Size: 45506 bytes. Tags: sh. Reporter: abuse_ch. First seen: 2026-05-13 19:11:37.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain k.php VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/k.php

IOC database

Type
domain
Value
k.php
First seen
Last seen
Attached to this threat
Appears in
14 threats
Description
Extracted from Threat MB-8cbc78702771f69eb7942d6476a214673d8f36ae1055d6610af0c48137af30c0

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/k.php

hash_sha256 1c2a32a448a3cbf99e2d69f6a4671fce90753808cdf29e441277d20832129365 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/1c2a32a448a3cbf99e2d69f6a4671fce90753808cdf29e441277d20832129365
1 feed

IOC database

Type
hash_sha256
Value
1c2a32a448a3cbf99e2d69f6a4671fce90753808cdf29e441277d20832129365
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/1c2a32a448a3cbf99e2d69f6a4671fce90753808cdf29e441277d20832129365

hash_sha1 6251e869e6543c0f3fc3ff4f29190c589fa992fa VT 25 / 75 2 feeds

IOC database

Type
hash_sha1
Value
6251e869e6543c0f3fc3ff4f29190c589fa992fa
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Flagged by 25 of 75 VirusTotal vendors

VendorVerdictDetection
ALYac malicious Trojan.GenericKDZ.116943
Arcabit malicious Trojan.Generic.D1C8CF
Avast malicious BV:Agent-CEL [Trj]
AVG malicious BV:Agent-CEL [Trj]
Avira malicious TR/BAT.Agent.CEL
BitDefender malicious Trojan.GenericKDZ.116943
CTX malicious shell.trojan.generickdz
Cynet malicious Malicious (score: 99)
Emsisoft malicious Trojan.GenericKDZ.116943 (B)
ESET-NOD32 malicious Linux/Agent.AOF trojan
F-Secure malicious Trojan.TR/BAT.Agent.CEL
Fortinet malicious BASH/Agent.AOF!tr
GData malicious Trojan.GenericKDZ.116943
Google malicious Detected
huorong malicious Backdoor/Linux.Agent.as
Kaspersky malicious HEUR:Trojan-Downloader.Shell.Agent.bc
Microsoft malicious TrojanDownloader:Script/Malgent.STD!MSR
MicroWorld-eScan malicious Trojan.GenericKDZ.116943
NANO-Antivirus malicious Trojan.Script.Dropper.kpvdnu
Rising malicious Downloader.Agent/BASH!9.67899 (XSE:WFNFX0JBVDp4A8rgf9LUkbys4ZR/N1vC)
Skyhigh malicious Linux/Downloader.mu
Tencent malicious Trojan-DL.Linux.Agent.505004
TrellixENS malicious Linux/Downloader.mu
Varist malicious Unix/Agent.VA
VIPRE malicious Trojan.GenericKDZ.116943

Details From VirusTotal

Basic Properties
MD507de0c936433ed95b47b671925cd56ed
SHA-16251e869e6543c0f3fc3ff4f29190c589fa992fa
SHA-2561c2a32a448a3cbf99e2d69f6a4671fce90753808cdf29e441277d20832129365
SSDEEP768:bU+19GKYpr9GKYp82fkR4nnA9GKYpr9GKYp82fkR4nnx:bU+mco
TLSHT1B9138D6956857C24AE99883B1C7E2F0CB9A983E1310451EDBFCB3CF58C19A9CD21971D
File typeShell script
File type tagshell
File extensionsh
MagicBourne-Again shell script, ASCII text executable, with very long lines (17446u)
File size44.4 KB
History
First seen on VirusTotal2026-05-13 19:13 UTC
Last submission2026-05-13 19:13 UTC
Last analysis2026-05-13 19:13 UTC
Last modified on VirusTotal2026-05-14 19:31 UTC
Known Names
  • _1c2a32a448a3cbf99e2d69f6a4671fce90753808cdf29e441277d20832129365.sh
hash_md5 07de0c936433ed95b47b671925cd56ed VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/07de0c936433ed95b47b671925cd56ed
2 feeds

IOC database

Type
hash_md5
Value
07de0c936433ed95b47b671925cd56ed
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/07de0c936433ed95b47b671925cd56ed

References (1)

Remediations (10)

  • web:community.freepbx.org

    If you were impacted by the restapps security regression a week or two ago, it is possible you were hit with a php script that is currently labeled " k.php " If you want to see if you were compromised by this script, I've included some content below that you can check. I do not claim to have identified everything, but I'm hoping this might help someone. Anyways, here are the places you ...

  • web:cyrisk.com

    Addressing PHP Vulnerabilities in Common Technologies In the ever-evolving landscape of cybersecurity, keeping software up to date is crucial for maintaining the security and functionality of your systems. A common issue faced by many organizations is outdated PHP installations, which can leave systems vulnerable to security risks. This article provides remediation instructions for upgrading ...

  • web:dipsylala.github.io

    CWE-522: Insufficiently Protected Credentials - PHP Overview Insufficiently protected credentials in PHP commonly appear as database passwords or API keys hardcoded directly in config.php, committed .env files, or credentials embedded in source code committed to version control.

  • web:security.stackexchange.com

    Use the Runkit extension This allows you to redefine functions, including PHP's builtin ones. Note that the runkit sandbox is not intended to provide much isolation - it does allow you to programmatically interact with PHP code running in a different thread / environment.

  • web:www.8isoft.com

    For a step-by-step guide on PHP remediation using 8iSoft YODA, don't miss our exclusive tutorial. Click here to watch the video and enhance your understanding of effective vulnerability management.

  • web:www.bleepingcomputer.com

    Threat intelligence company GreyNoise warns that a critical PHP remote code execution vulnerability that impacts Windows systems is now under mass exploitation.

  • web:www.netsolutions.com

    In this blow, we discuss PHP vulnerabilities like SQL injection attacks, cross-site scripting, session hijacking and how to fix them.

  • web:www.siteguarding.com

    Detecting and Removing PHP Webshells: Tools, Indicators & Real Case Studies Compromised PHP sites often hide webshells - small scripts that give attackers remote command execution, file management, database access, and persistence.

  • web:www.vicarius.io

    CVE-2026-40176 - Remediation Script for PHP Composer Command Injection Workaround. .DESCRIPTION This script implements a non-patch workaround to mitigate CVE-2026-40176, a command injection vulnerability in PHP Composer 's Perforce VCS driver. Since the vulnerability is triggered when Composer processes Perforce repository declarations in ...

  • web:www.wiz.io

    Understand the critical aspects of CVE-2025-1861 with a detailed vulnerability assessment, exploitation potential, affected technologies, and remediation guidance.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.