MALICIOUS — 63559cb87098de64cbe5f1d981bf782283a8e24e3d81926a3ddb80cae5b5d856.sh

MALICIOUS — 63559cb87098de64cbe5f1d981bf782283a8e24e3d81926a3ddb80cae5b5d856.sh is a shell sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the WebShell family. 3 of 50 detection engines flagged it, exhibiting 2 ATT&CK techniques.

Identification

Source: MalwareBazaar · first seen 2026-07-26T00:00:00.000Z · SHA-256 verified

Detections (3 of 50 engines)

MITRE ATT&CK

Why this verdict

The malicious score of 96/100 is the fusion of 9 weighted signals:

Dynamic analysis (linux)

892 behavior events · 0 ATT&CK techniques · 1 dropped files.

Runtime network

Dropped files

Embedded domains

Embedded IP addresses

More WebShell samples · Latest analyzed threats · ATT&CK coverage

Analyzed on MalwareAnalyzer by Cyble · Open interactive report