MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 68746fc30c09671a367a3c6ed4fdfec7e9caeb919390391f77084c832c0af740. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XorDDoS


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 68746fc30c09671a367a3c6ed4fdfec7e9caeb919390391f77084c832c0af740
SHA3-384 hash: 68258a8b93d14f385e06899f97816f10fe7206da31f56e02b12f4103589e64d9e740ef5f4d0915dd49535d43169c406b
SHA1 hash: 46ac0720ee46f16ce9fd0e5f9e50f82461075dd0
MD5 hash: 1839048de4489995c31f7200039cd8c4
humanhash: six-autumn-london-carolina
File name:p.sh
Download: download sample
Signature XorDDoS
File size:1'243 bytes
First seen:2025-08-14 21:06:32 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:fN7Pvj3RqpZ5lFTKGtypIGo39L6mvkRexV5O:V7DhcZbFTFty5s9L1vkReVM
TLSH T17121299955FA289075CD893F90AD9E8C8FCB2D964458120C63DFFFA8D0B856879C8334
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://89.32.41.16/p.txtc3714fc0446a1adaedbc86e3dd0b2121e65b34cc3d40494f709c6873fa0d56bc XorDDoSopendir Xorddos
http://89.32.41.16/r.txtn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
27
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2025-08-14 21:09:35 UTC
File Type:
Text (Shell)
AV detection:
6 of 24 (25.00%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

XorDDoS

sh 68746fc30c09671a367a3c6ed4fdfec7e9caeb919390391f77084c832c0af740

(this sample)

  
Delivery method
Distributed via web download

Comments