🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 419c571ee38b7e7266d130c4b6bbc4dd0ef44d6e5f3bc02cc2cf73b762f07c86. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 419c571ee38b7e7266d130c4b6bbc4dd0ef44d6e5f3bc02cc2cf73b762f07c86
SHA3-384 hash: c37be7d5cda4bda532ee23665a8de09df7fc10c4746cc539172b0e71cc38d4b08ccb4c741297ff63bdc19ca16f478c82
SHA1 hash: ffd1703ff78260a47e6ef6944baef5f4f2879764
MD5 hash: 2e594ed4c383db1746513f16244ce5a7
humanhash: virginia-grey-fruit-october
File name:tunnel.jsp
Download: download sample
File size:19'779 bytes
First seen:2026-09-29 00:11:22 UTC
Last seen:Never
File type:
MIME type:text/plain
ssdeep 384:9ESXOq8ubm2wNae7Z02fGD44+CWmUa5Wq6BVWz7wR7RO:9ESouQN8D446jA7gFO
TLSH T1B3925F9EC3494A5CC7EC6F8990E9298E57E0C11B3C2C159DABF765C3E576A0D3034AE8
Magika asp
Reporter smica83
Tags:jsp ShinyHunters UNC6240

Intelligence


File Origin
# of uploads :
1
# of downloads :
6
Origin country :
HU HU
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
html
First seen:
2023-10-30T01:43:00Z UTC
Last seen:
2026-09-27T02:21:00Z UTC
Hits:
~1000
Gathering data
Threat name:
ByteCode-JAVA.Backdoor.WebShell
Status:
Malicious
First seen:
2023-09-06 00:06:33 UTC
File Type:
Text (Java)
AV detection:
19 of 36 (52.78%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments