MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ae6d5f558e08966e3c1ed24a693feb1e091fb41f7a5558ec1fedaaf3fb595462. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Xorbot


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: ae6d5f558e08966e3c1ed24a693feb1e091fb41f7a5558ec1fedaaf3fb595462
SHA3-384 hash: 301fd5cbd4f300798beda9af565e740d62d7005967535b9cd8c921c767b0000f5b8ee3e7da0dca2a1a9bdbf82dc7e5a4
SHA1 hash: ac3a931404368ebe4e1ca0d4df764b1edda596e5
MD5 hash: 97a04046aaa544f4f5482c9f0755cbe7
humanhash: quiet-bluebird-chicken-enemy
File name:.shell
Download: download sample
Signature Xorbot
File size:208 bytes
First seen:2025-01-08 23:46:40 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 3:QnQzanFCKl2X4HMirLfzVx4LfzVNqRvLfzVaSLM9Kd:lOnFflHMIrVxGrVArVpM9Kd
TLSH T16FD012C9D0912DB2D8C489FD25E1F410609341D5DFC63A544CC9FD905448F0DB548E43
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://94.154.35.94/bins.sh03e0d6c2fc92854abceb894aa9cff9e1fa077f6e84ea055e6c7d484aef797e41 Xorbotascii bash sh Xorbot

Intelligence


File Origin
# of uploads :
1
# of downloads :
145
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Threat name:
Script.Downloader.Heuristic
Status:
Malicious
First seen:
2025-01-08 20:40:09 UTC
File Type:
Text (Shell)
AV detection:
3 of 38 (7.89%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Xorbot

sh ae6d5f558e08966e3c1ed24a693feb1e091fb41f7a5558ec1fedaaf3fb595462

(this sample)

  
Delivery method
Distributed via web download

Comments