MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f8131fc6a21d55e9979b7d2c621857e48b63b1062483de9d8507ee169053910e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Xorbot


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: f8131fc6a21d55e9979b7d2c621857e48b63b1062483de9d8507ee169053910e
SHA3-384 hash: 91571901d4454622d1f2901c2bcdc6d8fa597416fb47b5d36727861709fba34ce2e61a4704768197a981f6084a5b767d
SHA1 hash: 4d76b279ee9447c4441d4a4d7ab1c6dba6aec8df
MD5 hash: 51fa0a88bc67422f4a4b14871d1664cb
humanhash: delaware-mountain-robin-chicken
File name:.shell
Download: download sample
Signature Xorbot
File size:208 bytes
First seen:2025-02-07 04:45:55 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 3:QnQzanFCKl2X4HMiqnKWl9nKWxqRenKWGSLM9Kd:lOnFflHMfnNl9nNLnNlM9Kd
TLSH T169D0C9C9A05354F29AC0CEFD35E1B410605261959DD04B144CDCF8D8448CE0D205CE4A
Magika shell
Reporter abuse_ch
Tags:sh Xorbot
URLMalware sample (SHA256 hash)SignatureTags
http://37.44.238.88/bins.sh512c85432f47149b04a2620dea12b2520857884e398b886d768468a16ced73d5 Xorbotsh Xorbot

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
96.5%
Tags:
trojan agent shell
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Result
Verdict:
UNKNOWN
Threat name:
Script.Trojan.Boxter
Status:
Malicious
First seen:
2025-02-07 05:51:13 UTC
File Type:
Text (Shell)
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Xorbot

sh f8131fc6a21d55e9979b7d2c621857e48b63b1062483de9d8507ee169053910e

(this sample)

  
Delivery method
Distributed via web download

Comments