MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3847ec9b4a287b43d5d7dc9b1d5e4cc06b1ea3b768585f2a02ae591502e26c6f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 3847ec9b4a287b43d5d7dc9b1d5e4cc06b1ea3b768585f2a02ae591502e26c6f
SHA3-384 hash: ea628ba5383492e5b69762caf2a272ad6480eb5e346461b18f1ae780c4c6ecb5501b288db6c068d74aa7e9b23014e84d
SHA1 hash: 74b11a8fb5a62ff283ec28dc0708bd87b574c6fc
MD5 hash: faf01eab6dec494af7fbf152bf08d9ec
humanhash: gee-mike-ceiling-alaska
File name:aq.sh
Download: download sample
Signature CoinMiner
File size:583 bytes
First seen:2025-06-19 04:36:36 UTC
Last seen:2025-06-19 16:27:49 UTC
File type: sh
MIME type:text/plain
ssdeep 12:3WKDbnPZ7XOpue8f+AiJKq75L7KqwYf+D7bnQL7bnYMHqwYf+Y:GIbRi4wPFLeYf+DPQLPYUYf+Y
TLSH T102F078C99A22A870A6550DDEF0ABC404C989D7C5B6D36C58E6D0187E4C1E80037A9B27
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://158.51.126.131/nx86_64d586cb5dc9c05fb33f20045434f3c4abab2672c98effa6bc4ad0e84d414add81 Miraielf mirai ua-wget
http://158.51.126.131/ibark4funn/an/aCoinMiner

Intelligence


File Origin
# of uploads :
2
# of downloads :
81
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
92.5%
Tags:
backdoor agent hype
Status:
terminated
Behavior Graph:
%3 guuid=6b04a7b4-1a00-0000-af99-574e01080000 pid=2049 /usr/bin/sudo guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055 /tmp/sample.bin guuid=6b04a7b4-1a00-0000-af99-574e01080000 pid=2049->guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055 execve guuid=272d9cb7-1a00-0000-af99-574e09080000 pid=2057 /usr/bin/rm delete-file guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=272d9cb7-1a00-0000-af99-574e09080000 pid=2057 execve guuid=1696e8b7-1a00-0000-af99-574e0b080000 pid=2059 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=1696e8b7-1a00-0000-af99-574e0b080000 pid=2059 execve guuid=dc584db8-1a00-0000-af99-574e0d080000 pid=2061 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=dc584db8-1a00-0000-af99-574e0d080000 pid=2061 execve guuid=a74ac5b8-1a00-0000-af99-574e0e080000 pid=2062 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=a74ac5b8-1a00-0000-af99-574e0e080000 pid=2062 execve guuid=eb2c4eb9-1a00-0000-af99-574e0f080000 pid=2063 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=eb2c4eb9-1a00-0000-af99-574e0f080000 pid=2063 execve guuid=3f66f0b9-1a00-0000-af99-574e10080000 pid=2064 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=3f66f0b9-1a00-0000-af99-574e10080000 pid=2064 execve guuid=086574ba-1a00-0000-af99-574e11080000 pid=2065 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=086574ba-1a00-0000-af99-574e11080000 pid=2065 execve guuid=c8f5dbba-1a00-0000-af99-574e13080000 pid=2067 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=c8f5dbba-1a00-0000-af99-574e13080000 pid=2067 execve guuid=4f755dbb-1a00-0000-af99-574e14080000 pid=2068 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=4f755dbb-1a00-0000-af99-574e14080000 pid=2068 execve guuid=d4bde6bb-1a00-0000-af99-574e15080000 pid=2069 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=d4bde6bb-1a00-0000-af99-574e15080000 pid=2069 execve guuid=390158bc-1a00-0000-af99-574e16080000 pid=2070 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=390158bc-1a00-0000-af99-574e16080000 pid=2070 execve guuid=56f3c4bc-1a00-0000-af99-574e17080000 pid=2071 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=56f3c4bc-1a00-0000-af99-574e17080000 pid=2071 execve guuid=7eba25bd-1a00-0000-af99-574e1a080000 pid=2074 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=7eba25bd-1a00-0000-af99-574e1a080000 pid=2074 execve guuid=763b85bd-1a00-0000-af99-574e1c080000 pid=2076 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=763b85bd-1a00-0000-af99-574e1c080000 pid=2076 execve guuid=1132e5bd-1a00-0000-af99-574e1e080000 pid=2078 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=1132e5bd-1a00-0000-af99-574e1e080000 pid=2078 execve guuid=d35b4ebe-1a00-0000-af99-574e21080000 pid=2081 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=d35b4ebe-1a00-0000-af99-574e21080000 pid=2081 execve guuid=f6e0b4be-1a00-0000-af99-574e22080000 pid=2082 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=f6e0b4be-1a00-0000-af99-574e22080000 pid=2082 execve guuid=c0da3fbf-1a00-0000-af99-574e24080000 pid=2084 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=c0da3fbf-1a00-0000-af99-574e24080000 pid=2084 execve guuid=c685b0bf-1a00-0000-af99-574e25080000 pid=2085 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=c685b0bf-1a00-0000-af99-574e25080000 pid=2085 execve guuid=07e523c0-1a00-0000-af99-574e26080000 pid=2086 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=07e523c0-1a00-0000-af99-574e26080000 pid=2086 execve guuid=ef3e89c0-1a00-0000-af99-574e28080000 pid=2088 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=ef3e89c0-1a00-0000-af99-574e28080000 pid=2088 execve guuid=1ab9eac0-1a00-0000-af99-574e2b080000 pid=2091 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=1ab9eac0-1a00-0000-af99-574e2b080000 pid=2091 execve guuid=73ef4dc1-1a00-0000-af99-574e2d080000 pid=2093 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=73ef4dc1-1a00-0000-af99-574e2d080000 pid=2093 execve guuid=8322adc1-1a00-0000-af99-574e2f080000 pid=2095 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=8322adc1-1a00-0000-af99-574e2f080000 pid=2095 execve guuid=5b4b10c2-1a00-0000-af99-574e31080000 pid=2097 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=5b4b10c2-1a00-0000-af99-574e31080000 pid=2097 execve guuid=566476c2-1a00-0000-af99-574e33080000 pid=2099 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=566476c2-1a00-0000-af99-574e33080000 pid=2099 execve guuid=f8e8efc2-1a00-0000-af99-574e34080000 pid=2100 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=f8e8efc2-1a00-0000-af99-574e34080000 pid=2100 execve guuid=71865bc3-1a00-0000-af99-574e37080000 pid=2103 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=71865bc3-1a00-0000-af99-574e37080000 pid=2103 execve guuid=267213c4-1a00-0000-af99-574e3a080000 pid=2106 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=267213c4-1a00-0000-af99-574e3a080000 pid=2106 execve guuid=23a074c4-1a00-0000-af99-574e3d080000 pid=2109 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=23a074c4-1a00-0000-af99-574e3d080000 pid=2109 execve guuid=a9d9cfc4-1a00-0000-af99-574e3e080000 pid=2110 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=a9d9cfc4-1a00-0000-af99-574e3e080000 pid=2110 execve guuid=329f42c5-1a00-0000-af99-574e3f080000 pid=2111 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=329f42c5-1a00-0000-af99-574e3f080000 pid=2111 execve guuid=dc59adc5-1a00-0000-af99-574e41080000 pid=2113 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=dc59adc5-1a00-0000-af99-574e41080000 pid=2113 execve guuid=256d2bc6-1a00-0000-af99-574e42080000 pid=2114 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=256d2bc6-1a00-0000-af99-574e42080000 pid=2114 execve guuid=b838a6c6-1a00-0000-af99-574e43080000 pid=2115 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=b838a6c6-1a00-0000-af99-574e43080000 pid=2115 execve guuid=12521cc7-1a00-0000-af99-574e44080000 pid=2116 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=12521cc7-1a00-0000-af99-574e44080000 pid=2116 execve guuid=bd0f8cc7-1a00-0000-af99-574e47080000 pid=2119 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=bd0f8cc7-1a00-0000-af99-574e47080000 pid=2119 execve guuid=684802c8-1a00-0000-af99-574e49080000 pid=2121 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=684802c8-1a00-0000-af99-574e49080000 pid=2121 execve guuid=31e16ec8-1a00-0000-af99-574e4c080000 pid=2124 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=31e16ec8-1a00-0000-af99-574e4c080000 pid=2124 execve guuid=8ba8ccc8-1a00-0000-af99-574e4e080000 pid=2126 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=8ba8ccc8-1a00-0000-af99-574e4e080000 pid=2126 execve guuid=790854c9-1a00-0000-af99-574e51080000 pid=2129 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=790854c9-1a00-0000-af99-574e51080000 pid=2129 execve guuid=35ecbec9-1a00-0000-af99-574e53080000 pid=2131 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=35ecbec9-1a00-0000-af99-574e53080000 pid=2131 execve guuid=c5fa46ca-1a00-0000-af99-574e55080000 pid=2133 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=c5fa46ca-1a00-0000-af99-574e55080000 pid=2133 execve guuid=bc63d8ca-1a00-0000-af99-574e58080000 pid=2136 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=bc63d8ca-1a00-0000-af99-574e58080000 pid=2136 execve guuid=8a995ccb-1a00-0000-af99-574e5a080000 pid=2138 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=8a995ccb-1a00-0000-af99-574e5a080000 pid=2138 execve guuid=ec17bdcb-1a00-0000-af99-574e5d080000 pid=2141 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=ec17bdcb-1a00-0000-af99-574e5d080000 pid=2141 execve guuid=a81920cc-1a00-0000-af99-574e5f080000 pid=2143 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=a81920cc-1a00-0000-af99-574e5f080000 pid=2143 execve guuid=d94f88cc-1a00-0000-af99-574e62080000 pid=2146 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=d94f88cc-1a00-0000-af99-574e62080000 pid=2146 execve guuid=2691f3cc-1a00-0000-af99-574e63080000 pid=2147 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=2691f3cc-1a00-0000-af99-574e63080000 pid=2147 execve guuid=672052cd-1a00-0000-af99-574e65080000 pid=2149 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=672052cd-1a00-0000-af99-574e65080000 pid=2149 execve guuid=1d8fbfcd-1a00-0000-af99-574e66080000 pid=2150 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=1d8fbfcd-1a00-0000-af99-574e66080000 pid=2150 execve guuid=fa823bce-1a00-0000-af99-574e67080000 pid=2151 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=fa823bce-1a00-0000-af99-574e67080000 pid=2151 execve guuid=9b42d4ce-1a00-0000-af99-574e69080000 pid=2153 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=9b42d4ce-1a00-0000-af99-574e69080000 pid=2153 execve guuid=72f86dcf-1a00-0000-af99-574e6a080000 pid=2154 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=72f86dcf-1a00-0000-af99-574e6a080000 pid=2154 execve guuid=1008f9cf-1a00-0000-af99-574e6b080000 pid=2155 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=1008f9cf-1a00-0000-af99-574e6b080000 pid=2155 execve guuid=f3426ad0-1a00-0000-af99-574e6d080000 pid=2157 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=f3426ad0-1a00-0000-af99-574e6d080000 pid=2157 execve guuid=3af3d2d0-1a00-0000-af99-574e6f080000 pid=2159 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=3af3d2d0-1a00-0000-af99-574e6f080000 pid=2159 execve guuid=e53937d1-1a00-0000-af99-574e71080000 pid=2161 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=e53937d1-1a00-0000-af99-574e71080000 pid=2161 execve guuid=8d1898d1-1a00-0000-af99-574e73080000 pid=2163 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=8d1898d1-1a00-0000-af99-574e73080000 pid=2163 execve guuid=b5522cd2-1a00-0000-af99-574e76080000 pid=2166 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=b5522cd2-1a00-0000-af99-574e76080000 pid=2166 execve guuid=68e792d2-1a00-0000-af99-574e78080000 pid=2168 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=68e792d2-1a00-0000-af99-574e78080000 pid=2168 execve guuid=8ff8eed2-1a00-0000-af99-574e7a080000 pid=2170 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=8ff8eed2-1a00-0000-af99-574e7a080000 pid=2170 execve guuid=adc44ad3-1a00-0000-af99-574e7c080000 pid=2172 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=adc44ad3-1a00-0000-af99-574e7c080000 pid=2172 execve guuid=2625aad3-1a00-0000-af99-574e7e080000 pid=2174 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=2625aad3-1a00-0000-af99-574e7e080000 pid=2174 execve guuid=b40315d4-1a00-0000-af99-574e80080000 pid=2176 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=b40315d4-1a00-0000-af99-574e80080000 pid=2176 execve guuid=82df7cd4-1a00-0000-af99-574e83080000 pid=2179 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=82df7cd4-1a00-0000-af99-574e83080000 pid=2179 execve guuid=f194e1d4-1a00-0000-af99-574e84080000 pid=2180 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=f194e1d4-1a00-0000-af99-574e84080000 pid=2180 execve guuid=2dab5cd5-1a00-0000-af99-574e87080000 pid=2183 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=2dab5cd5-1a00-0000-af99-574e87080000 pid=2183 execve guuid=a38ee3d5-1a00-0000-af99-574e89080000 pid=2185 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=a38ee3d5-1a00-0000-af99-574e89080000 pid=2185 execve guuid=8a2051d6-1a00-0000-af99-574e8b080000 pid=2187 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=8a2051d6-1a00-0000-af99-574e8b080000 pid=2187 execve guuid=18efb7d6-1a00-0000-af99-574e8d080000 pid=2189 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=18efb7d6-1a00-0000-af99-574e8d080000 pid=2189 execve guuid=5d824bd7-1a00-0000-af99-574e90080000 pid=2192 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=5d824bd7-1a00-0000-af99-574e90080000 pid=2192 execve guuid=69eeeed7-1a00-0000-af99-574e93080000 pid=2195 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=69eeeed7-1a00-0000-af99-574e93080000 pid=2195 execve guuid=850d54d8-1a00-0000-af99-574e95080000 pid=2197 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=850d54d8-1a00-0000-af99-574e95080000 pid=2197 execve guuid=f2d4f2d8-1a00-0000-af99-574e97080000 pid=2199 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=f2d4f2d8-1a00-0000-af99-574e97080000 pid=2199 execve guuid=1e0599d9-1a00-0000-af99-574e99080000 pid=2201 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=1e0599d9-1a00-0000-af99-574e99080000 pid=2201 execve guuid=cbad34da-1a00-0000-af99-574e9c080000 pid=2204 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=cbad34da-1a00-0000-af99-574e9c080000 pid=2204 execve guuid=ae98afda-1a00-0000-af99-574e9f080000 pid=2207 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=ae98afda-1a00-0000-af99-574e9f080000 pid=2207 execve guuid=c2ef24db-1a00-0000-af99-574ea2080000 pid=2210 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=c2ef24db-1a00-0000-af99-574ea2080000 pid=2210 execve guuid=ccdb95db-1a00-0000-af99-574ea4080000 pid=2212 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=ccdb95db-1a00-0000-af99-574ea4080000 pid=2212 execve guuid=22f107dc-1a00-0000-af99-574ea6080000 pid=2214 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=22f107dc-1a00-0000-af99-574ea6080000 pid=2214 execve guuid=217883dc-1a00-0000-af99-574ea9080000 pid=2217 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=217883dc-1a00-0000-af99-574ea9080000 pid=2217 execve guuid=9520e6dc-1a00-0000-af99-574eab080000 pid=2219 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=9520e6dc-1a00-0000-af99-574eab080000 pid=2219 execve guuid=a7aa9add-1a00-0000-af99-574eae080000 pid=2222 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=a7aa9add-1a00-0000-af99-574eae080000 pid=2222 execve guuid=89240ede-1a00-0000-af99-574eb1080000 pid=2225 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=89240ede-1a00-0000-af99-574eb1080000 pid=2225 execve guuid=6b976dde-1a00-0000-af99-574eb3080000 pid=2227 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=6b976dde-1a00-0000-af99-574eb3080000 pid=2227 execve guuid=1153cade-1a00-0000-af99-574eb5080000 pid=2229 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=1153cade-1a00-0000-af99-574eb5080000 pid=2229 execve guuid=654c06e0-1a00-0000-af99-574eb8080000 pid=2232 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=654c06e0-1a00-0000-af99-574eb8080000 pid=2232 execve guuid=eefc93e0-1a00-0000-af99-574ebb080000 pid=2235 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=eefc93e0-1a00-0000-af99-574ebb080000 pid=2235 execve guuid=676b41e1-1a00-0000-af99-574ebd080000 pid=2237 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=676b41e1-1a00-0000-af99-574ebd080000 pid=2237 execve guuid=c6c8e9e1-1a00-0000-af99-574ec0080000 pid=2240 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=c6c8e9e1-1a00-0000-af99-574ec0080000 pid=2240 execve guuid=95c569e2-1a00-0000-af99-574ec3080000 pid=2243 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=95c569e2-1a00-0000-af99-574ec3080000 pid=2243 execve guuid=0114e4e2-1a00-0000-af99-574ec5080000 pid=2245 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=0114e4e2-1a00-0000-af99-574ec5080000 pid=2245 execve guuid=8cf25ae3-1a00-0000-af99-574ec8080000 pid=2248 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=8cf25ae3-1a00-0000-af99-574ec8080000 pid=2248 execve guuid=e5e4cae3-1a00-0000-af99-574eca080000 pid=2250 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=e5e4cae3-1a00-0000-af99-574eca080000 pid=2250 execve guuid=6d423ce4-1a00-0000-af99-574ecc080000 pid=2252 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=6d423ce4-1a00-0000-af99-574ecc080000 pid=2252 execve guuid=cb590de5-1a00-0000-af99-574ed0080000 pid=2256 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=cb590de5-1a00-0000-af99-574ed0080000 pid=2256 execve guuid=a5b2a7e5-1a00-0000-af99-574ed2080000 pid=2258 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=a5b2a7e5-1a00-0000-af99-574ed2080000 pid=2258 execve guuid=bd7121e6-1a00-0000-af99-574ed4080000 pid=2260 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=bd7121e6-1a00-0000-af99-574ed4080000 pid=2260 execve guuid=ffdf8ae6-1a00-0000-af99-574ed6080000 pid=2262 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=ffdf8ae6-1a00-0000-af99-574ed6080000 pid=2262 execve guuid=9483ebe6-1a00-0000-af99-574ed8080000 pid=2264 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=9483ebe6-1a00-0000-af99-574ed8080000 pid=2264 execve guuid=4a0b4be7-1a00-0000-af99-574eda080000 pid=2266 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=4a0b4be7-1a00-0000-af99-574eda080000 pid=2266 execve guuid=ecd4aae7-1a00-0000-af99-574edc080000 pid=2268 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=ecd4aae7-1a00-0000-af99-574edc080000 pid=2268 execve guuid=81eb15e8-1a00-0000-af99-574ede080000 pid=2270 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=81eb15e8-1a00-0000-af99-574ede080000 pid=2270 execve guuid=2dab84e8-1a00-0000-af99-574ee0080000 pid=2272 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=2dab84e8-1a00-0000-af99-574ee0080000 pid=2272 execve guuid=7e4519e9-1a00-0000-af99-574ee4080000 pid=2276 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=7e4519e9-1a00-0000-af99-574ee4080000 pid=2276 execve guuid=060e76e9-1a00-0000-af99-574ee6080000 pid=2278 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=060e76e9-1a00-0000-af99-574ee6080000 pid=2278 execve guuid=8e13d9e9-1a00-0000-af99-574ee9080000 pid=2281 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=8e13d9e9-1a00-0000-af99-574ee9080000 pid=2281 execve guuid=dca240ea-1a00-0000-af99-574eeb080000 pid=2283 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=dca240ea-1a00-0000-af99-574eeb080000 pid=2283 execve guuid=0114adea-1a00-0000-af99-574eee080000 pid=2286 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=0114adea-1a00-0000-af99-574eee080000 pid=2286 execve guuid=35842aeb-1a00-0000-af99-574ef0080000 pid=2288 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=35842aeb-1a00-0000-af99-574ef0080000 pid=2288 execve guuid=5e13adeb-1a00-0000-af99-574ef3080000 pid=2291 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=5e13adeb-1a00-0000-af99-574ef3080000 pid=2291 execve guuid=075214ec-1a00-0000-af99-574ef5080000 pid=2293 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=075214ec-1a00-0000-af99-574ef5080000 pid=2293 execve guuid=6d9470ec-1a00-0000-af99-574ef7080000 pid=2295 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=6d9470ec-1a00-0000-af99-574ef7080000 pid=2295 execve guuid=bb7ad2ec-1a00-0000-af99-574ef9080000 pid=2297 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=bb7ad2ec-1a00-0000-af99-574ef9080000 pid=2297 execve guuid=259734ed-1a00-0000-af99-574efb080000 pid=2299 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=259734ed-1a00-0000-af99-574efb080000 pid=2299 execve guuid=665d8fed-1a00-0000-af99-574efe080000 pid=2302 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=665d8fed-1a00-0000-af99-574efe080000 pid=2302 execve guuid=78f5efed-1a00-0000-af99-574e00090000 pid=2304 /usr/bin/ls guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=78f5efed-1a00-0000-af99-574e00090000 pid=2304 execve guuid=b72b5fee-1a00-0000-af99-574e03090000 pid=2307 /usr/bin/dash guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=b72b5fee-1a00-0000-af99-574e03090000 pid=2307 clone guuid=11f0fb1d-1b00-0000-af99-574e70090000 pid=2416 /usr/bin/chmod guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=11f0fb1d-1b00-0000-af99-574e70090000 pid=2416 execve guuid=6db8331e-1b00-0000-af99-574e71090000 pid=2417 /home/ntpclient guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=6db8331e-1b00-0000-af99-574e71090000 pid=2417 execve guuid=63280942-1b00-0000-af99-574e73090000 pid=2419 /usr/bin/dash guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=63280942-1b00-0000-af99-574e73090000 pid=2419 clone guuid=ebf71ba3-1b00-0000-af99-574e340a0000 pid=2612 /usr/bin/chmod guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=ebf71ba3-1b00-0000-af99-574e340a0000 pid=2612 execve guuid=165b5fa3-1b00-0000-af99-574e350a0000 pid=2613 /home/ntpclient mprotect-exec guuid=cb5357b7-1a00-0000-af99-574e07080000 pid=2055->guuid=165b5fa3-1b00-0000-af99-574e350a0000 pid=2613 execve guuid=e3f16bee-1a00-0000-af99-574e04090000 pid=2308 /usr/bin/curl net send-data write-file guuid=b72b5fee-1a00-0000-af99-574e03090000 pid=2307->guuid=e3f16bee-1a00-0000-af99-574e04090000 pid=2308 execve 2beca644-24da-5e18-bc49-c06b8c4a111d 158.51.126.131:80 guuid=e3f16bee-1a00-0000-af99-574e04090000 pid=2308->2beca644-24da-5e18-bc49-c06b8c4a111d send: 85B guuid=e8fcf641-1b00-0000-af99-574e72090000 pid=2418 /home/klogd dns net send-data zombie guuid=6db8331e-1b00-0000-af99-574e71090000 pid=2417->guuid=e8fcf641-1b00-0000-af99-574e72090000 pid=2418 clone 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=e8fcf641-1b00-0000-af99-574e72090000 pid=2418->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 88B e7650c37-2d48-5bba-9655-17990176f334 167.99.179.81:8443 guuid=e8fcf641-1b00-0000-af99-574e72090000 pid=2418->e7650c37-2d48-5bba-9655-17990176f334 send: 785B 7f30281f-6565-565b-903e-76ab0b9d4286 stun.l.google.com:19302 guuid=e8fcf641-1b00-0000-af99-574e72090000 pid=2418->7f30281f-6565-565b-903e-76ab0b9d4286 send: 20B 0d99cd9b-0458-5ab2-aeb6-2b96e18f1cd9 167.99.179.81:9000 guuid=e8fcf641-1b00-0000-af99-574e72090000 pid=2418->0d99cd9b-0458-5ab2-aeb6-2b96e18f1cd9 send: 32B guuid=11597292-1b00-0000-af99-574e0e0a0000 pid=2574 /home/klogd dns net send-data guuid=e8fcf641-1b00-0000-af99-574e72090000 pid=2418->guuid=11597292-1b00-0000-af99-574e0e0a0000 pid=2574 clone guuid=e8081842-1b00-0000-af99-574e74090000 pid=2420 /usr/bin/curl net send-data write-file guuid=63280942-1b00-0000-af99-574e73090000 pid=2419->guuid=e8081842-1b00-0000-af99-574e74090000 pid=2420 execve guuid=e8081842-1b00-0000-af99-574e74090000 pid=2420->2beca644-24da-5e18-bc49-c06b8c4a111d send: 87B guuid=11597292-1b00-0000-af99-574e0e0a0000 pid=2574->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 542B a4109754-3997-5f42-83f5-f487770de60e dualstack.zd.map.fastly.net:80 guuid=11597292-1b00-0000-af99-574e0e0a0000 pid=2574->a4109754-3997-5f42-83f5-f487770de60e send: 115B 9a1f19f7-05c7-58ab-bb1e-9e2201dd7599 ookla.snt.utwente.nl:8080 guuid=11597292-1b00-0000-af99-574e0e0a0000 pid=2574->9a1f19f7-05c7-58ab-bb1e-9e2201dd7599 send: 113B 80b46101-7099-5c85-a2dc-644bdcdb628e speedtest.agw1.as49436.net:8080 guuid=11597292-1b00-0000-af99-574e0e0a0000 pid=2574->80b46101-7099-5c85-a2dc-644bdcdb628e send: 67794112B ece7dee1-c772-5b7f-933d-8eeef2534107 speedtest.agw2.as49436.net:8080 guuid=11597292-1b00-0000-af99-574e0e0a0000 pid=2574->ece7dee1-c772-5b7f-933d-8eeef2534107 send: 119B 202b70f1-48d6-52a4-a97f-da0985c0ff89 speedtest.stadtwerke-soest.de:8080 guuid=11597292-1b00-0000-af99-574e0e0a0000 pid=2574->202b70f1-48d6-52a4-a97f-da0985c0ff89 send: 122B c969a2a0-e062-54ba-9dac-58e05b641d6c speedtest.schlueter-server.de:8080 guuid=11597292-1b00-0000-af99-574e0e0a0000 pid=2574->c969a2a0-e062-54ba-9dac-58e05b641d6c send: 122B 8795ff54-6bd8-5b6f-91a6-97541d65c1d5 nl.st.spacecore.pro:8080 guuid=11597292-1b00-0000-af99-574e0e0a0000 pid=2574->8795ff54-6bd8-5b6f-91a6-97541d65c1d5 send: 112B 5795d144-bba6-5454-9a77-b19ce2f10776 speedtest.wol.jonasdevries.de:8080 guuid=11597292-1b00-0000-af99-574e0e0a0000 pid=2574->5795d144-bba6-5454-9a77-b19ce2f10776 send: 122B 464a049a-1462-5e70-82e5-e82c0c936861 dus.speedtest.komdsl.de:8080 guuid=11597292-1b00-0000-af99-574e0e0a0000 pid=2574->464a049a-1462-5e70-82e5-e82c0c936861 send: 116B 356734c6-dbe0-54ca-9245-7cbb0d3c962c speed.de-west-02.wiit-cloud.io:8080 guuid=11597292-1b00-0000-af99-574e0e0a0000 pid=2574->356734c6-dbe0-54ca-9245-7cbb0d3c962c send: 123B 0c4e3e48-3683-5f2a-9d3a-bb78829182ae speedtest01.netmountains.space:8080 guuid=11597292-1b00-0000-af99-574e0e0a0000 pid=2574->0c4e3e48-3683-5f2a-9d3a-bb78829182ae send: 123B guuid=be2519a5-1b00-0000-af99-574e3b0a0000 pid=2619 /home/ntpclient zombie guuid=165b5fa3-1b00-0000-af99-574e350a0000 pid=2613->guuid=be2519a5-1b00-0000-af99-574e3b0a0000 pid=2619 clone guuid=631534a5-1b00-0000-af99-574e3c0a0000 pid=2620 /home/ntpclient guuid=be2519a5-1b00-0000-af99-574e3b0a0000 pid=2619->guuid=631534a5-1b00-0000-af99-574e3c0a0000 pid=2620 clone guuid=631534a5-1b00-0000-af99-574e3c0a0000 pid=2621 /home/ntpclient guuid=631534a5-1b00-0000-af99-574e3c0a0000 pid=2620->guuid=631534a5-1b00-0000-af99-574e3c0a0000 pid=2621 clone guuid=631534a5-1b00-0000-af99-574e3c0a0000 pid=2622 /home/ntpclient guuid=631534a5-1b00-0000-af99-574e3c0a0000 pid=2620->guuid=631534a5-1b00-0000-af99-574e3c0a0000 pid=2622 clone guuid=631534a5-1b00-0000-af99-574e3c0a0000 pid=2623 /home/ntpclient guuid=631534a5-1b00-0000-af99-574e3c0a0000 pid=2620->guuid=631534a5-1b00-0000-af99-574e3c0a0000 pid=2623 clone guuid=631534a5-1b00-0000-af99-574e3c0a0000 pid=2624 /home/ntpclient guuid=631534a5-1b00-0000-af99-574e3c0a0000 pid=2620->guuid=631534a5-1b00-0000-af99-574e3c0a0000 pid=2624 clone guuid=631534a5-1b00-0000-af99-574e3c0a0000 pid=2625 /home/ntpclient guuid=631534a5-1b00-0000-af99-574e3c0a0000 pid=2620->guuid=631534a5-1b00-0000-af99-574e3c0a0000 pid=2625 clone
Threat name:
Script.Trojan.Multiverze
Status:
Malicious
First seen:
2025-06-19 00:07:43 UTC
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CoinMiner

sh 3847ec9b4a287b43d5d7dc9b1d5e4cc06b1ea3b768585f2a02ae591502e26c6f

(this sample)

  
Delivery method
Distributed via web download

Comments