ph.sh
Classification: Malicious
ph.sh is a malicious file sample. Linked to Kinsing malware. Reported by 2 threat sources, last seen 2026-04-05.
Detection summary
- 0 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: KINSING (S0599)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Xmrig | Triage | 2026-04-05 06:19:18 | 2026-04-05 06:19:18 | malicious-activity | |
| Kinsing | Triage | 2026-04-04 00:17:51 | 2026-04-04 00:17:51 | malicious-activity | S0599 Kinsing |
| Kinsing_rootkit | Triage | 2026-03-29 12:11:57 | 2026-03-30 12:21:35 | malicious-activity | |
| Kinsing | MalwareBazaar Abuse.ch | 2026-03-27 13:50:28 | 2026-03-27 13:50:28 | malicious-activity | S0599 Kinsing |
Tags
kinsing kinsing_rootkit xmrig antivm defense_evasion discovery exection execution linux loader miner persistence privilege_escalation rootkit upxSample information
- Filenames
- ph.sh
- MD5
946cf98b381af1ef5fb347a95430a77b- SHA-1
b66e7d530c645a29819f319d1245c1e188638cf9- SHA-256
e533f1531ca20a072c5bab4ddbeeda3d7014e408320ca8507802e2b7b402261a- First indexed
- 2026-03-27 13:50:28
- Last updated
- 2026-07-15 12:08:36