🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 19b8cc08c112cc738cbf3de08b8755c68fae2d5b731fbdb4c4a848ef79ae89f9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 19b8cc08c112cc738cbf3de08b8755c68fae2d5b731fbdb4c4a848ef79ae89f9
SHA3-384 hash: ec3b448b58d29e49f58140f8f9936c1adee37b8d146ed25ced1194a5e09fd890daee54d0f10fc1b12a882618c1def29a
SHA1 hash: b4e6fac0c24fec0236db039841ea1451746b12bc
MD5 hash: 35dce80eeab6047541f7d3af1d571be2
humanhash: arkansas-kilo-delta-juliet
File name:check2.sh
Download: download sample
Signature CoinMiner
File size:1'116 bytes
First seen:2026-07-08 21:58:11 UTC
Last seen:2026-07-09 19:35:30 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:lmGWlv4tMGakyJIrbMGSUG+qpMGakyJIrbMGSU2cJ:0GUv5RkyB6GORkyB62cJ
TLSH T16A21D0DEFA137B391BD109DDFA1418BCB5A38EA65814EC34F2529C2C4084359036FC2E
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
https://raw.githubusercontent.com/nulltrafficaway/labprojecttest/refs/heads/main/w2.shn/an/aCoinMiner sh ua-wget
https://github.com/nulltrafficaway/project-lab-test/releases/download/test/softwaretechn/an/aCoinMiner elf ua-wget
https://raw.githubusercontent.com/nulltrafficaway/labprojecttest/refs/heads/main/config.jsonn/an/aCoinMiner config json ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
88
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
base64 obfuscated
Verdict:
Adware
File Type:
unix shell
First seen:
2026-07-08T19:12:00Z UTC
Last seen:
2026-07-10T04:10:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=93e198a0-1900-0000-554d-bdb62b140000 pid=5163 /usr/bin/sudo guuid=f8844ea3-1900-0000-554d-bdb62c140000 pid=5164 /tmp/sample.bin guuid=93e198a0-1900-0000-554d-bdb62b140000 pid=5163->guuid=f8844ea3-1900-0000-554d-bdb62c140000 pid=5164 execve guuid=802a1aa4-1900-0000-554d-bdb62d140000 pid=5165 /usr/bin/ps guuid=f8844ea3-1900-0000-554d-bdb62c140000 pid=5164->guuid=802a1aa4-1900-0000-554d-bdb62d140000 pid=5165 execve guuid=a0bf72a8-1900-0000-554d-bdb62e140000 pid=5166 /usr/bin/bash guuid=f8844ea3-1900-0000-554d-bdb62c140000 pid=5164->guuid=a0bf72a8-1900-0000-554d-bdb62e140000 pid=5166 clone guuid=3d62efa8-1900-0000-554d-bdb631140000 pid=5169 /usr/bin/rm guuid=f8844ea3-1900-0000-554d-bdb62c140000 pid=5164->guuid=3d62efa8-1900-0000-554d-bdb631140000 pid=5169 execve guuid=510146a9-1900-0000-554d-bdb632140000 pid=5170 /usr/bin/curl guuid=f8844ea3-1900-0000-554d-bdb62c140000 pid=5164->guuid=510146a9-1900-0000-554d-bdb632140000 pid=5170 execve guuid=320bca57-1e00-0000-554d-bdb65b140000 pid=5211 /usr/bin/curl guuid=f8844ea3-1900-0000-554d-bdb62c140000 pid=5164->guuid=320bca57-1e00-0000-554d-bdb65b140000 pid=5211 execve guuid=bddde904-2300-0000-554d-bdb65d140000 pid=5213 /usr/bin/curl guuid=f8844ea3-1900-0000-554d-bdb62c140000 pid=5164->guuid=bddde904-2300-0000-554d-bdb65d140000 pid=5213 execve guuid=ed7e83a8-1900-0000-554d-bdb62f140000 pid=5167 /usr/bin/bash guuid=a0bf72a8-1900-0000-554d-bdb62e140000 pid=5166->guuid=ed7e83a8-1900-0000-554d-bdb62f140000 pid=5167 clone guuid=19fb8aa8-1900-0000-554d-bdb630140000 pid=5168 /usr/bin/mawk guuid=a0bf72a8-1900-0000-554d-bdb62e140000 pid=5166->guuid=19fb8aa8-1900-0000-554d-bdb630140000 pid=5168 execve guuid=510146a9-1900-0000-554d-bdb632140000 pid=5171 /usr/bin/curl net send-data guuid=510146a9-1900-0000-554d-bdb632140000 pid=5170->guuid=510146a9-1900-0000-554d-bdb632140000 pid=5171 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=510146a9-1900-0000-554d-bdb632140000 pid=5171->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 344B guuid=320bca57-1e00-0000-554d-bdb65b140000 pid=5212 /usr/bin/curl net send-data guuid=320bca57-1e00-0000-554d-bdb65b140000 pid=5211->guuid=320bca57-1e00-0000-554d-bdb65b140000 pid=5212 clone guuid=320bca57-1e00-0000-554d-bdb65b140000 pid=5212->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 224B guuid=bddde904-2300-0000-554d-bdb65d140000 pid=5214 /usr/bin/curl net send-data guuid=bddde904-2300-0000-554d-bdb65d140000 pid=5213->guuid=bddde904-2300-0000-554d-bdb65d140000 pid=5214 clone guuid=bddde904-2300-0000-554d-bdb65d140000 pid=5214->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 344B
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-08 21:59:39 UTC
File Type:
Text (Shell)
AV detection:
5 of 24 (20.83%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:xmrig antivm defense_evasion discovery linux miner persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Changes its process name
Checks CPU configuration
Reads CPU attributes
Modifies Bash startup script
Checks hardware identifiers (DMI)
Contacts third-party web service commonly abused for C2
Creates/modifies environment variables
Enumerates running processes
Reads hardware information
File and Directory Permissions Modification
Executes dropped EXE
Family: xmrig
XMRig Miner payload
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CoinMiner

sh 19b8cc08c112cc738cbf3de08b8755c68fae2d5b731fbdb4c4a848ef79ae89f9

(this sample)

  
Delivery method
Distributed via web download

Comments