MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 382dc078f427e7a2e34bfd03c4d8634f4f2b93cba6e840bfca50dab7f7f7727a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 10


Intelligence 10 IOCs YARA 16 File information Comments

SHA256 hash: 382dc078f427e7a2e34bfd03c4d8634f4f2b93cba6e840bfca50dab7f7f7727a
SHA3-384 hash: d1744a367ab8467477819cadd769ac2deabe0aa31fc12d7459e53a4efd63de2305f1ed8a1b3da2d57e3c8a9e1b36a673
SHA1 hash: 422d116fb5492ee5fee7ac6b0584f77e667d0367
MD5 hash: d5c481507973874611e0df5fad002ee3
humanhash: eight-iowa-mississippi-zulu
File name:d5a0377ee9f1732a6f10372750fd638e081edf44a9703eda5d5ef53a2ab82f43
Download: download sample
Signature CoinMiner
File size:5'060'624 bytes
First seen:2026-07-27 15:59:41 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 98304:jmuGqB07PI77UcVHpB4Lldybz6++iRDMT+wBS7Hqv2wwKFKoArC4pa/i+Dg+2:zB7B4WRtwBo6GCutv
TLSH T11D365D4BF1A360FCC1ABC434475B9963B931786901247DBB66D4EA302B33F605B69F62
telfhash t12d7251f487e434e1a2a5ca5ae7b5b4b0c6730cba57d175b148367d62dfa4f0c0d2ac22
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:CoinMiner elf upx-dec


Avatar
abuse_ch
UPX decompressed file, sourced from SHA256 d5a0377ee9f1732a6f10372750fd638e081edf44a9703eda5d5ef53a2ab82f43
File size (compressed) :1'954'604 bytes
File size (de-compressed) :5'060'624 bytes
Format:linux/amd64
Packed file: d5a0377ee9f1732a6f10372750fd638e081edf44a9703eda5d5ef53a2ab82f43

Intelligence


File Origin
# of uploads :
1
# of downloads :
104
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file
Sends data to a server
Receives data from a server
Changes access rights for a written file
Runs as daemon
Changes the time when the file was created, accessed, or modified
Kills processes
Locks files
Collects information on the CPU
Launching a process
Collects information on the RAM
Connection attempt
Substitutes an application name
Creates or modifies files in /cron to set up autorun
Performs a bruteforce attack in the network
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
expand gcc lolbin
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
true
Architecture:
x86
Packer:
not packed
Botnet:
unknown
Number of open files:
67
Number of processes launched:
1
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
Anti-VM
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Verdict:
Malicious
File Type:
elf.64.le
First seen:
2026-07-21T06:15:00Z UTC
Last seen:
2026-07-21T07:30:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=d31f76fe-2100-0000-17ee-8eda880b0000 pid=2952 /usr/bin/sudo guuid=75c24300-2200-0000-17ee-8eda8e0b0000 pid=2958 /tmp/sample.bin mprotect-exec guuid=d31f76fe-2100-0000-17ee-8eda880b0000 pid=2952->guuid=75c24300-2200-0000-17ee-8eda8e0b0000 pid=2958 execve guuid=48546903-2200-0000-17ee-8eda930b0000 pid=2963 /tmp/sample.bin net zombie guuid=75c24300-2200-0000-17ee-8eda8e0b0000 pid=2958->guuid=48546903-2200-0000-17ee-8eda930b0000 pid=2963 clone 5f6004ab-135d-5863-8d6f-a6f76ba0720b 45.148.10.68:21370 guuid=48546903-2200-0000-17ee-8eda930b0000 pid=2963->5f6004ab-135d-5863-8d6f-a6f76ba0720b con 5493bef4-721b-597b-a55d-af49e1a84f0e 45.148.10.113:21370 guuid=48546903-2200-0000-17ee-8eda930b0000 pid=2963->5493bef4-721b-597b-a55d-af49e1a84f0e con 45f8967d-b6f1-5a0a-9184-ee30bdda1397 45.148.10.112:2137 guuid=48546903-2200-0000-17ee-8eda930b0000 pid=2963->45f8967d-b6f1-5a0a-9184-ee30bdda1397 con 0f31b1cb-e863-5dc9-8beb-7665b59ed1a9 95.215.19.53:853 guuid=48546903-2200-0000-17ee-8eda930b0000 pid=2963->0f31b1cb-e863-5dc9-8beb-7665b59ed1a9 con 14ac75f0-edad-5de2-b6fb-37afde7f0bf7 45.148.10.208:21370 guuid=48546903-2200-0000-17ee-8eda930b0000 pid=2963->14ac75f0-edad-5de2-b6fb-37afde7f0bf7 con guuid=4e7dbe05-2200-0000-17ee-8eda9b0b0000 pid=2971 /usr/bin/dash guuid=48546903-2200-0000-17ee-8eda930b0000 pid=2963->guuid=4e7dbe05-2200-0000-17ee-8eda9b0b0000 pid=2971 execve guuid=cbab0206-2200-0000-17ee-8eda9f0b0000 pid=2975 /tmp/sample.bin guuid=48546903-2200-0000-17ee-8eda930b0000 pid=2963->guuid=cbab0206-2200-0000-17ee-8eda9f0b0000 pid=2975 clone guuid=5d082106-2200-0000-17ee-8edaa20b0000 pid=2978 /usr/bin/dash guuid=48546903-2200-0000-17ee-8eda930b0000 pid=2963->guuid=5d082106-2200-0000-17ee-8edaa20b0000 pid=2978 execve guuid=48546903-2200-0000-17ee-8eda930b0000 pid=3042 /tmp/sample.bin bpf-socket-filter net net-scan send-data write-config zombie guuid=48546903-2200-0000-17ee-8eda930b0000 pid=2963->guuid=48546903-2200-0000-17ee-8eda930b0000 pid=3042 clone guuid=48546903-2200-0000-17ee-8eda930b0000 pid=3073 /tmp/sample.bin guuid=48546903-2200-0000-17ee-8eda930b0000 pid=2963->guuid=48546903-2200-0000-17ee-8eda930b0000 pid=3073 clone guuid=b097e805-2200-0000-17ee-8eda9d0b0000 pid=2973 /usr/bin/dash guuid=4e7dbe05-2200-0000-17ee-8eda9b0b0000 pid=2971->guuid=b097e805-2200-0000-17ee-8eda9d0b0000 pid=2973 clone guuid=638eef05-2200-0000-17ee-8eda9e0b0000 pid=2974 /usr/bin/dash guuid=4e7dbe05-2200-0000-17ee-8eda9b0b0000 pid=2971->guuid=638eef05-2200-0000-17ee-8eda9e0b0000 pid=2974 clone guuid=89270706-2200-0000-17ee-8edaa00b0000 pid=2976 /tmp/sample.bin zombie guuid=cbab0206-2200-0000-17ee-8eda9f0b0000 pid=2975->guuid=89270706-2200-0000-17ee-8edaa00b0000 pid=2976 clone guuid=4d252507-2200-0000-17ee-8edaa60b0000 pid=2982 /usr/sbin/xtables-nft-multi guuid=5d082106-2200-0000-17ee-8edaa20b0000 pid=2978->guuid=4d252507-2200-0000-17ee-8edaa60b0000 pid=2982 execve guuid=efabe916-2200-0000-17ee-8edac00b0000 pid=3008 /usr/sbin/xtables-nft-multi guuid=5d082106-2200-0000-17ee-8edaa20b0000 pid=2978->guuid=efabe916-2200-0000-17ee-8edac00b0000 pid=3008 execve guuid=48546903-2200-0000-17ee-8eda930b0000 pid=3042|network network activity to 2056 IP addresses review logs to see them all guuid=48546903-2200-0000-17ee-8eda930b0000 pid=3042->guuid=48546903-2200-0000-17ee-8eda930b0000 pid=3042|network network guuid=9717b32c-2200-0000-17ee-8edaf40b0000 pid=3060 /usr/bin/dash guuid=48546903-2200-0000-17ee-8eda930b0000 pid=3042->guuid=9717b32c-2200-0000-17ee-8edaf40b0000 pid=3060 execve guuid=a6a8f42c-2200-0000-17ee-8edaf50b0000 pid=3061 /usr/sbin/xtables-nft-multi guuid=9717b32c-2200-0000-17ee-8edaf40b0000 pid=3060->guuid=a6a8f42c-2200-0000-17ee-8edaf50b0000 pid=3061 execve guuid=8e01502d-2200-0000-17ee-8edaf70b0000 pid=3063 /usr/sbin/xtables-nft-multi guuid=9717b32c-2200-0000-17ee-8edaf40b0000 pid=3060->guuid=8e01502d-2200-0000-17ee-8edaf70b0000 pid=3063 execve guuid=4056ab2d-2200-0000-17ee-8edaf90b0000 pid=3065 /usr/sbin/xtables-nft-multi guuid=9717b32c-2200-0000-17ee-8edaf40b0000 pid=3060->guuid=4056ab2d-2200-0000-17ee-8edaf90b0000 pid=3065 execve guuid=9d9e012e-2200-0000-17ee-8edafa0b0000 pid=3066 /usr/sbin/xtables-nft-multi guuid=9717b32c-2200-0000-17ee-8edaf40b0000 pid=3060->guuid=9d9e012e-2200-0000-17ee-8edafa0b0000 pid=3066 execve
Result
Threat name:
Detection:
malicious
Classification:
troj.spyw.mine
Score:
96 / 100
Signature
Antivirus / Scanner detection for submitted sample
Connects to many ports of the same IP (likely port scanning)
Executes the "crontab" command typically for achieving persistence
Executes the "iptables" command to insert, remove and/or manipulate rules
Found strings related to Crypto-Mining
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Opens /sys/class/net/* files useful for querying network interface information
Sample tries to persist itself using cron
Yara detected Xmrig cryptocurrency miner
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1948468 Sample: d5a0377ee9f1732a6f10372750f... Startdate: 27/07/2026 Architecture: LINUX Score: 96 49 154.228.0.223 ZAINUGASUG Uganda 2->49 51 114.211.84.75 XEPHIONNTT-MECorporationJP China 2->51 53 98 other IPs or domains 2->53 57 Malicious sample detected (through community Yara rule) 2->57 59 Antivirus / Scanner detection for submitted sample 2->59 61 Multi AV Scanner detection for submitted file 2->61 63 2 other signatures 2->63 9 d5a0377ee9f1732a6f10372750fd638e081edf44a9703eda5d5ef53a2ab82f43.elf 2->9         started        12 dash rm 2->12         started        14 dash rm 2->14         started        signatures3 process4 signatures5 65 Found strings related to Crypto-Mining 9->65 16 d5a0377ee9f1732a6f10372750fd638e081edf44a9703eda5d5ef53a2ab82f43.elf 9->16         started        process6 signatures7 55 Opens /sys/class/net/* files useful for querying network interface information 16->55 19 d5a0377ee9f1732a6f10372750fd638e081edf44a9703eda5d5ef53a2ab82f43.elf sh 16->19         started        21 d5a0377ee9f1732a6f10372750fd638e081edf44a9703eda5d5ef53a2ab82f43.elf sh 16->21         started        23 d5a0377ee9f1732a6f10372750fd638e081edf44a9703eda5d5ef53a2ab82f43.elf sh 16->23         started        25 2 other processes 16->25 process8 process9 27 sh crontab 19->27         started        31 sh crontab 19->31         started        33 sh 19->33         started        35 sh iptables 21->35         started        37 sh iptables 21->37         started        45 2 other processes 21->45 39 sh iptables 23->39         started        41 sh iptables 23->41         started        43 d5a0377ee9f1732a6f10372750fd638e081edf44a9703eda5d5ef53a2ab82f43.elf 25->43         started        file10 47 /var/spool/cron/crontabs/tmp.zB3dt1, ASCII 27->47 dropped 67 Sample tries to persist itself using cron 27->67 69 Executes the "crontab" command typically for achieving persistence 27->69 71 Executes the "iptables" command to insert, remove and/or manipulate rules 39->71 signatures11
Threat name:
Linux.Coinminer.XMRig
Status:
Malicious
First seen:
2026-07-21 15:35:23 UTC
AV detection:
17 of 38 (44.74%)
Threat level:
  4/5
Result
Malware family:
Score:
  10/10
Tags:
family:xmrig antivm command_and_control defense_evasion discovery execution linux miner persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Changes its process name
Checks CPU configuration
Reads CPU attributes
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Enumerates running processes
Reads hardware information
Reads network interface configuration
Creates Raw socket
Flushes firewall rules
Outbound SSH connection to public host
Unexpected DNS network traffic destination
Contacts a large (303246) amount of remote hosts
Creates a large amount of network flows
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:enterpriseunix2
Author:Tim Brown @timb_machine
Description:Enterprise UNIX
Rule name:Linux_Trojan_Pornoasset_927f314f
Author:Elastic Security
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:miner_lin_xmrig_strings
Author:Sekoia.io
Description:Detects XMRig ELF
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
Rule name:upxHook
Author:@r3dbU7z
Description:Detect artifacts from 'upxHook' - modification of UPX packer
Reference:https://bazaar.abuse.ch/sample/6352be8aa5d8063673aa428c3807228c40505004320232a23d99ebd9ef48478a/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

CoinMiner

elf 382dc078f427e7a2e34bfd03c4d8634f4f2b93cba6e840bfca50dab7f7f7727a

(this sample)

Comments