MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 02d785651e84eb62c6ad7388c01c57a284b4f99144987e2e7be17b6f2a7b75ca. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Xorbot


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 02d785651e84eb62c6ad7388c01c57a284b4f99144987e2e7be17b6f2a7b75ca
SHA3-384 hash: d6f943fa7e1b23b72f287c7c88f2600081eda2f5cf5c747b04a574798fa4bafc6fdc1556c6937c535d2b24271878d08d
SHA1 hash: 6376fd79a9647680f011f34ee0dfcb3a572c6340
MD5 hash: f51402cce5997e4b5c2650c85623596a
humanhash: chicken-river-steak-hydrogen
File name:.shell
Download: download sample
Signature Xorbot
File size:208 bytes
First seen:2025-05-28 18:26:32 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 3:QnQzanFCKl2X4HMiDvdLeHKWlQvdLeHKWxqR3vdLeHKWGSLM9Kd:lOnFflHM4AliAMAlM9Kd
TLSH T15DD012C9E95179B0D8C6CDF925E2F50067604595DDC20F35EEC8F89A44C9F0C304DE41
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://141.98.11.82/bins.sha67a3cb487854437d1f43246571f204ef58507deb3c12e795ec32989c0ae0a59 Xorbotsh ua-wget Xorbot

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
96.5%
Tags:
trojan agent virus
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Threat name:
Script.Trojan.Boxter
Status:
Malicious
First seen:
2025-05-29 02:07:00 UTC
File Type:
Text (Shell)
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Xorbot

sh 02d785651e84eb62c6ad7388c01c57a284b4f99144987e2e7be17b6f2a7b75ca

(this sample)

  
Delivery method
Distributed via web download

Comments