MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4a9320ff6ecf7c6e77b9b3fe09438fd61d7867309a8a6133abaab8b03c9df4a8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Xorbot


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 4a9320ff6ecf7c6e77b9b3fe09438fd61d7867309a8a6133abaab8b03c9df4a8
SHA3-384 hash: aef037dd34f962484c235b28a04f7bb61336cf86f73763b683b8c77ea14f0d74dba4127be48d1d46829ac2075d54232d
SHA1 hash: ceaf321afb8791d6e8ed10c9955516eac2dd1bb1
MD5 hash: 54b9e44f44ddf9b393d237d404df8daf
humanhash: quebec-mockingbird-kentucky-white
File name:.shell
Download: download sample
Signature Xorbot
File size:208 bytes
First seen:2024-12-24 16:36:21 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 3:QnQzanFCKl2X4HMilLwooxyLwooNqRRLwooaSLM9Kd:lOnFflHMewooxYwoo2woopM9Kd
TLSH T1F0D012C9D05264B0D8C0AAFD36E1FC407071B5D69CDD4A54CCC8F8B052C9F1C2048E4D
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://38.43.93.139/bins.sh1e2563334e1d3cad772d99f6c44d5b3f1ce4d84f81bac2298e5a01653a1e7e80 Xorbotmirai sh Xorbot

Intelligence


File Origin
# of uploads :
1
# of downloads :
98
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Result
Verdict:
UNKNOWN
Threat name:
Script.Downloader.Heuristic
Status:
Malicious
First seen:
2024-12-20 23:08:26 UTC
File Type:
Text (Shell)
AV detection:
3 of 38 (7.89%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Xorbot

sh 4a9320ff6ecf7c6e77b9b3fe09438fd61d7867309a8a6133abaab8b03c9df4a8

(this sample)

  
Delivery method
Distributed via web download

Comments