MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cd4962d5534e231110902866823f2c79757921e7947cad75dbdbcaa5fdca3e4d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: cd4962d5534e231110902866823f2c79757921e7947cad75dbdbcaa5fdca3e4d
SHA3-384 hash: d27e7cfd7e30bba631a7bbf10ecd068763c2829f89106fb030da817631cd8005a2965822fbf05a8bcdea852440a855d4
SHA1 hash: 2ec30bd2dd5c418dbb0b2734d341f357535052a3
MD5 hash: e424a7d4ce6186c27c4dbab9b3cdff7b
humanhash: burger-chicken-wyoming-comet
File name:xbot1.sh
Download: download sample
File size:2'853 bytes
First seen:2025-04-11 14:33:30 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:IjB+BllBhrBf7BFBiH7BueSBJBoB6FU5FpBGohH/BGrGrHr/BiBG:UEt3f1ziVueYnK6FU5FHGohHJGSLVIG
TLSH T1935123C662A224343CE3F5A73364EB24FAD41C556C91DE8964F5F5B8898EE0512860FF
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.9%
Tags:
trojandownloader mirai virus agent
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox
Threat name:
Linux.Downloader.MiraiA
Status:
Malicious
First seen:
2025-04-11 14:34:15 UTC
File Type:
Text (Shell)
AV detection:
15 of 24 (62.50%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh cd4962d5534e231110902866823f2c79757921e7947cad75dbdbcaa5fdca3e4d

(this sample)

  
Delivery method
Distributed via web download

Comments