🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c48da982aabb6f9617b9f57dd2f27e671ede64b326594b730b3105fb6bf3ecf2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: c48da982aabb6f9617b9f57dd2f27e671ede64b326594b730b3105fb6bf3ecf2
SHA3-384 hash: 22cedcb32d3e6bba4dd1110b736dc16b3c083a59271bd7caf3b4b3d3d2e6dc6bc89d15457f0a79190331853c8750e69d
SHA1 hash: b629ed7b132ebb9e6b4418c5a0e0a96cb76942dc
MD5 hash: a607a36f1d391f6259ff0088d6d0543c
humanhash: mike-carbon-friend-fanta
File name:c48da982aabb6f9617b9f57dd2f27e671ede64b326594b730b3105fb6bf3ecf2.bin
Download: download sample
File size:1'193 bytes
First seen:2026-09-16 12:12:11 UTC
Last seen:Never
File type:php php
MIME type:text/x-php
ssdeep 24:iNWFUvMhpqJ6lsSZCp6nlvP73DfFU4a1rhi4qXz:iN2XZ88L3DfF21ViVz
TLSH T17D2184325AC0B85879183E6640ECF80E09E02949BF26886D1B6147DB4E0896D2EAEF48
Magika php
Reporter Birdo

Intelligence


File Origin
# of uploads :
1
# of downloads :
57
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-09-14T17:26:00Z UTC
Last seen:
2026-09-18T10:07:00Z UTC
Hits:
~100
Threat name:
Script-BAT.Dropper.Heuristic
Status:
Malicious
First seen:
2026-09-16 12:13:17 UTC
File Type:
Text (PHP)
AV detection:
6 of 36 (16.67%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments