MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1ee0b487163280ff193f2f37cc06d94285d2fcf413a06c9c6904ab386eff7ccc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 1ee0b487163280ff193f2f37cc06d94285d2fcf413a06c9c6904ab386eff7ccc
SHA3-384 hash: 8d27ff2ab24d2e49db2b4eff2ac412cd1823a7f6f01c7beca60dcbfd287aca98e8ef29932cc234d73a3d9d5706453961
SHA1 hash: dd937834399fb9826e22fb9725ff8523fb849d76
MD5 hash: 44ede4f1cde6b8f1c6b15390cd5616bf
humanhash: music-kansas-burger-three
File name:1.php
Download: download sample
File size:68 bytes
First seen:2026-06-10 12:45:58 UTC
Last seen:Never
File type:php php
MIME type:text/x-php
ssdeep 3:iFRARO/6xHtYTEd8xDWHbCI:iFm0/ZE2xKHbCI
TLSH T12BA002D34555BC6417CB4EB5A501C8595069A6885B99DB900F66F2CCC00EE9CACC3437
Magika php
Reporter Ation
Tags:php

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
CN CN
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
70%
Tags:
infosteal
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
backdoor
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-10T09:49:00Z UTC
Last seen:
2026-06-12T01:44:00Z UTC
Hits:
~10
Detections:
HEUR:Backdoor.PHP.WebShell.gen
Threat name:
Script-PHP.Backdoor.WebShell
Status:
Malicious
First seen:
2026-06-10 12:46:56 UTC
File Type:
Text (PHP)
AV detection:
14 of 23 (60.87%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments