MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4b1ed08fb22619db0cb275baab7ae4c29ec0f99a0769406cc02343212447db3e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 4b1ed08fb22619db0cb275baab7ae4c29ec0f99a0769406cc02343212447db3e
SHA3-384 hash: 4c48fd53b3554736addb918772b0d7fa62fadd5b2f3decbc4e48208f27b4397eaa5b18d1e26f50baa01d33eccfed5ad1
SHA1 hash: ef77c2fb94519f1aae46697989f93cd7c1873f16
MD5 hash: f4e2ff7535140ab51faf8548562cd7ee
humanhash: helium-massachusetts-magazine-april
File name:app2
Download: download sample
Signature CoinMiner
File size:2'968'780 bytes
First seen:2026-02-02 06:29:31 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 49152:CeYLwBBIaFzS1lJydoUi8mmOf8cLqDamlNi+iCeokgxzUCSlunTbXtLECIjSYE:CeYmBiSoUi8mzkcLeDe+iCogqVstICIo
TLSH T17DD53305D55CAC856B73E0208404161532ABD16A2CEF2DF460BDCDAFAD82D07EFA7EC9
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:CoinMiner elf

Intelligence


File Origin
# of uploads :
1
# of downloads :
99
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=6741d19f-1700-0000-4bdd-9fe5360c0000 pid=3126 /usr/bin/sudo guuid=939c67a1-1700-0000-4bdd-9fe53d0c0000 pid=3133 /tmp/sample.bin net write-file guuid=6741d19f-1700-0000-4bdd-9fe5360c0000 pid=3126->guuid=939c67a1-1700-0000-4bdd-9fe53d0c0000 pid=3133 execve 7615029e-1e01-5cd4-9880-d144d7b8df37 127.0.0.1:54648 guuid=939c67a1-1700-0000-4bdd-9fe53d0c0000 pid=3133->7615029e-1e01-5cd4-9880-d144d7b8df37 con guuid=939c67a1-1700-0000-4bdd-9fe53d0c0000 pid=3202 /tmp/sample.bin guuid=939c67a1-1700-0000-4bdd-9fe53d0c0000 pid=3133->guuid=939c67a1-1700-0000-4bdd-9fe53d0c0000 pid=3202 clone guuid=939c67a1-1700-0000-4bdd-9fe53d0c0000 pid=3203 /tmp/sample.bin guuid=939c67a1-1700-0000-4bdd-9fe53d0c0000 pid=3133->guuid=939c67a1-1700-0000-4bdd-9fe53d0c0000 pid=3203 clone guuid=939c67a1-1700-0000-4bdd-9fe53d0c0000 pid=3204 /tmp/sample.bin guuid=939c67a1-1700-0000-4bdd-9fe53d0c0000 pid=3133->guuid=939c67a1-1700-0000-4bdd-9fe53d0c0000 pid=3204 clone guuid=939c67a1-1700-0000-4bdd-9fe53d0c0000 pid=3205 /tmp/sample.bin guuid=939c67a1-1700-0000-4bdd-9fe53d0c0000 pid=3133->guuid=939c67a1-1700-0000-4bdd-9fe53d0c0000 pid=3205 clone guuid=3ad612d4-1700-0000-4bdd-9fe5880c0000 pid=3208 /tmp/sample.bin guuid=939c67a1-1700-0000-4bdd-9fe53d0c0000 pid=3133->guuid=3ad612d4-1700-0000-4bdd-9fe5880c0000 pid=3208 clone guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3209 /tmp/sample.bin delete-file net send-data write-file zombie guuid=939c67a1-1700-0000-4bdd-9fe53d0c0000 pid=3133->guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3209 execve guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3209->7615029e-1e01-5cd4-9880-d144d7b8df37 con 6bd4ccf7-dd02-562b-9cc5-bb33369b8898 127.0.0.1:56718 guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3209->6bd4ccf7-dd02-562b-9cc5-bb33369b8898 con 54d92a3b-1447-55af-b534-047898c60c8d 1.1.1.1:53 guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3209->54d92a3b-1447-55af-b534-047898c60c8d send: 47B fe3e8087-6d6b-5fa7-84ca-48c99af68d41 172.217.20.147:443 guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3209->fe3e8087-6d6b-5fa7-84ca-48c99af68d41 send: 851B guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3292 /tmp/sample.bin zombie guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3209->guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3292 clone guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3293 /tmp/sample.bin net send-data zombie guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3209->guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3293 clone guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3294 /tmp/sample.bin net send-data zombie guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3209->guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3294 clone guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3295 /tmp/sample.bin send-data zombie guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3209->guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3295 clone guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3334 /tmp/sample.bin send-data zombie guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3209->guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3334 clone guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3480 /tmp/sample.bin send-data write-file zombie guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3209->guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3480 clone guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3293->54d92a3b-1447-55af-b534-047898c60c8d con guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3293->fe3e8087-6d6b-5fa7-84ca-48c99af68d41 send: 2160B guuid=d28517a3-1900-0000-4bdd-9fe5ac100000 pid=4268 /tmp/sample.bin guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3293->guuid=d28517a3-1900-0000-4bdd-9fe5ac100000 pid=4268 clone guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4269 /home/755ia474q6p0z delete-file mprotect-exec net guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3293->guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4269 execve guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3294->54d92a3b-1447-55af-b534-047898c60c8d con guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3294->fe3e8087-6d6b-5fa7-84ca-48c99af68d41 send: 18720B 6f5d75c7-da72-5130-9414-1872b188d765 2a00:1450:4001:80b::2013:53 guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3294->6f5d75c7-da72-5130-9414-1872b188d765 con 0c366bb2-ee18-5465-9d0c-4c13ce847f2f 172.217.20.147:53 guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3294->0c366bb2-ee18-5465-9d0c-4c13ce847f2f con guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3295->54d92a3b-1447-55af-b534-047898c60c8d send: 47B guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3295->fe3e8087-6d6b-5fa7-84ca-48c99af68d41 send: 16398B guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3334->fe3e8087-6d6b-5fa7-84ca-48c99af68d41 send: 30000B guuid=03ce19d4-1700-0000-4bdd-9fe5890c0000 pid=3480->fe3e8087-6d6b-5fa7-84ca-48c99af68d41 send: 816B c7432d84-2f41-58ca-a276-b594c8075cd1 127.0.0.1:29974 guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4269->c7432d84-2f41-58ca-a276-b594c8075cd1 con guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4500 /home/755ia474q6p0z guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4269->guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4500 clone guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4501 /home/755ia474q6p0z dns net send-data write-file guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4269->guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4501 clone guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4502 /home/755ia474q6p0z guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4269->guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4502 clone guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4503 /home/755ia474q6p0z net send-data guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4269->guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4503 clone guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4504 /home/755ia474q6p0z guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4269->guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4504 clone guuid=821149f6-1900-0000-4bdd-9fe59f110000 pid=4511 /home/755ia474q6p0z guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4269->guuid=821149f6-1900-0000-4bdd-9fe59f110000 pid=4511 clone guuid=fc2154f6-1900-0000-4bdd-9fe5a0110000 pid=4512 /home/755ia474q6p0z guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4269->guuid=fc2154f6-1900-0000-4bdd-9fe5a0110000 pid=4512 clone guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4523 /home/755ia474q6p0z net send-data write-file guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4269->guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4523 clone guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4808 /home/755ia474q6p0z net guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4269->guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4808 clone guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=5252 /home/755ia474q6p0z dns net send-data write-file guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4269->guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=5252 clone guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=5299 /home/755ia474q6p0z guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4269->guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=5299 clone guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=5300 /home/755ia474q6p0z guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4269->guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=5300 clone guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=5301 /home/755ia474q6p0z guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4269->guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=5301 clone guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=5302 /home/755ia474q6p0z guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4269->guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=5302 clone guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=5303 /home/755ia474q6p0z guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4269->guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=5303 clone guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=5304 /home/755ia474q6p0z guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4269->guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=5304 clone guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=5305 /home/755ia474q6p0z guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4269->guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=5305 clone guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4501->54d92a3b-1447-55af-b534-047898c60c8d send: 47B guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4501->fe3e8087-6d6b-5fa7-84ca-48c99af68d41 send: 184B 7e0008c6-7408-5d99-b919-51aed6fa692e 127.0.0.1:34803 guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4501->7e0008c6-7408-5d99-b919-51aed6fa692e con 1d9baf6b-9e16-5749-b892-c2cc9844f85f monerooceans.stream:53 guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4501->1d9baf6b-9e16-5749-b892-c2cc9844f85f con 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4501->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 44B guuid=a6ce5ae6-1c00-0000-4bdd-9fe585140000 pid=5253 /root/DGjlVCqg net write-file guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4502->guuid=a6ce5ae6-1c00-0000-4bdd-9fe585140000 pid=5253 execve guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4503->54d92a3b-1447-55af-b534-047898c60c8d send: 47B guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4503->fe3e8087-6d6b-5fa7-84ca-48c99af68d41 send: 1478B guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4503->7e0008c6-7408-5d99-b919-51aed6fa692e con f70ea765-21ba-527b-a62a-05ec6229126f 172.217.16.211:53 guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4503->f70ea765-21ba-527b-a62a-05ec6229126f con 48072a68-314f-5998-888a-f9681b5132f3 2a00:1450:4001:811::2013:53 guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4503->48072a68-314f-5998-888a-f9681b5132f3 con 559e3d39-a7c5-5ef4-b7b9-652b77baaeac 172.217.16.211:443 guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4503->559e3d39-a7c5-5ef4-b7b9-652b77baaeac con guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4523->54d92a3b-1447-55af-b534-047898c60c8d send: 47B guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4523->7e0008c6-7408-5d99-b919-51aed6fa692e con guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4523->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 96B guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4523->559e3d39-a7c5-5ef4-b7b9-652b77baaeac send: 184B guuid=2839cb47-1f00-0000-4bdd-9fe5aa140000 pid=5290 /usr/bin/bash guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4523->guuid=2839cb47-1f00-0000-4bdd-9fe5aa140000 pid=5290 execve guuid=e91f4948-1f00-0000-4bdd-9fe5ab140000 pid=5291 /usr/bin/dash guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4523->guuid=e91f4948-1f00-0000-4bdd-9fe5ab140000 pid=5291 execve guuid=8f779248-1f00-0000-4bdd-9fe5ac140000 pid=5292 /usr/bin/bash guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4523->guuid=8f779248-1f00-0000-4bdd-9fe5ac140000 pid=5292 execve guuid=e02c4549-1f00-0000-4bdd-9fe5b0140000 pid=5296 /usr/bin/dash guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4523->guuid=e02c4549-1f00-0000-4bdd-9fe5b0140000 pid=5296 execve guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4808->54d92a3b-1447-55af-b534-047898c60c8d con guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4808->fe3e8087-6d6b-5fa7-84ca-48c99af68d41 con guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4808->0c366bb2-ee18-5465-9d0c-4c13ce847f2f con cd60e4d1-6d4e-5144-ac80-59dbc86b0f38 2a00:1450:4001:805::2013:53 guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=4808->cd60e4d1-6d4e-5144-ac80-59dbc86b0f38 con guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=5252->54d92a3b-1447-55af-b534-047898c60c8d send: 47B guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=5252->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 52B guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=5252->559e3d39-a7c5-5ef4-b7b9-652b77baaeac send: 1478B 4a2db357-40d0-595c-af9f-2cf14ae2a89a auto.c3pool.org:53 guuid=03ef29a3-1900-0000-4bdd-9fe5ad100000 pid=5252->4a2db357-40d0-595c-af9f-2cf14ae2a89a con guuid=a6ce5ae6-1c00-0000-4bdd-9fe585140000 pid=5253->c7432d84-2f41-58ca-a276-b594c8075cd1 con guuid=a6ce5ae6-1c00-0000-4bdd-9fe585140000 pid=5253->7e0008c6-7408-5d99-b919-51aed6fa692e con guuid=a6ce5ae6-1c00-0000-4bdd-9fe585140000 pid=5254 /root/DGjlVCqg guuid=a6ce5ae6-1c00-0000-4bdd-9fe585140000 pid=5253->guuid=a6ce5ae6-1c00-0000-4bdd-9fe585140000 pid=5254 clone guuid=a6ce5ae6-1c00-0000-4bdd-9fe585140000 pid=5255 /root/DGjlVCqg guuid=a6ce5ae6-1c00-0000-4bdd-9fe585140000 pid=5253->guuid=a6ce5ae6-1c00-0000-4bdd-9fe585140000 pid=5255 clone guuid=a6ce5ae6-1c00-0000-4bdd-9fe585140000 pid=5256 /root/DGjlVCqg guuid=a6ce5ae6-1c00-0000-4bdd-9fe585140000 pid=5253->guuid=a6ce5ae6-1c00-0000-4bdd-9fe585140000 pid=5256 clone guuid=a6ce5ae6-1c00-0000-4bdd-9fe585140000 pid=5257 /root/DGjlVCqg net guuid=a6ce5ae6-1c00-0000-4bdd-9fe585140000 pid=5253->guuid=a6ce5ae6-1c00-0000-4bdd-9fe585140000 pid=5257 clone guuid=a6ce5ae6-1c00-0000-4bdd-9fe585140000 pid=5257->c7432d84-2f41-58ca-a276-b594c8075cd1 con guuid=2ffaf048-1f00-0000-4bdd-9fe5ad140000 pid=5293 /usr/bin/bash guuid=8f779248-1f00-0000-4bdd-9fe5ac140000 pid=5292->guuid=2ffaf048-1f00-0000-4bdd-9fe5ad140000 pid=5293 clone guuid=78b0fb48-1f00-0000-4bdd-9fe5ae140000 pid=5294 /usr/bin/bash guuid=8f779248-1f00-0000-4bdd-9fe5ac140000 pid=5292->guuid=78b0fb48-1f00-0000-4bdd-9fe5ae140000 pid=5294 clone guuid=5f030649-1f00-0000-4bdd-9fe5af140000 pid=5295 /usr/bin/bash guuid=2ffaf048-1f00-0000-4bdd-9fe5ad140000 pid=5293->guuid=5f030649-1f00-0000-4bdd-9fe5af140000 pid=5295 clone guuid=1227a049-1f00-0000-4bdd-9fe5b1140000 pid=5297 /usr/bin/dash guuid=e02c4549-1f00-0000-4bdd-9fe5b0140000 pid=5296->guuid=1227a049-1f00-0000-4bdd-9fe5b1140000 pid=5297 clone guuid=5205a949-1f00-0000-4bdd-9fe5b2140000 pid=5298 /usr/bin/dash guuid=e02c4549-1f00-0000-4bdd-9fe5b0140000 pid=5296->guuid=5205a949-1f00-0000-4bdd-9fe5b2140000 pid=5298 clone
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
60 / 100
Signature
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample deletes itself
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1861418 Sample: app2.elf Startdate: 02/02/2026 Architecture: LINUX Score: 60 33 www.fastsoco.top 2->33 35 109.202.202.202, 80 INIT7CH Switzerland 2->35 37 3 other IPs or domains 2->37 39 Malicious sample detected (through community Yara rule) 2->39 41 Multi AV Scanner detection for submitted file 2->41 9 dash rm app2.elf 2->9         started        11 dash rm 2->11         started        13 dash cat 2->13         started        15 7 other processes 2->15 signatures3 process4 process5 17 app2.elf app2.elf 9->17         started        20 app2.elf 9->20         started        file6 31 /opt/3ufqa76b6wsp9, ELF 17->31 dropped 22 app2.elf 3ufqa76b6wsp9 17->22         started        25 app2.elf 17->25         started        process7 signatures8 43 Sample deletes itself 22->43 27 3ufqa76b6wsp9 22->27         started        29 3ufqa76b6wsp9 22->29         started        process9
Threat name:
Linux.Trojan.Multiverze
Status:
Malicious
First seen:
2026-02-02 06:30:59 UTC
File Type:
ELF64 Little (Exe)
AV detection:
7 of 36 (19.44%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:xmrig antivm defense_evasion discovery execution linux miner persistence privilege_escalation upx
Behaviour
Command and Scripting Interpreter: Unix Shell
Enumerates kernel/hardware configuration
Reads runtime system information
Checks CPU configuration
Reads CPU attributes
Modifies Bash startup script
UPX packed file
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Creates/modifies environment variables
Enumerates running processes
Reads hardware information
Reads list of loaded kernel modules
Deletes itself
Executes dropped EXE
XMRig Miner payload
Xmrig family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CoinMiner

elf 4b1ed08fb22619db0cb275baab7ae4c29ec0f99a0769406cc02343212447db3e

(this sample)

  
Delivery method
Distributed via web download

Comments