MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 123ea06da51088cde0a40415b6eccb4b3bb7d6d3c6b791ca849940cdc70b992c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 3 File information Comments

SHA256 hash: 123ea06da51088cde0a40415b6eccb4b3bb7d6d3c6b791ca849940cdc70b992c
SHA3-384 hash: 74ddb61af17b296b1a5be78d4e9cbc3aed150b444ef664134efc1531c9f8b3af38d3ee2ee2307b0b0bca2cf5cebdf019
SHA1 hash: 4b42238e3d8003eac111aa6d6ef63585fe818f11
MD5 hash: c9ab864cae87496922c5477fd01dcc1f
humanhash: bakerloo-mobile-oklahoma-utah
File name:shell.php
Download: download sample
File size:32 bytes
First seen:2026-06-14 16:04:04 UTC
Last seen:Never
File type:php php
MIME type:text/x-php
ssdeep 3:E1IxmRF7:EaxmRF7
TLSH TNULL
Magika php
Reporter Ation
Tags:php

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
CN CN
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
96.5%
Tags:
chopper hope
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
apt backdoor
Verdict:
Malicious
File Type:
unix shell
First seen:
2021-05-17T23:13:00Z UTC
Last seen:
2026-06-14T19:20:00Z UTC
Hits:
~100
Threat name:
Script-PHP.Backdoor.SinoChoper
Status:
Malicious
First seen:
2021-05-20 16:28:20 UTC
File Type:
Text (PHP)
AV detection:
13 of 41 (31.71%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:APT_WebShell_Tiny_1
Author:Florian Roth (Nextron Systems)
Description:Detetcs a tiny webshell involved in the Australian Parliament House network compromise
Reference:https://twitter.com/cyb3rops/status/1097423665472376832
Rule name:APT_WebShell_Tiny_1_RID2DFE
Author:Florian Roth
Description:Detetcs a tiny webshell involved in the Australian Parliament House network compromise
Reference:https://twitter.com/cyb3rops/status/1097423665472376832
Rule name:ChinaChopper_Generic
Author:Florian Roth (Nextron Systems)
Description:China Chopper Webshells - PHP and ASPX
Reference:https://www.fireeye.com/content/dam/legacy/resources/pdfs/fireeye-china-chopper-report.pdf

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments