🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f878eccf4b300f8085ceb866a2f71aed10428109e2cb89079a685699c6ef0941. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: f878eccf4b300f8085ceb866a2f71aed10428109e2cb89079a685699c6ef0941
SHA3-384 hash: a46c74384e731379db8ebcafaf3bf8e0ac50975aa833e7301ed389b01b9f92889376121cd8db5c9426af6067bfb57729
SHA1 hash: 91879d05b5d15dfb81c7dfb2a5d5dc8cb3aaf7f0
MD5 hash: 9ac325d6bc66ee68d2bf5804462a339b
humanhash: grey-earth-louisiana-helium
File name:nx_verify-iteration-3.sh
Download: download sample
File size:1'108 bytes
First seen:2026-10-02 04:09:39 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:tu61823AMxm+JAMxu90p5AMxT8J18Il9lUpWflV838rlzkaFl:tuU8qGqOup5z8D8IXGpWfX838rB
TLSH T12B11659DA0835DCB2EFE0EB9322BD5102146C32F591B2DD68B4371EE10992CC6298AF1
Magika shell
Reporter boredchilada2
Tags:citrix-netscaler cve-2026-88771 sh shell-script webshell

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
CA CA
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=7012ce1a-1a00-0000-8c65-93767f070000 pid=1919 /usr/bin/sudo guuid=5c619d1c-1a00-0000-8c65-937683070000 pid=1923 /tmp/sample.bin write-file guuid=7012ce1a-1a00-0000-8c65-93767f070000 pid=1919->guuid=5c619d1c-1a00-0000-8c65-937683070000 pid=1923 execve guuid=73d7dc1c-1a00-0000-8c65-937684070000 pid=1924 /usr/bin/mkdir guuid=5c619d1c-1a00-0000-8c65-937683070000 pid=1923->guuid=73d7dc1c-1a00-0000-8c65-937684070000 pid=1924 execve guuid=116fea1d-1a00-0000-8c65-937685070000 pid=1925 /usr/bin/id guuid=5c619d1c-1a00-0000-8c65-937683070000 pid=1923->guuid=116fea1d-1a00-0000-8c65-937685070000 pid=1925 execve guuid=8d22bc1e-1a00-0000-8c65-937689070000 pid=1929 /usr/bin/uname guuid=5c619d1c-1a00-0000-8c65-937683070000 pid=1923->guuid=8d22bc1e-1a00-0000-8c65-937689070000 pid=1929 execve guuid=260b1e1f-1a00-0000-8c65-93768a070000 pid=1930 /usr/bin/hostname guuid=5c619d1c-1a00-0000-8c65-937683070000 pid=1923->guuid=260b1e1f-1a00-0000-8c65-93768a070000 pid=1930 execve guuid=9f6e721f-1a00-0000-8c65-93768c070000 pid=1932 /usr/bin/id guuid=5c619d1c-1a00-0000-8c65-937683070000 pid=1923->guuid=9f6e721f-1a00-0000-8c65-93768c070000 pid=1932 execve guuid=fd0bc91f-1a00-0000-8c65-93768e070000 pid=1934 /usr/bin/uname guuid=5c619d1c-1a00-0000-8c65-937683070000 pid=1923->guuid=fd0bc91f-1a00-0000-8c65-93768e070000 pid=1934 execve guuid=e5b40420-1a00-0000-8c65-937690070000 pid=1936 /usr/bin/hostname guuid=5c619d1c-1a00-0000-8c65-937683070000 pid=1923->guuid=e5b40420-1a00-0000-8c65-937690070000 pid=1936 execve guuid=4e7c4620-1a00-0000-8c65-937691070000 pid=1937 /usr/bin/id guuid=5c619d1c-1a00-0000-8c65-937683070000 pid=1923->guuid=4e7c4620-1a00-0000-8c65-937691070000 pid=1937 execve guuid=863aa320-1a00-0000-8c65-937693070000 pid=1939 /usr/bin/uname guuid=5c619d1c-1a00-0000-8c65-937683070000 pid=1923->guuid=863aa320-1a00-0000-8c65-937693070000 pid=1939 execve guuid=a3da0321-1a00-0000-8c65-937694070000 pid=1940 /usr/bin/hostname guuid=5c619d1c-1a00-0000-8c65-937683070000 pid=1923->guuid=a3da0321-1a00-0000-8c65-937694070000 pid=1940 execve guuid=dd429921-1a00-0000-8c65-937697070000 pid=1943 /usr/bin/chmod guuid=5c619d1c-1a00-0000-8c65-937683070000 pid=1923->guuid=dd429921-1a00-0000-8c65-937697070000 pid=1943 execve guuid=7aca3822-1a00-0000-8c65-93769a070000 pid=1946 /usr/bin/chmod guuid=5c619d1c-1a00-0000-8c65-937683070000 pid=1923->guuid=7aca3822-1a00-0000-8c65-93769a070000 pid=1946 execve guuid=bebcc322-1a00-0000-8c65-93769c070000 pid=1948 /usr/bin/chmod guuid=5c619d1c-1a00-0000-8c65-937683070000 pid=1923->guuid=bebcc322-1a00-0000-8c65-93769c070000 pid=1948 execve guuid=81724023-1a00-0000-8c65-93769e070000 pid=1950 /usr/bin/chmod guuid=5c619d1c-1a00-0000-8c65-937683070000 pid=1923->guuid=81724023-1a00-0000-8c65-93769e070000 pid=1950 execve guuid=51b49223-1a00-0000-8c65-9376a0070000 pid=1952 /usr/bin/sed guuid=5c619d1c-1a00-0000-8c65-937683070000 pid=1923->guuid=51b49223-1a00-0000-8c65-9376a0070000 pid=1952 execve guuid=d5321c24-1a00-0000-8c65-9376a1070000 pid=1953 /usr/bin/cat guuid=5c619d1c-1a00-0000-8c65-937683070000 pid=1923->guuid=d5321c24-1a00-0000-8c65-9376a1070000 pid=1953 execve
Threat name:
Win32.Backdoor.WebShell
Status:
Malicious
First seen:
2026-10-02 04:10:24 UTC
File Type:
Text (PHP)
AV detection:
5 of 24 (20.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments