🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b2f650febac82738b39bdf1e8b246841c5aff5c1e3adba3f57fa2e274439bd89. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: b2f650febac82738b39bdf1e8b246841c5aff5c1e3adba3f57fa2e274439bd89
SHA3-384 hash: ae8a9408b1f88c3f070296bde904f1f54dad0b83b4f1673e103e2b8d380f8bbe7f1fd7859132d30c62c18fe8f71f82b1
SHA1 hash: 3ec8d82b3828bcb245152c5c4b290aebbc6d5cfb
MD5 hash: 751f148fa7064a9a0de0a8eade4b3431
humanhash: may-kansas-muppet-victor
File name:plugin-autoupdate.php
Download: download sample
File size:654 bytes
First seen:2026-10-01 10:39:41 UTC
Last seen:Never
File type:php php
MIME type:text/plain
ssdeep 12:BX/SxAjphJt9E6WyplQGAQ0AE0hfUhW8AFDpoDA9teU/X+oiC8TQiNyq:RHjphjGUgjQheenoD+tevoY0iNyq
TLSH T1A4F0D3915659FD30179BDFE106CEA412B1A4433B53111A2631AE4D7A9DB082542F7FDC
Magika txt
Reporter emilstahl
Tags:ClickFix GIF89a-polyglot php webshell wordpress

Intelligence


File Origin
# of uploads :
1
# of downloads :
49
Origin country :
DK DK
Vendor Threat Intelligence
No detections
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2026-10-01 11:06:12 UTC
File Type:
Text (PHP)
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments