🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6f94b2f7d0a57f39e500a08a24cf90177acd3c2cce1fdbdb586170d2a7d42cbe. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 2 File information Comments

SHA256 hash: 6f94b2f7d0a57f39e500a08a24cf90177acd3c2cce1fdbdb586170d2a7d42cbe
SHA3-384 hash: badaef9ba6677c7f495525396400537877720d46276f0ceb96cb0de9d79f6af5bb63b760c1c99b7ed009d86338c483ab
SHA1 hash: 86f61a6de45dee6f1b93382463ff06fe666d8585
MD5 hash: c6371ceda495b1549070482217540c4e
humanhash: mississippi-oklahoma-lamp-lion
File name:nexus.txt
Download: download sample
File size:68'490 bytes
First seen:2026-09-25 03:14:12 UTC
Last seen:Never
File type:php php
MIME type:text/x-php
ssdeep 768:FT94VpizpbtL4T1bNfqYINY79WKJ5zMLUsTeD9vM3bpHXXSl0RG+m2:FialWT1bNfqYwYcgvixq0xV
TLSH T19F63D76638EF24635217B8B8275B9B0F3255810BD009CD043EEC23D89FC5F99D9EA799
TrID 62.5% (.PHP) PHP source (5000/1)
37.5% (.HTML) HyperText Markup Language (3000/1/1)
Magika php
Reporter boredchilada2
Tags:cpanel kamp4ng nexus php php-webshell

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
CA CA
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
backdoor base64 magic masquerade obfuscated obfuscated php
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
Rule name:SUSP_shellpop_Bash
Author:Tobias Michalski
Description:Detects susupicious bash command
Reference:https://github.com/0x00-0x00/ShellPop

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

php php 6f94b2f7d0a57f39e500a08a24cf90177acd3c2cce1fdbdb586170d2a7d42cbe

(this sample)

Comments