MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9781861f24fb1059ded43d876e310c11948efdc43e7a64655abf76d919a7ebd0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Xorbot


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 9781861f24fb1059ded43d876e310c11948efdc43e7a64655abf76d919a7ebd0
SHA3-384 hash: 5442d84c08256b234676235a813a86636b92b7a0bcb6d6db5d59b30db11b4cbb3f21d0a4964b44fe705e9a42c65967e1
SHA1 hash: ced046914f12c6d9f69500c45c34b285b53fe777
MD5 hash: 579baa889d215173aece20231fa02269
humanhash: bluebird-west-iowa-south
File name:.shell
Download: download sample
Signature Xorbot
File size:214 bytes
First seen:2025-05-01 16:17:44 UTC
Last seen:2025-05-03 06:40:41 UTC
File type: sh
MIME type:text/plain
ssdeep 3:QnQzanFCKl2X4HMiB3L5ZM+S3L5ZMSqR13L5ZMBSLM9Kd:lOnFflHMk3GW3M9Kd
TLSH T1F7D0C9C990615DF4ACCBA9BD25F2B448605081A59CC14F25CED9F8D2A848E8DB458B51
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.240.157.77/bins.sh84f8a9c3f5b38ccb2dc214cb09cd05c3da8e8c861070866f7df58a1aed508edd Xorbotsh ua-wget Xorbot

Intelligence


File Origin
# of uploads :
3
# of downloads :
75
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.9%
Tags:
trojandownloader shell virus
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Threat name:
Script.Trojan.Boxter
Status:
Malicious
First seen:
2025-05-01 22:44:27 UTC
File Type:
Text (Shell)
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Xorbot

sh 9781861f24fb1059ded43d876e310c11948efdc43e7a64655abf76d919a7ebd0

(this sample)

Comments