MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4720ee78506641aeaf6f5dc471d121014c9db72007acff2712ee1a9d31dade3a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 4720ee78506641aeaf6f5dc471d121014c9db72007acff2712ee1a9d31dade3a
SHA3-384 hash: 610d4d87531745fd8cd3cfc0f5eebec03950a409c63486d7496d21edf4fa2dc315af17f9461bdcdc9620bb3c4a96f9c4
SHA1 hash: 2dec9752d8c9ac61f391ab6ca66a230e122ee89a
MD5 hash: c865bffaa7c67cc1ed404af4baf26e8c
humanhash: cola-tango-double-lactose
File name:vtubers.sh
Download: download sample
Signature CoinMiner
File size:1'149 bytes
First seen:2025-12-01 20:35:22 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:CRxXaJNIpuhsChuIAGF0IpuhsChuXm/xOR:C7Q7hsJbS07hsJmx6
TLSH T123215C0ACA2506B0171844FEAF83461C724A488B05CF869FF52D61F91F7CD85B26B249
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter juroots
Tags:CoinMiner sh vtuber

Intelligence


File Origin
# of uploads :
1
# of downloads :
29
Origin country :
IL IL
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-01T05:14:00Z UTC
Last seen:
2025-12-01T10:04:00Z UTC
Hits:
~100
Threat name:
Script.Browser.Heuristic
Status:
Malicious
First seen:
2025-12-01 09:13:55 UTC
File Type:
Text (Shell)
AV detection:
2 of 36 (5.56%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:xmrig antivm credential_access defense_evasion discovery linux miner upx
Behaviour
GoLang User-Agent
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads CPU attributes
Reads system network configuration
UPX packed file
Checks hardware identifiers (DMI)
Enumerates active TCP sockets
Enumerates running processes
Reads hardware information
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
OS Credential Dumping
Unexpected DNS network traffic destination
XMRig Miner payload
Xmrig family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CoinMiner

sh 4720ee78506641aeaf6f5dc471d121014c9db72007acff2712ee1a9d31dade3a

(this sample)

  
Delivery method
Distributed via web download

Comments