MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 4f17d2f0c21f583c788514f8f6f32b011e62bc26cddb67eabef0ceb4c8e08adc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
CoinMiner
Vendor detections: 3
| SHA256 hash: | 4f17d2f0c21f583c788514f8f6f32b011e62bc26cddb67eabef0ceb4c8e08adc |
|---|---|
| SHA3-384 hash: | 70829bedc763b4a2916a17225edaf21a57bbcf6599a0a55b569dbb40df0da17065a8f547ad4f9cb3177d13c272eea80d |
| SHA1 hash: | 6b7e70b97024ab3fe24bd7fbaf2ffb26a364c348 |
| MD5 hash: | 546f1d6b9d4dc321cf68b79b066171aa |
| humanhash: | seventeen-emma-louisiana-florida |
| File name: | setup_c3pool_miner.sh |
| Download: | download sample |
| Signature | CoinMiner |
| File size: | 12'745 bytes |
| First seen: | 2025-06-11 04:23:13 UTC |
| Last seen: | 2025-07-15 11:13:25 UTC |
| File type: | sh |
| MIME type: | text/x-shellscript |
| ssdeep | 384:GqEHeA0MpI05MtJyjiKH6DUqBuRyRG+o1SS48WG0l1XDs/G:Gq4J0My9EiKH6DRuRyRG+oQ1nGy17 |
| TLSH | T1A842A5B1B95233F1603C80707DDA9148B39C655F16AA3CBDF4AAA5B4301C3D91DFE16A |
| Magika | shell |
| Reporter | |
| Tags: | CoinMiner sh |
Shell script dropper
This file seems to be a shell script dropper, using wget, ftpget and/or curl. More information about the corresponding payload URLs are shown below.
| URL | Malware sample (SHA256 hash) | Signature | Tags |
|---|---|---|---|
| http://14.103.234.180/xmrig.tar.gz | n/a | n/a | CoinMiner gz |
| https://github.com/xmrig/xmrig/releases/latest | n/a | n/a | n/a |
Intelligence
File Origin
# of uploads :
2
# of downloads :
69
Origin country :
DEVendor Threat Intelligence
Detection(s):
Verdict:
Clean
Score:
99.9%
Link:
Tags:
n/a
Score:
0%
Verdict:
Benign
File Type:
SCRIPT
Threat name:
Linux.Coinminer.XMRig
Status:
Malicious
First seen:
2025-06-11 04:25:02 UTC
File Type:
Text (Shell)
AV detection:
21 of 38 (55.26%)
Threat level:
4/5
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
3/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
7072c8ec2f9087b22beca1d6b27da7b678f6d22781491f7865ea8f5b86928c2b
Delivery method
Distributed via web download
Dropping
MD5 1ea1691220acb93328f95cae436926ad
Dropping
SHA256 7072c8ec2f9087b22beca1d6b27da7b678f6d22781491f7865ea8f5b86928c2b
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.