MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c770508261d5fd638f02d9dbe75fba828e39c759f2502fb435558c404443a22b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XorDDoS


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: c770508261d5fd638f02d9dbe75fba828e39c759f2502fb435558c404443a22b
SHA3-384 hash: a66fb83448b58a7f2655a59310b025f9d512f46307d1c5c425ce359b1df6cc39a5ff4245858eeb774cf2b39d061b5458
SHA1 hash: 846dfacc04ba40184bf0a6c183935f285a3d63bc
MD5 hash: 30a76ae0b69af55f66a5f5391172c723
humanhash: freddie-avocado-bacon-carpet
File name:p.sh
Download: download sample
Signature XorDDoS
File size:1'243 bytes
First seen:2025-08-23 06:14:20 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:fN7PvQd03RqGd0Z5Cd0FTztypRo39LjvkRexV5O:V7hhqZZFTztyns9LjvkReVM
TLSH T14E212C9954FA246071CE893F909D9E4C4FCB3D964458120C63DFFF98D0741687AC8334
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://89.32.41.25/p.txt5fefeaf30b8cd96607ee013a771c619d2bcba75e294f57e98ba86e8b40e51090 XorDDoSelf geofenced ua-wget USA x86 Xorddos
http://89.32.41.25/r.txtn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
30
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Threat name:
Script.Trojan.Multiverze
Status:
Malicious
First seen:
2025-08-23 06:15:55 UTC
File Type:
Text (Shell)
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

XorDDoS

sh c770508261d5fd638f02d9dbe75fba828e39c759f2502fb435558c404443a22b

(this sample)

  
Delivery method
Distributed via web download

Comments