MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4176f6ee43565073813008555718f33b4cf16b9af4e2296a504608b1eba955b1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Xorbot


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 4176f6ee43565073813008555718f33b4cf16b9af4e2296a504608b1eba955b1
SHA3-384 hash: 154e132e3d16eb1c93a5defc5e05917a14eda294a7bc87073921e889cf1415bb129138909a5426f8681bca10b0afae64
SHA1 hash: 91849dc60019d805e6bcda80ccebd9783939fc5d
MD5 hash: bc1f204e139a571cbc3636e48f9bb125
humanhash: bluebird-johnny-bluebird-arkansas
File name:.shell
Download: download sample
Signature Xorbot
File size:211 bytes
First seen:2025-01-08 21:26:33 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 3:QnQzanFCKl2X4HMiaou9+pou9SqR+ou9BSLM9Kd:lOnFflHMrouIpou6ou2M9Kd
TLSH T1ADD0C9C9B06524F498C0CAB925F1B440715442EADCD08A2488CABCD04248ECCB54EB81
Magika shell
Reporter abuse_ch
Tags:sh Xorbot
URLMalware sample (SHA256 hash)SignatureTags
http://51.210.223.35/bins.shn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
128
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Threat name:
Script.Downloader.Heuristic
Status:
Malicious
First seen:
2025-01-08 22:05:04 UTC
File Type:
Text (Shell)
AV detection:
3 of 38 (7.89%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Xorbot

sh 4176f6ee43565073813008555718f33b4cf16b9af4e2296a504608b1eba955b1

(this sample)

  
Delivery method
Distributed via web download

Comments