MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bc74c261d81c630a79c9a793958f1d10a989e05d9e02d0748e994d41bcf26ebf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Xorbot


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: bc74c261d81c630a79c9a793958f1d10a989e05d9e02d0748e994d41bcf26ebf
SHA3-384 hash: fc72a334265aa9adc9b7d4c3a18e5720b5e4b627584172393aee927c93afb3699d0d1ecba09eacb007e27fd4d3dea398
SHA1 hash: 369092a6613ce25732f44d1de0adb91abe3fb574
MD5 hash: fdc76c40cabd02a720fbfe29ef9d4a2b
humanhash: single-moon-orange-mars
File name:.shell
Download: download sample
Signature Xorbot
File size:208 bytes
First seen:2025-03-01 03:37:25 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 3:QnQzanFCKl2X4HMiqhKH39hKHPqRehKHsSLM9Kd:lOnFflHMfhI9hKh2M9Kd
TLSH T173D0C9CA905354F29AC2CEBD35E1B410625361959CD06B648CCDBCD0408DE0D214CA8A
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://37.44.238.92/bins.sh4e0b27339e784ecfec59332890bec0c7cd664b60416f61c9fef79d936e12d173 Xorbotsh Xorbot

Intelligence


File Origin
# of uploads :
1
# of downloads :
114
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
95.7%
Tags:
trojan mirai agent shell
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Result
Verdict:
UNKNOWN
Threat name:
Script.Trojan.Boxter
Status:
Malicious
First seen:
2025-03-01 07:23:45 UTC
File Type:
Text (Shell)
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Xorbot

sh bc74c261d81c630a79c9a793958f1d10a989e05d9e02d0748e994d41bcf26ebf

(this sample)

Comments