🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3a98d48c9346e330c7eaccdd25d231e735958f5029e7756b2f9deec75b8125f2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 6


Intelligence 6 IOCs YARA 14 File information Comments

SHA256 hash: 3a98d48c9346e330c7eaccdd25d231e735958f5029e7756b2f9deec75b8125f2
SHA3-384 hash: 7a7dbef07de6741e13261b13815536487f22a5954300d11e2d2a6abaa4182700306e5f88665301ba185fa5aea84ee37c
SHA1 hash: 480f27c4c14b694b3462ab0c85f6d7578cad3bce
MD5 hash: a6fdff137ea8a6fb15c3c0472c953f0e
humanhash: yankee-butter-pip-music
File name:74e87fa2a30a457be066f70b4a47ba63483e17ebaaa7bbb23cfe0e8f376ba469.zip
Download: download sample
Signature CoinMiner
File size:5'069'894 bytes
First seen:2026-09-29 08:29:13 UTC
Last seen:2026-10-01 08:27:10 UTC
File type: zip
MIME type:application/zip
Note:This file is a password protected archive. The password is: infected
ssdeep 98304:gMQHuByQ5GWH/h+PGfa3mMCyJW7BG2SfKcWTJPqHoW1LuwPdC4u5hy7zGg:p6KoWNDyozSCbTwHoW1LnVCf5iGg
TLSH T1E23633DE625D7D596B7079D4086DD840CAAFC1D8696F02CA56083C93C1BFEE3C9C2B62
Magika zip
Reporter DarkDataLabs
Tags:CoinMiner

Intelligence


File Origin
# of uploads :
3
# of downloads :
126
Origin country :
US US
File Archive Information

This file archive contains 18 file(s), sorted by their relevance:

File name:run
File size:376 bytes
SHA256 hash: 289dfa1a65739556b5c90e844d558726b070350aefcad15b11bf83f969472c09
MD5 hash: e757884c25e6b616f2b636925ffc5026
MIME type:text/x-shellscript
Signature CoinMiner
File name:init
File size:967 bytes
SHA256 hash: 658040b1789b15e9ba238bae6520fc0cdcd7eebbdbda3774aef176790c6a2eab
MD5 hash: 7151baf2c01a76581e0f816c7f91de7e
MIME type:text/plain
Signature CoinMiner
File name:kthreadadd
File size:216 bytes
SHA256 hash: d6228ada864c88960c9b7f7d527f831ad7440daff4be455d895f4ad15d62223e
MD5 hash: 3a684fd75149823a983b121d7b4a22a2
MIME type:text/x-shellscript
Signature CoinMiner
File name:crond
File size:2'781'976 bytes
SHA256 hash: 2ab4da58efa51dadd0787a32b44cf8533d3d3a7bc1788123c112dcb267821030
MD5 hash: 531527ac24a1501cb39959c10a04a79b
MIME type:application/x-executable
Signature CoinMiner
File name:kthreadadd64
File size:1'145'176 bytes
SHA256 hash: 94d45a4da52d0b4593387673b8579892c866b19d71408dde550800050a3d65b8
MD5 hash: a803de211bbdc0dfae46c5e2af7b2591
MIME type:application/x-executable
Signature CoinMiner
File name:delsshd
File size:1'543 bytes
SHA256 hash: e450d3eb9d15c8585e776eabbec02fb6286e8738f9ef200746322da2f66fed93
MD5 hash: c26752eb21cd360070f2b757963a2fe2
MIME type:text/plain
Signature CoinMiner
File name:stop
File size:1'253 bytes
SHA256 hash: 767db73de8cbe6bf2ca192ef5730c70c1d3a9f1e4e783d5f3d8df2c52bc4fb5c
MD5 hash: df9471e0f14d5c6ee60768ae5cecb209
MIME type:text/x-shellscript
Signature CoinMiner
File name:v
File size:0 bytes
SHA256 hash: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
MD5 hash: d41d8cd98f00b204e9800998ecf8427e
MIME type:inode/x-empty
Signature CoinMiner
File name:init01
File size:9'389 bytes
SHA256 hash: 82eba36c8ac1613f451333eae4bff558e53cf814938d4b181790644371400eec
MD5 hash: e8ffc6aac5c2784b10319c25d229a44e
MIME type:text/x-shellscript
Signature CoinMiner
File name:init2
File size:713 bytes
SHA256 hash: 07e3060d67a7afb8a6ce14ca4e183bfa9436a28d2608b4e736a1278fd7a7d447
MD5 hash: f34e5bdf60d3c86facf84d899b6ae974
MIME type:text/plain
Signature CoinMiner
File name:a
File size:6'571 bytes
SHA256 hash: c8913c895f8ae2fc1ec6162850c0843f875f7882b6742550d68b101cbf662898
MD5 hash: 69c7923ed59fb2c2b98952e2388c152b
MIME type:text/x-shellscript
Signature CoinMiner
File name:kthreadadd32
File size:1'170'868 bytes
SHA256 hash: 289abf2d87fb23983de053535a7e2946a90865c2d96f80f94f491e28c388fb1f
MD5 hash: 2d9562fe6d78e5eb5932e9f827a21385
MIME type:application/x-executable
Signature CoinMiner
File name:go
File size:1'030 bytes
SHA256 hash: 4c9a37391ad2dcd1d8403ffe3cbc7c21899364c68b251a9692efb5eac588b1c1
MD5 hash: 7ea7e3a9597b233f4a197335ca37b10d
MIME type:text/x-shellscript
Signature CoinMiner
File name:rmkwork
File size:2'121 bytes
SHA256 hash: efa6d7375136e09ed7e0116f33d63ae34f480ebeaac82bdb1d11190714e6c793
MD5 hash: 93556f520cced7aaabbf4cf7dc066e57
MIME type:text/x-shellscript
Signature CoinMiner
File name:init02
File size:4'034 bytes
SHA256 hash: 6c1831216e42bd6f907e5f0f07a4c23e9e047dba3ca943fa7fe304d318c2555d
MD5 hash: 6929b19efca6d8371db14062d4535964
MIME type:text/x-shellscript
Signature CoinMiner
File name:initall
File size:193 bytes
SHA256 hash: 4a126e7fbd235ceda41d0e0c89dd43af6008a025681e74fc39c24cbf3050a6f9
MD5 hash: 569cb7206b83d666f77d50610c7b969f
MIME type:text/x-shellscript
Signature CoinMiner
File name:start
File size:203 bytes
SHA256 hash: 9dbbc9b5d7793425968e42e995226c5f9fe32e502a0a694320a5e838d57c8836
MD5 hash: ffd387bdf3adab8969941693d3a86ee7
MIME type:text/x-shellscript
Signature CoinMiner
File name:clean.sh
File size:8'201 bytes
SHA256 hash: 486d24d4c640561478f4bdf813b208e04d483e11ba3f4306275f3655356e2762
MD5 hash: d49d1d183a20fb5a5faf51bad349f620
MIME type:text/x-shellscript
Signature CoinMiner
Vendor Threat Intelligence
Verdict:
inconclusive
YARA:
2 match(es)
Tags:
Elf Executable Executable Zip Archive
Result
Malware family:
xmrig_linux
Score:
  10/10
Tags:
family:xmrig family:xmrig_linux antivm defense_evasion discovery linux miner persistence privilege_escalation rootkit upx
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads CPU attributes
Checks hardware identifiers (DMI)
Enumerates running processes
Reads hardware information
Removes the immutable protection flag from a file
Write file to user bin folder
File and Directory Permissions Modification
Executes dropped EXE
Loads a kernel module
XMRig Miner payload
Family: xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:SUSP_ELF_LNX_UPX_Compressed_File
Author:Florian Roth (Nextron Systems)
Description:Detects a suspicious ELF binary with UPX compression
Reference:Internal Research
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:upxHook
Author:@r3dbU7z
Description:Detect artifacts from 'upxHook' - modification of UPX packer
Reference:https://bazaar.abuse.ch/sample/6352be8aa5d8063673aa428c3807228c40505004320232a23d99ebd9ef48478a/
Rule name:UPXProtectorv10x2
Author:malware-lu
Rule name:upx_packed_elf_v1
Author:RandomMalware
Rule name:WHIRLPOOL_Constants
Author:phoul (@phoul)
Description:Look for WhirlPool constants

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments