MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0d63cca52a1f18a4d1461e49739aabb46e28ef8d2e50f4e80404088e2ba6343a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 0d63cca52a1f18a4d1461e49739aabb46e28ef8d2e50f4e80404088e2ba6343a
SHA3-384 hash: f0abe4150142ca3c7cd747229c0ab8108d3c52f0f5cfd62e5fa03fd2c70e22288ef3ed1c5d4f75f23912ab6c0be44ecd
SHA1 hash: afb586f2d8dc8798624a3d7997f5333db35167df
MD5 hash: 2a1d315282822ceb549d9b076f6096e1
humanhash: missouri-early-fish-angel
File name:apt0.sh
Download: download sample
Signature CoinMiner
File size:2'435 bytes
First seen:2026-04-03 23:50:47 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:inOx1T70gMP1P4Uo4UlDlCJH/M18lBJQTYXLpIbZt:SS17q1QUHUIH/e8l4TYX90Zt
TLSH T1DE4174E668B4A2F8BF4FA524496E31A9F00257524F876C9CF0A65C0EE5B4895232FC53
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
35
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Verdict:
Adware
File Type:
unix shell
First seen:
2026-04-02T08:24:00Z UTC
Last seen:
2026-04-05T17:44:00Z UTC
Hits:
~10
Detections:
not-a-virus:HEUR:Downloader.Shell.Miner.a
Status:
terminated
Behavior Graph:
%3 guuid=9edd24c3-1600-0000-8f85-5707480e0000 pid=3656 /usr/bin/sudo guuid=c4d767c5-1600-0000-8f85-5707490e0000 pid=3657 /tmp/sample.bin guuid=9edd24c3-1600-0000-8f85-5707480e0000 pid=3656->guuid=c4d767c5-1600-0000-8f85-5707490e0000 pid=3657 execve guuid=6642d8c5-1600-0000-8f85-57074a0e0000 pid=3658 /usr/bin/sudo net guuid=c4d767c5-1600-0000-8f85-5707490e0000 pid=3657->guuid=6642d8c5-1600-0000-8f85-57074a0e0000 pid=3658 execve guuid=7789b0fa-1600-0000-8f85-57070e0f0000 pid=3854 /usr/bin/pgrep guuid=c4d767c5-1600-0000-8f85-5707490e0000 pid=3657->guuid=7789b0fa-1600-0000-8f85-57070e0f0000 pid=3854 execve guuid=06029efd-1600-0000-8f85-57071c0f0000 pid=3868 /usr/bin/pgrep guuid=c4d767c5-1600-0000-8f85-5707490e0000 pid=3657->guuid=06029efd-1600-0000-8f85-57071c0f0000 pid=3868 execve guuid=980fac01-1700-0000-8f85-57072b0f0000 pid=3883 /usr/bin/pgrep guuid=c4d767c5-1600-0000-8f85-5707490e0000 pid=3657->guuid=980fac01-1700-0000-8f85-57072b0f0000 pid=3883 execve guuid=d9d56005-1700-0000-8f85-57073d0f0000 pid=3901 /usr/bin/pgrep guuid=c4d767c5-1600-0000-8f85-5707490e0000 pid=3657->guuid=d9d56005-1700-0000-8f85-57073d0f0000 pid=3901 execve guuid=77db2409-1700-0000-8f85-5707480f0000 pid=3912 /usr/bin/pgrep guuid=c4d767c5-1600-0000-8f85-5707490e0000 pid=3657->guuid=77db2409-1700-0000-8f85-5707480f0000 pid=3912 execve guuid=00bda70c-1700-0000-8f85-5707550f0000 pid=3925 /usr/bin/pgrep guuid=c4d767c5-1600-0000-8f85-5707490e0000 pid=3657->guuid=00bda70c-1700-0000-8f85-5707550f0000 pid=3925 execve guuid=b2e20310-1700-0000-8f85-5707600f0000 pid=3936 /usr/bin/uname guuid=c4d767c5-1600-0000-8f85-5707490e0000 pid=3657->guuid=b2e20310-1700-0000-8f85-5707600f0000 pid=3936 execve guuid=6d4fd310-1700-0000-8f85-5707640f0000 pid=3940 /usr/bin/sudo net guuid=c4d767c5-1600-0000-8f85-5707490e0000 pid=3657->guuid=6d4fd310-1700-0000-8f85-5707640f0000 pid=3940 execve guuid=f0571713-1700-0000-8f85-5707720f0000 pid=3954 /usr/bin/wget dns net send-data write-file guuid=c4d767c5-1600-0000-8f85-5707490e0000 pid=3657->guuid=f0571713-1700-0000-8f85-5707720f0000 pid=3954 execve guuid=1b5c1f13-1700-0000-8f85-5707730f0000 pid=3955 /usr/bin/sudo net guuid=c4d767c5-1600-0000-8f85-5707490e0000 pid=3657->guuid=1b5c1f13-1700-0000-8f85-5707730f0000 pid=3955 execve guuid=79fb0835-1700-0000-8f85-570707100000 pid=4103 /usr/bin/sudo net guuid=c4d767c5-1600-0000-8f85-5707490e0000 pid=3657->guuid=79fb0835-1700-0000-8f85-570707100000 pid=4103 execve guuid=8ffdab36-1700-0000-8f85-57070e100000 pid=4110 /usr/bin/cat guuid=c4d767c5-1600-0000-8f85-5707490e0000 pid=3657->guuid=8ffdab36-1700-0000-8f85-57070e100000 pid=4110 execve guuid=6ab4b236-1700-0000-8f85-57070f100000 pid=4111 /usr/bin/sudo net guuid=c4d767c5-1600-0000-8f85-5707490e0000 pid=3657->guuid=6ab4b236-1700-0000-8f85-57070f100000 pid=4111 execve guuid=8cca3538-1700-0000-8f85-57071a100000 pid=4122 /usr/bin/sudo net guuid=c4d767c5-1600-0000-8f85-5707490e0000 pid=3657->guuid=8cca3538-1700-0000-8f85-57071a100000 pid=4122 execve guuid=c0a6f339-1700-0000-8f85-570722100000 pid=4130 /usr/bin/bash guuid=c4d767c5-1600-0000-8f85-5707490e0000 pid=3657->guuid=c0a6f339-1700-0000-8f85-570722100000 pid=4130 clone guuid=ebb6f939-1700-0000-8f85-570723100000 pid=4131 /usr/bin/sudo net guuid=c4d767c5-1600-0000-8f85-5707490e0000 pid=3657->guuid=ebb6f939-1700-0000-8f85-570723100000 pid=4131 execve guuid=33b37d3b-1700-0000-8f85-57072e100000 pid=4142 /usr/bin/sudo net guuid=c4d767c5-1600-0000-8f85-5707490e0000 pid=3657->guuid=33b37d3b-1700-0000-8f85-57072e100000 pid=4142 execve guuid=0f745662-1700-0000-8f85-5707df100000 pid=4319 /usr/bin/sudo net guuid=c4d767c5-1600-0000-8f85-5707490e0000 pid=3657->guuid=0f745662-1700-0000-8f85-5707df100000 pid=4319 execve guuid=f25f0689-1700-0000-8f85-570791110000 pid=4497 /usr/bin/sudo net guuid=c4d767c5-1600-0000-8f85-5707490e0000 pid=3657->guuid=f25f0689-1700-0000-8f85-570791110000 pid=4497 execve 0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 10.0.2.15:0 guuid=6642d8c5-1600-0000-8f85-57074a0e0000 pid=3658->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con 558177e1-1f18-5f39-990b-d68b1c194e8a fec0::5054:ff:fe12:3456:0 guuid=6642d8c5-1600-0000-8f85-57074a0e0000 pid=3658->558177e1-1f18-5f39-990b-d68b1c194e8a con cbc59886-1795-52e1-b014-449ae22fd09b fe80::5054:ff:fe12:3456:0 guuid=6642d8c5-1600-0000-8f85-57074a0e0000 pid=3658->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=35c866c8-1600-0000-8f85-5707510e0000 pid=3665 /usr/bin/systemctl guuid=6642d8c5-1600-0000-8f85-57074a0e0000 pid=3658->guuid=35c866c8-1600-0000-8f85-5707510e0000 pid=3665 execve guuid=6d4fd310-1700-0000-8f85-5707640f0000 pid=3940->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=6d4fd310-1700-0000-8f85-5707640f0000 pid=3940->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=6d4fd310-1700-0000-8f85-5707640f0000 pid=3940->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=5b61b112-1700-0000-8f85-57076e0f0000 pid=3950 /usr/bin/mkdir guuid=6d4fd310-1700-0000-8f85-5707640f0000 pid=3940->guuid=5b61b112-1700-0000-8f85-57076e0f0000 pid=3950 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=f0571713-1700-0000-8f85-5707720f0000 pid=3954->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 164B 75aab096-419b-50ef-be46-7d76b6a90e4c github.com:443 guuid=f0571713-1700-0000-8f85-5707720f0000 pid=3954->75aab096-419b-50ef-be46-7d76b6a90e4c send: 802B f8c5e44f-328d-5324-8bbd-da50752b9120 release-assets.githubusercontent.com:0 guuid=f0571713-1700-0000-8f85-5707720f0000 pid=3954->f8c5e44f-328d-5324-8bbd-da50752b9120 con f0eebea5-e97d-507c-a771-59cac353877c release-assets.githubusercontent.com:443 guuid=f0571713-1700-0000-8f85-5707720f0000 pid=3954->f0eebea5-e97d-507c-a771-59cac353877c send: 1660B guuid=1b5c1f13-1700-0000-8f85-5707730f0000 pid=3955->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=1b5c1f13-1700-0000-8f85-5707730f0000 pid=3955->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=1b5c1f13-1700-0000-8f85-5707730f0000 pid=3955->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=f8d04c14-1700-0000-8f85-57077a0f0000 pid=3962 /usr/bin/tar write-file guuid=1b5c1f13-1700-0000-8f85-5707730f0000 pid=3955->guuid=f8d04c14-1700-0000-8f85-57077a0f0000 pid=3962 execve guuid=cf3a9814-1700-0000-8f85-57077d0f0000 pid=3965 /usr/bin/tar guuid=f8d04c14-1700-0000-8f85-57077a0f0000 pid=3962->guuid=cf3a9814-1700-0000-8f85-57077d0f0000 pid=3965 clone guuid=2309a714-1700-0000-8f85-57077e0f0000 pid=3966 /usr/bin/gzip guuid=cf3a9814-1700-0000-8f85-57077d0f0000 pid=3965->guuid=2309a714-1700-0000-8f85-57077e0f0000 pid=3966 execve guuid=79fb0835-1700-0000-8f85-570707100000 pid=4103->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=79fb0835-1700-0000-8f85-570707100000 pid=4103->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=79fb0835-1700-0000-8f85-570707100000 pid=4103->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=cb173436-1700-0000-8f85-57070b100000 pid=4107 /usr/bin/mv guuid=79fb0835-1700-0000-8f85-570707100000 pid=4103->guuid=cb173436-1700-0000-8f85-57070b100000 pid=4107 execve guuid=6ab4b236-1700-0000-8f85-57070f100000 pid=4111->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=6ab4b236-1700-0000-8f85-57070f100000 pid=4111->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=6ab4b236-1700-0000-8f85-57070f100000 pid=4111->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=3639d837-1700-0000-8f85-570716100000 pid=4118 /usr/bin/tee write-config guuid=6ab4b236-1700-0000-8f85-57070f100000 pid=4111->guuid=3639d837-1700-0000-8f85-570716100000 pid=4118 execve guuid=8cca3538-1700-0000-8f85-57071a100000 pid=4122->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=8cca3538-1700-0000-8f85-57071a100000 pid=4122->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=8cca3538-1700-0000-8f85-57071a100000 pid=4122->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=a8786f39-1700-0000-8f85-57071f100000 pid=4127 /usr/bin/grep guuid=8cca3538-1700-0000-8f85-57071a100000 pid=4122->guuid=a8786f39-1700-0000-8f85-57071f100000 pid=4127 execve guuid=ebb6f939-1700-0000-8f85-570723100000 pid=4131->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=ebb6f939-1700-0000-8f85-570723100000 pid=4131->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=ebb6f939-1700-0000-8f85-570723100000 pid=4131->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=f361203b-1700-0000-8f85-57072c100000 pid=4140 /usr/bin/tee write-file guuid=ebb6f939-1700-0000-8f85-570723100000 pid=4131->guuid=f361203b-1700-0000-8f85-57072c100000 pid=4140 execve guuid=33b37d3b-1700-0000-8f85-57072e100000 pid=4142->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=33b37d3b-1700-0000-8f85-57072e100000 pid=4142->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=33b37d3b-1700-0000-8f85-57072e100000 pid=4142->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=4d5faa3c-1700-0000-8f85-570734100000 pid=4148 /usr/bin/systemctl guuid=33b37d3b-1700-0000-8f85-57072e100000 pid=4142->guuid=4d5faa3c-1700-0000-8f85-570734100000 pid=4148 execve guuid=0f745662-1700-0000-8f85-5707df100000 pid=4319->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=0f745662-1700-0000-8f85-5707df100000 pid=4319->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=0f745662-1700-0000-8f85-5707df100000 pid=4319->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=e7938a63-1700-0000-8f85-5707e8100000 pid=4328 /usr/bin/systemctl guuid=0f745662-1700-0000-8f85-5707df100000 pid=4319->guuid=e7938a63-1700-0000-8f85-5707e8100000 pid=4328 execve guuid=f25f0689-1700-0000-8f85-570791110000 pid=4497->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=f25f0689-1700-0000-8f85-570791110000 pid=4497->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=f25f0689-1700-0000-8f85-570791110000 pid=4497->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=b218808a-1700-0000-8f85-570797110000 pid=4503 /usr/bin/systemctl guuid=f25f0689-1700-0000-8f85-570791110000 pid=4497->guuid=b218808a-1700-0000-8f85-570797110000 pid=4503 execve
Result
Malware family:
xmrig_linux
Score:
  10/10
Tags:
family:xmrig family:xmrig_linux defense_evasion discovery linux miner persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Reads CPU attributes
Modifies Bash startup script
Abuse Elevation Control Mechanism: Sudo and Sudo Caching
Creates/modifies environment variables
Enumerates running processes
Modifies systemd
XMRig Miner payload
Xmrig family
Xmrig_linux family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CoinMiner

sh 0d63cca52a1f18a4d1461e49739aabb46e28ef8d2e50f4e80404088e2ba6343a

(this sample)

  
Delivery method
Distributed via web download

Comments