MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3e83e0866bf9d3191febe8560374849ccff901f4071b76543bd431785300c3c6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: 3e83e0866bf9d3191febe8560374849ccff901f4071b76543bd431785300c3c6
SHA3-384 hash: 7c16bce1ecc7cdbe127650ba4a1361914290cebe377620e36de0a65c7c19af8b039cfe86e2bf6f4507ca23d2465853b3
SHA1 hash: 234550fe84e2f864cf0e6b053dc0b3a2b3b2a201
MD5 hash: 9b0e4a9338bc2193d112b0c52be8edd8
humanhash: march-charlie-yellow-virginia
File name:run-CN.sh
Download: download sample
Signature CoinMiner
File size:6'356 bytes
First seen:2025-08-03 17:48:37 UTC
Last seen:2025-08-04 00:51:17 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 192:2I848CzDN1eEXOKD5+rqaBxayH3MeYVxbMNZlu:hvnc95PAxbyu
TLSH T1FED17405FB81DAF425D8C168044A1D80694B511B3D092C18FCEDB5AABF28B6C62FDBF6
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.248.53.119:8000/mon.sh1e891ab1521b27923233e694f60fdbf0e1b840e657d8b1ffdefd8b5ef5e38964 CoinMinerCoinMiner
http://162.248.53.119:8000/yes.tar.gzn/an/aopendir
https://cdn.tempfile.pro/0c748b9e8bc6b5b4/huby33.binn/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
33
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=47edf795-1600-0000-89b8-4ef4b70c0000 pid=3255 /usr/bin/sudo guuid=8ff4ca98-1600-0000-89b8-4ef4bf0c0000 pid=3263 /tmp/sample.bin guuid=47edf795-1600-0000-89b8-4ef4b70c0000 pid=3255->guuid=8ff4ca98-1600-0000-89b8-4ef4bf0c0000 pid=3263 execve guuid=473a3899-1600-0000-89b8-4ef4c00c0000 pid=3264 /usr/bin/systemctl guuid=8ff4ca98-1600-0000-89b8-4ef4bf0c0000 pid=3263->guuid=473a3899-1600-0000-89b8-4ef4c00c0000 pid=3264 execve guuid=c168b09b-1600-0000-89b8-4ef4c80c0000 pid=3272 /usr/bin/bash guuid=8ff4ca98-1600-0000-89b8-4ef4bf0c0000 pid=3263->guuid=c168b09b-1600-0000-89b8-4ef4c80c0000 pid=3272 clone guuid=a48958a3-1600-0000-89b8-4ef4de0c0000 pid=3294 /usr/bin/bash guuid=8ff4ca98-1600-0000-89b8-4ef4bf0c0000 pid=3263->guuid=a48958a3-1600-0000-89b8-4ef4de0c0000 pid=3294 clone guuid=6eaee5a3-1600-0000-89b8-4ef4e50c0000 pid=3301 /usr/bin/id guuid=8ff4ca98-1600-0000-89b8-4ef4bf0c0000 pid=3263->guuid=6eaee5a3-1600-0000-89b8-4ef4e50c0000 pid=3301 execve guuid=953274a4-1600-0000-89b8-4ef4e70c0000 pid=3303 /usr/bin/mkdir guuid=8ff4ca98-1600-0000-89b8-4ef4bf0c0000 pid=3263->guuid=953274a4-1600-0000-89b8-4ef4e70c0000 pid=3303 execve guuid=db50d6a4-1600-0000-89b8-4ef4ea0c0000 pid=3306 /usr/bin/wget dns net send-data write-file guuid=8ff4ca98-1600-0000-89b8-4ef4bf0c0000 pid=3263->guuid=db50d6a4-1600-0000-89b8-4ef4ea0c0000 pid=3306 execve guuid=6aacf3ea-1600-0000-89b8-4ef4900d0000 pid=3472 /usr/bin/mv guuid=8ff4ca98-1600-0000-89b8-4ef4bf0c0000 pid=3263->guuid=6aacf3ea-1600-0000-89b8-4ef4900d0000 pid=3472 execve guuid=2eb54ceb-1600-0000-89b8-4ef4930d0000 pid=3475 /usr/bin/rm guuid=8ff4ca98-1600-0000-89b8-4ef4bf0c0000 pid=3263->guuid=2eb54ceb-1600-0000-89b8-4ef4930d0000 pid=3475 execve guuid=eadf85eb-1600-0000-89b8-4ef4940d0000 pid=3476 /usr/bin/chmod guuid=8ff4ca98-1600-0000-89b8-4ef4bf0c0000 pid=3263->guuid=eadf85eb-1600-0000-89b8-4ef4940d0000 pid=3476 execve guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478 /usr/lib/dev/systemdev/systemd-mont mprotect-exec net send-data guuid=8ff4ca98-1600-0000-89b8-4ef4bf0c0000 pid=3263->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478 execve guuid=aa97d2eb-1600-0000-89b8-4ef4980d0000 pid=3480 /usr/bin/sleep guuid=8ff4ca98-1600-0000-89b8-4ef4bf0c0000 pid=3263->guuid=aa97d2eb-1600-0000-89b8-4ef4980d0000 pid=3480 execve guuid=155b110a-1700-0000-89b8-4ef4000e0000 pid=3584 /usr/bin/ps guuid=8ff4ca98-1600-0000-89b8-4ef4bf0c0000 pid=3263->guuid=155b110a-1700-0000-89b8-4ef4000e0000 pid=3584 execve guuid=91f9fb0f-1700-0000-89b8-4ef4120e0000 pid=3602 /usr/bin/sleep guuid=8ff4ca98-1600-0000-89b8-4ef4bf0c0000 pid=3263->guuid=91f9fb0f-1700-0000-89b8-4ef4120e0000 pid=3602 execve guuid=f63bf91c-1800-0000-89b8-4ef45c110000 pid=4444 /usr/bin/ps guuid=8ff4ca98-1600-0000-89b8-4ef4bf0c0000 pid=3263->guuid=f63bf91c-1800-0000-89b8-4ef45c110000 pid=4444 execve guuid=a6ecf821-1800-0000-89b8-4ef46d110000 pid=4461 /usr/bin/rm guuid=8ff4ca98-1600-0000-89b8-4ef4bf0c0000 pid=3263->guuid=a6ecf821-1800-0000-89b8-4ef46d110000 pid=4461 execve guuid=8fcc4b22-1800-0000-89b8-4ef46f110000 pid=4463 /usr/bin/rm guuid=8ff4ca98-1600-0000-89b8-4ef4bf0c0000 pid=3263->guuid=8fcc4b22-1800-0000-89b8-4ef46f110000 pid=4463 execve guuid=dc3dbf9b-1600-0000-89b8-4ef4c90c0000 pid=3273 /usr/bin/wget dns net send-data guuid=c168b09b-1600-0000-89b8-4ef4c80c0000 pid=3272->guuid=dc3dbf9b-1600-0000-89b8-4ef4c90c0000 pid=3273 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=dc3dbf9b-1600-0000-89b8-4ef4c90c0000 pid=3273->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B 0690ccd5-4816-5f11-94dc-7c585f38cdea ipv4.icanhazip.com:0 guuid=dc3dbf9b-1600-0000-89b8-4ef4c90c0000 pid=3273->0690ccd5-4816-5f11-94dc-7c585f38cdea con d0ecfe49-aa79-583f-85c6-85ac97075256 ipv4.icanhazip.com:80 guuid=dc3dbf9b-1600-0000-89b8-4ef4c90c0000 pid=3273->d0ecfe49-aa79-583f-85c6-85ac97075256 send: 133B guuid=8a8968a3-1600-0000-89b8-4ef4e00c0000 pid=3296 /usr/bin/bash guuid=a48958a3-1600-0000-89b8-4ef4de0c0000 pid=3294->guuid=8a8968a3-1600-0000-89b8-4ef4e00c0000 pid=3296 clone guuid=fe6e70a3-1600-0000-89b8-4ef4e10c0000 pid=3297 /usr/bin/sed guuid=a48958a3-1600-0000-89b8-4ef4de0c0000 pid=3294->guuid=fe6e70a3-1600-0000-89b8-4ef4e10c0000 pid=3297 execve guuid=7b5c76a3-1600-0000-89b8-4ef4e20c0000 pid=3298 /usr/bin/cut guuid=a48958a3-1600-0000-89b8-4ef4de0c0000 pid=3294->guuid=7b5c76a3-1600-0000-89b8-4ef4e20c0000 pid=3298 execve guuid=db50d6a4-1600-0000-89b8-4ef4ea0c0000 pid=3306->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B b4e27614-81b3-59ca-8787-716d0d292a6d cdn.tempfile.pro:0 guuid=db50d6a4-1600-0000-89b8-4ef4ea0c0000 pid=3306->b4e27614-81b3-59ca-8787-716d0d292a6d con e0beffae-5a5b-5021-9f66-3b7bd68d1c4e cdn.tempfile.pro:443 guuid=db50d6a4-1600-0000-89b8-4ef4ea0c0000 pid=3306->e0beffae-5a5b-5021-9f66-3b7bd68d1c4e send: 777B 27958174-7cd5-58aa-a656-dcfbbd6ab520 51.178.73.238:9118 guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->27958174-7cd5-58aa-a656-dcfbbd6ab520 send: 561B guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3493 /usr/lib/dev/systemdev/systemd-mont write-file zombie guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3493 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3494 /usr/lib/dev/systemdev/systemd-mont send-data guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3494 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3495 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3495 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3496 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3496 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3497 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3497 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3501 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3501 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3502 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3502 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3503 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3503 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3504 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3504 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3516 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3516 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3517 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3517 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3518 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3518 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3519 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3519 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3541 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3541 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3542 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3542 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3543 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3543 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3544 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3544 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3556 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3556 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3557 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3557 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3558 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3558 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3559 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3559 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3587 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3587 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3588 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3588 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3589 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3589 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3590 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3590 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3606 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3606 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3607 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3607 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3608 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3608 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3609 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3609 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3611 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3611 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3612 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3612 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3613 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3613 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3614 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3614 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3632 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3632 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3633 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3633 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3634 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3634 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3635 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3635 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3649 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3649 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3650 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3650 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3651 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3651 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3652 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3652 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3661 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3661 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3663 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3663 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3664 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3664 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3665 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3665 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3691 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3691 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3692 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3692 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3693 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3693 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3694 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3694 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3722 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3722 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3723 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3723 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3724 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3724 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3725 /usr/lib/dev/systemdev/systemd-mont guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3478->guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3725 clone guuid=98f2c2eb-1600-0000-89b8-4ef4960d0000 pid=3494->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 80B
Verdict:
Malicious
Threat:
HEUR:Downloader.Shell.Miner
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2025-08-03 17:49:25 UTC
File Type:
Text (Shell)
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
xmrig_linux
Score:
  10/10
Tags:
family:xmrig family:xmrig_linux antivm defense_evasion discovery linux miner upx
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads CPU attributes
UPX packed file
Checks hardware identifiers (DMI)
Enumerates running processes
Reads hardware information
File and Directory Permissions Modification
Executes dropped EXE
XMRig Miner payload
Xmrig family
Xmrig_linux family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_SH_CryptoMiner_Indicators_Dec20_1
Author:Florian Roth (Nextron Systems)
Description:Detects helper script used in a crypto miner campaign
Reference:https://www.intezer.com/blog/research/new-golang-worm-drops-xmrig-miner-on-servers/
Rule name:SUSP_LNX_SH_CryptoMiner_Indicators_Dec20_1_RID364E
Author:Florian Roth
Description:Detects helper script used in a crypto miner campaign
Reference:https://www.intezer.com/blog/research/new-golang-worm-drops-xmrig-miner-on-servers/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Distributed via web download

Comments