MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8b4c515313d99f78da8e522fd2dee37bd2520bea55568c428c21910a8a4f6c3c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Xorbot


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 8b4c515313d99f78da8e522fd2dee37bd2520bea55568c428c21910a8a4f6c3c
SHA3-384 hash: 35a0e8ac2ef1375099bd9645fd25a2e67d969cf44156a6a80b2ddd8d4d55b0f5afc9da78a4ede4a900830f491abb0243
SHA1 hash: 82943bb170155cc3e4d9386a2f93dece81bb1d86
MD5 hash: 860ca8de4c29abcdb13cefb41c501dbf
humanhash: uranus-rugby-paris-oklahoma
File name:.shell
Download: download sample
Signature Xorbot
File size:205 bytes
First seen:2025-04-21 06:58:13 UTC
Last seen:2025-04-22 09:10:44 UTC
File type: sh
MIME type:text/plain
ssdeep 3:QnQzanFCKl2X4HMirLDoVUcZx4LDoVUcZNqRvLDoVUcZaSLM9Kd:lOnFflHMIDoVUGxGDoVUGADoVUGpM9Kd
TLSH T18FD012C9D0A155B0D8C0C9FD25E1F401605182E5DDC20AD4CCC8F8D042C8F8FA44CE41
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://94.26.90.14/bins.sha3f5af7cf973a231699835ad84beeb34d1dd8099cbae77cf325eec189335c797 Xorbotsh ua-wget Xorbot

Intelligence


File Origin
# of uploads :
2
# of downloads :
93
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
97.4%
Tags:
trojan agent virus
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Threat name:
Script.Trojan.Boxter
Status:
Malicious
First seen:
2025-04-21 19:41:32 UTC
File Type:
Text (Shell)
AV detection:
7 of 24 (29.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Xorbot

sh 8b4c515313d99f78da8e522fd2dee37bd2520bea55568c428c21910a8a4f6c3c

(this sample)

  
Delivery method
Distributed via web download

Comments