MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 11ca3819a2bb745a6c990bc8f31990aa38a7f760d5cf0bee967381a9f7371b14. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 5


Intelligence 5 IOCs YARA 2 File information Comments

SHA256 hash: 11ca3819a2bb745a6c990bc8f31990aa38a7f760d5cf0bee967381a9f7371b14
SHA3-384 hash: 1553a6efa4e39e60fac7e93be2e8cfe7615d2688251bc125e9262ce43497d4a03c6955f151235325c103c68395a8cd07
SHA1 hash: a2f4fa1faf7609fed792948dfce3250e50062dc0
MD5 hash: 5470a5c569ae5109f22c3d04a4b7865e
humanhash: sodium-undress-winter-alanine
File name:run.sh.bkp
Download: download sample
Signature CoinMiner
File size:5'387 bytes
First seen:2025-07-16 02:41:58 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:2I8QX7EeanozGeEXOKDCcF9Q16AdJ+bgOI70Wlvo6lFMrYCJi7JiIul8jl/G:2I848nozGeEXOKD5S1d+bgOm0WlvjOYY
TLSH T1D6B1A811F78045F015C9C1A4088D2584A947901B3F056D68FCAEB1B6FF19E18B2FEBF6
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.248.53.119:8000/mon.sh1e891ab1521b27923233e694f60fdbf0e1b840e657d8b1ffdefd8b5ef5e38964 CoinMinerCoinMiner
https://github.com/xmrig/xmrig/releases/download/v6.22.2/xmrig-6.22.2-linux-static-x64.tar.gzn/an/an/a
https://github.com/doktor83/SRBMiner-Multi/releases/download/0.9.7/SRBMiner-Multi-0-9-7-Linux.tar.xzn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
33
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=c976504b-1900-0000-cf0b-72af3b0a0000 pid=2619 /usr/bin/sudo guuid=7275e04c-1900-0000-cf0b-72af420a0000 pid=2626 /tmp/sample.bin guuid=c976504b-1900-0000-cf0b-72af3b0a0000 pid=2619->guuid=7275e04c-1900-0000-cf0b-72af420a0000 pid=2626 execve guuid=e8348e4d-1900-0000-cf0b-72af440a0000 pid=2628 /usr/bin/systemctl guuid=7275e04c-1900-0000-cf0b-72af420a0000 pid=2626->guuid=e8348e4d-1900-0000-cf0b-72af440a0000 pid=2628 execve guuid=472cd54f-1900-0000-cf0b-72af4c0a0000 pid=2636 /usr/bin/bash guuid=7275e04c-1900-0000-cf0b-72af420a0000 pid=2626->guuid=472cd54f-1900-0000-cf0b-72af4c0a0000 pid=2636 clone guuid=61ed1557-1900-0000-cf0b-72af630a0000 pid=2659 /usr/bin/bash guuid=7275e04c-1900-0000-cf0b-72af420a0000 pid=2626->guuid=61ed1557-1900-0000-cf0b-72af630a0000 pid=2659 clone guuid=7935cd57-1900-0000-cf0b-72af6a0a0000 pid=2666 /usr/bin/id guuid=7275e04c-1900-0000-cf0b-72af420a0000 pid=2626->guuid=7935cd57-1900-0000-cf0b-72af6a0a0000 pid=2666 execve guuid=bf29bf58-1900-0000-cf0b-72af6d0a0000 pid=2669 /usr/bin/mkdir guuid=7275e04c-1900-0000-cf0b-72af420a0000 pid=2626->guuid=bf29bf58-1900-0000-cf0b-72af6d0a0000 pid=2669 execve guuid=d89b4059-1900-0000-cf0b-72af700a0000 pid=2672 /usr/bin/wget dns net send-data write-file guuid=7275e04c-1900-0000-cf0b-72af420a0000 pid=2626->guuid=d89b4059-1900-0000-cf0b-72af700a0000 pid=2672 execve guuid=ccfc939c-1900-0000-cf0b-72aff10a0000 pid=2801 /usr/bin/tar write-file guuid=7275e04c-1900-0000-cf0b-72af420a0000 pid=2626->guuid=ccfc939c-1900-0000-cf0b-72aff10a0000 pid=2801 execve guuid=9a395db6-1900-0000-cf0b-72af1c0b0000 pid=2844 /usr/bin/mv guuid=7275e04c-1900-0000-cf0b-72af420a0000 pid=2626->guuid=9a395db6-1900-0000-cf0b-72af1c0b0000 pid=2844 execve guuid=448cd7b6-1900-0000-cf0b-72af1f0b0000 pid=2847 /usr/bin/rm delete-file guuid=7275e04c-1900-0000-cf0b-72af420a0000 pid=2626->guuid=448cd7b6-1900-0000-cf0b-72af1f0b0000 pid=2847 execve guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849 /usr/lib/dev/systemdev/systemd-mont mprotect-exec guuid=7275e04c-1900-0000-cf0b-72af420a0000 pid=2626->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849 execve guuid=6e0388b7-1900-0000-cf0b-72af220b0000 pid=2850 /usr/bin/sleep guuid=7275e04c-1900-0000-cf0b-72af420a0000 pid=2626->guuid=6e0388b7-1900-0000-cf0b-72af220b0000 pid=2850 execve guuid=59fe6ae3-1a00-0000-cf0b-72afd20c0000 pid=3282 /usr/bin/ps guuid=7275e04c-1900-0000-cf0b-72af420a0000 pid=2626->guuid=59fe6ae3-1a00-0000-cf0b-72afd20c0000 pid=3282 execve guuid=6d4eb3ed-1a00-0000-cf0b-72afdf0c0000 pid=3295 /usr/bin/rm guuid=7275e04c-1900-0000-cf0b-72af420a0000 pid=2626->guuid=6d4eb3ed-1a00-0000-cf0b-72afdf0c0000 pid=3295 execve guuid=dced17ee-1a00-0000-cf0b-72afe00c0000 pid=3296 /usr/bin/rm guuid=7275e04c-1900-0000-cf0b-72af420a0000 pid=2626->guuid=dced17ee-1a00-0000-cf0b-72afe00c0000 pid=3296 execve guuid=418eea4f-1900-0000-cf0b-72af4d0a0000 pid=2637 /usr/bin/wget dns net send-data guuid=472cd54f-1900-0000-cf0b-72af4c0a0000 pid=2636->guuid=418eea4f-1900-0000-cf0b-72af4d0a0000 pid=2637 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=418eea4f-1900-0000-cf0b-72af4d0a0000 pid=2637->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B 0690ccd5-4816-5f11-94dc-7c585f38cdea ipv4.icanhazip.com:0 guuid=418eea4f-1900-0000-cf0b-72af4d0a0000 pid=2637->0690ccd5-4816-5f11-94dc-7c585f38cdea con d0ecfe49-aa79-583f-85c6-85ac97075256 ipv4.icanhazip.com:80 guuid=418eea4f-1900-0000-cf0b-72af4d0a0000 pid=2637->d0ecfe49-aa79-583f-85c6-85ac97075256 send: 133B guuid=07a22057-1900-0000-cf0b-72af640a0000 pid=2660 /usr/bin/bash guuid=61ed1557-1900-0000-cf0b-72af630a0000 pid=2659->guuid=07a22057-1900-0000-cf0b-72af640a0000 pid=2660 clone guuid=b9232d57-1900-0000-cf0b-72af650a0000 pid=2661 /usr/bin/sed guuid=61ed1557-1900-0000-cf0b-72af630a0000 pid=2659->guuid=b9232d57-1900-0000-cf0b-72af650a0000 pid=2661 execve guuid=6c703557-1900-0000-cf0b-72af670a0000 pid=2663 /usr/bin/cut guuid=61ed1557-1900-0000-cf0b-72af630a0000 pid=2659->guuid=6c703557-1900-0000-cf0b-72af670a0000 pid=2663 execve guuid=d89b4059-1900-0000-cf0b-72af700a0000 pid=2672->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 164B 75aab096-419b-50ef-be46-7d76b6a90e4c github.com:443 guuid=d89b4059-1900-0000-cf0b-72af700a0000 pid=2672->75aab096-419b-50ef-be46-7d76b6a90e4c send: 809B f8c5e44f-328d-5324-8bbd-da50752b9120 release-assets.githubusercontent.com:0 guuid=d89b4059-1900-0000-cf0b-72af700a0000 pid=2672->f8c5e44f-328d-5324-8bbd-da50752b9120 con f0eebea5-e97d-507c-a771-59cac353877c release-assets.githubusercontent.com:443 guuid=d89b4059-1900-0000-cf0b-72af700a0000 pid=2672->f0eebea5-e97d-507c-a771-59cac353877c send: 1657B guuid=2487259d-1900-0000-cf0b-72aff30a0000 pid=2803 /usr/bin/xz guuid=ccfc939c-1900-0000-cf0b-72aff10a0000 pid=2801->guuid=2487259d-1900-0000-cf0b-72aff30a0000 pid=2803 execve guuid=76f94371-1a00-0000-cf0b-72af5c0c0000 pid=3164 /usr/bin/dash guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=76f94371-1a00-0000-cf0b-72af5c0c0000 pid=3164 execve guuid=cfb84575-1a00-0000-cf0b-72af650c0000 pid=3173 /usr/bin/dash guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=cfb84575-1a00-0000-cf0b-72af650c0000 pid=3173 execve guuid=85a45f76-1a00-0000-cf0b-72af680c0000 pid=3176 /usr/bin/dash guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=85a45f76-1a00-0000-cf0b-72af680c0000 pid=3176 execve guuid=de62ad76-1a00-0000-cf0b-72af690c0000 pid=3177 /usr/bin/dash guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=de62ad76-1a00-0000-cf0b-72af690c0000 pid=3177 execve guuid=a955e676-1a00-0000-cf0b-72af6b0c0000 pid=3179 /usr/bin/dash guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=a955e676-1a00-0000-cf0b-72af6b0c0000 pid=3179 execve guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3197 /usr/lib/dev/systemdev/systemd-mont mprotect-exec net zombie guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3197 clone guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3221 /usr/lib/dev/systemdev/systemd-mont guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3221 clone guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3226 /usr/lib/dev/systemdev/systemd-mont guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3226 clone guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3232 /usr/lib/dev/systemdev/systemd-mont guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3232 clone guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3235 /usr/lib/dev/systemdev/systemd-mont guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3235 clone guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3240 /usr/lib/dev/systemdev/systemd-mont guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3240 clone guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3241 /usr/lib/dev/systemdev/systemd-mont guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3241 clone guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3248 /usr/lib/dev/systemdev/systemd-mont guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3248 clone guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3249 /usr/lib/dev/systemdev/systemd-mont guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3249 clone guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3250 /usr/lib/dev/systemdev/systemd-mont guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3250 clone guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3251 /usr/lib/dev/systemdev/systemd-mont mprotect-exec zombie guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3251 clone guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3252 /usr/lib/dev/systemdev/systemd-mont guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3252 clone guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3253 /usr/lib/dev/systemdev/systemd-mont guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3253 clone guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3299 /usr/lib/dev/systemdev/systemd-mont dns mprotect-exec net send-data zombie guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3299 clone guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3313 /usr/lib/dev/systemdev/systemd-mont zombie guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3313 clone guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3314 /usr/lib/dev/systemdev/systemd-mont mprotect-exec send-data zombie guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3314 clone guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3340 /usr/lib/dev/systemdev/systemd-mont guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3340 clone guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3341 /usr/lib/dev/systemdev/systemd-mont zombie guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3341 clone guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3482 /usr/lib/dev/systemdev/systemd-mont zombie guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3482 clone guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=4706 /usr/lib/dev/systemdev/systemd-mont zombie guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=4706 clone guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=5283 /usr/lib/dev/systemdev/systemd-mont zombie guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=5283 clone guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=5316 /usr/lib/dev/systemdev/systemd-mont mprotect-exec zombie guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=5316 clone guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=5317 /usr/lib/dev/systemdev/systemd-mont mprotect-exec zombie guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=5317 clone guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=5318 /usr/lib/dev/systemdev/systemd-mont guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=5318 clone guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=5319 /usr/lib/dev/systemdev/systemd-mont guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=5319 clone guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=5320 /usr/lib/dev/systemdev/systemd-mont guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=5320 clone guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=5321 /usr/lib/dev/systemdev/systemd-mont guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=5321 clone guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=5322 /usr/lib/dev/systemdev/systemd-mont guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=2849->guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=5322 clone guuid=e0abe675-1a00-0000-cf0b-72af660c0000 pid=3174 /usr/bin/cat guuid=cfb84575-1a00-0000-cf0b-72af650c0000 pid=3173->guuid=e0abe675-1a00-0000-cf0b-72af660c0000 pid=3174 execve guuid=4d5e1e77-1a00-0000-cf0b-72af6d0c0000 pid=3181 /usr/bin/kmod load-kernel-module guuid=a955e676-1a00-0000-cf0b-72af6b0c0000 pid=3179->guuid=4d5e1e77-1a00-0000-cf0b-72af6d0c0000 pid=3181 execve 281961e4-12ba-576f-817b-8818e6a342d9 46.165.235.8:3333 guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3197->281961e4-12ba-576f-817b-8818e6a342d9 con guuid=1884cd7e-1a00-0000-cf0b-72af7e0c0000 pid=3198 /usr/bin/dash guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3197->guuid=1884cd7e-1a00-0000-cf0b-72af7e0c0000 pid=3198 execve guuid=8d0b0b7f-1a00-0000-cf0b-72af7f0c0000 pid=3199 /usr/bin/wget dns net send-data guuid=1884cd7e-1a00-0000-cf0b-72af7e0c0000 pid=3198->guuid=8d0b0b7f-1a00-0000-cf0b-72af7f0c0000 pid=3199 execve guuid=8d0b0b7f-1a00-0000-cf0b-72af7f0c0000 pid=3199->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 60B 167b6a71-9ae8-5611-bb81-5084d396aefa srbminer.com:0 guuid=8d0b0b7f-1a00-0000-cf0b-72af7f0c0000 pid=3199->167b6a71-9ae8-5611-bb81-5084d396aefa con 3b6282a8-9c6f-516c-adee-ceddf97de757 srbminer.com:443 guuid=8d0b0b7f-1a00-0000-cf0b-72af7f0c0000 pid=3199->3b6282a8-9c6f-516c-adee-ceddf97de757 send: 769B guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3299->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 32B 66a20c23-74ee-517c-be52-75ba287a1ea0 :::3334 guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3299->66a20c23-74ee-517c-be52-75ba287a1ea0 con 2ec38fea-9246-5a41-8d0f-42b26fb91f4c 0.0.0.0:3334 guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3299->2ec38fea-9246-5a41-8d0f-42b26fb91f4c con 9809b4ed-84a9-5bba-a2c2-d5aa9d198612 de.epicmine.io:3334 guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3299->9809b4ed-84a9-5bba-a2c2-d5aa9d198612 send: 410B guuid=fda67cb7-1900-0000-cf0b-72af210b0000 pid=3314->9809b4ed-84a9-5bba-a2c2-d5aa9d198612 send: 278B
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2025-07-16 02:42:25 UTC
File Type:
Text (Shell)
AV detection:
5 of 24 (20.83%)
Threat level:
  5/5
Result
Malware family:
xmrig_linux
Score:
  10/10
Tags:
family:xmrig family:xmrig_linux antivm defense_evasion discovery linux miner rootkit upx
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
Reads CPU attributes
UPX packed file
Checks hardware identifiers (DMI)
Enumerates running processes
Reads hardware information
File and Directory Permissions Modification
Executes dropped EXE
Loads a kernel module
XMRig Miner payload
Xmrig family
Xmrig_linux family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_SH_CryptoMiner_Indicators_Dec20_1
Author:Florian Roth (Nextron Systems)
Description:Detects helper script used in a crypto miner campaign
Reference:https://www.intezer.com/blog/research/new-golang-worm-drops-xmrig-miner-on-servers/
Rule name:SUSP_LNX_SH_CryptoMiner_Indicators_Dec20_1_RID364E
Author:Florian Roth
Description:Detects helper script used in a crypto miner campaign
Reference:https://www.intezer.com/blog/research/new-golang-worm-drops-xmrig-miner-on-servers/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Distributed via web download

Comments