MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 61bed861502c8356ba044b7f3f920894207767dabc9fcd94896ddd8796cd251b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Xorbot


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 61bed861502c8356ba044b7f3f920894207767dabc9fcd94896ddd8796cd251b
SHA3-384 hash: 13d755ac99a3cf84b9f08e6a0ea25bd3c2d7fa9335993e631008bf1b696cf00c06fe8e044e6b4bcc3b1598876407c4cd
SHA1 hash: b287ae4a3d3a1eb5ce61cb1408ab3544b5c64985
MD5 hash: 38466977b872491e37f759c1a518d113
humanhash: south-robin-mockingbird-tennessee
File name:.shell
Download: download sample
Signature Xorbot
File size:211 bytes
First seen:2025-01-08 12:46:04 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 3:QnQzanFCKl2X4HMiPPtXXd9+WPtXXd9SqRDPtXXd9BSLM9Kd:lOnFflHMkl3++l3Rl3kM9Kd
TLSH T1A5D0C9CDB05114B0D9E0C9B979E2F90061A461959CC13B1848CDB8D286A8E0C3C48ED2
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://87.121.86.228/bins.shb57d6888e16f48da6ef0422e150b9972b83ccaf61a66a3c185874c8bf6ebe786 Xorbotmirai sh ua-wget Xorbot

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
90.2%
Tags:
trojan shell agent
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2025-01-08 12:53:06 UTC
File Type:
Text (Shell)
AV detection:
2 of 38 (5.26%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Xorbot

sh 61bed861502c8356ba044b7f3f920894207767dabc9fcd94896ddd8796cd251b

(this sample)

  
Delivery method
Distributed via web download

Comments