🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2b901a472f87a14b153d836e8a611d29bd8d475a7d162fb6adfb0abf987f72f1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 2b901a472f87a14b153d836e8a611d29bd8d475a7d162fb6adfb0abf987f72f1
SHA3-384 hash: 7967fe21849a9955798be5ea3b7b5406dc639691adb031c28da88a016df83c0d0a17e8f2286c69cd95d99b811c869fca
SHA1 hash: e03c1c81cfce77afae8904e283e859a607212571
MD5 hash: fd2fab145a9d3b7ba5af19a84c7a6609
humanhash: one-bravo-three-may
File name:2b901a472f87a14b153d836e8a611d29bd8d475a7d162fb6adfb0abf987f72f1.bin
Download: download sample
File size:1'189 bytes
First seen:2026-09-12 06:08:57 UTC
Last seen:Never
File type:php php
MIME type:text/x-php
ssdeep 24:iNWFUvMhpqJ6lsSZCp6nlvP73DfFU4n1rhi4qXz:iN2XZ88L3DfFz1ViVz
TLSH T15B2184325AC0B85879183E5640ACF80E09E02949BF26886D1B5147DB4E0896D2EAEF48
Magika php
Reporter Birdo

Intelligence


File Origin
# of uploads :
1
# of downloads :
52
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-09-11T18:58:00Z UTC
Last seen:
2026-09-13T03:08:00Z UTC
Hits:
~100
Threat name:
Script-BAT.Dropper.Heuristic
Status:
Malicious
First seen:
2026-09-12 06:09:29 UTC
File Type:
Text (PHP)
AV detection:
6 of 36 (16.67%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments