MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4f17d2f0c21f583c788514f8f6f32b011e62bc26cddb67eabef0ceb4c8e08adc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4f17d2f0c21f583c788514f8f6f32b011e62bc26cddb67eabef0ceb4c8e08adc
SHA3-384 hash: 70829bedc763b4a2916a17225edaf21a57bbcf6599a0a55b569dbb40df0da17065a8f547ad4f9cb3177d13c272eea80d
SHA1 hash: 6b7e70b97024ab3fe24bd7fbaf2ffb26a364c348
MD5 hash: 546f1d6b9d4dc321cf68b79b066171aa
humanhash: seventeen-emma-louisiana-florida
File name:setup_c3pool_miner.sh
Download: download sample
Signature CoinMiner
File size:12'745 bytes
First seen:2025-06-11 04:23:13 UTC
Last seen:2025-07-15 11:13:25 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 384:GqEHeA0MpI05MtJyjiKH6DUqBuRyRG+o1SS48WG0l1XDs/G:Gq4J0My9EiKH6DRuRyRG+oQ1nGy17
TLSH T1A842A5B1B95233F1603C80707DDA9148B39C655F16AA3CBDF4AAA5B4301C3D91DFE16A
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
http://14.103.234.180/xmrig.tar.gzn/an/aCoinMiner gz
https://github.com/xmrig/xmrig/releases/latestn/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
69
Origin country :
DE DE
Vendor Threat Intelligence
Threat name:
Linux.Coinminer.XMRig
Status:
Malicious
First seen:
2025-06-11 04:25:02 UTC
File Type:
Text (Shell)
AV detection:
21 of 38 (55.26%)
Threat level:
  4/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CoinMiner

sh 4f17d2f0c21f583c788514f8f6f32b011e62bc26cddb67eabef0ceb4c8e08adc

(this sample)

7072c8ec2f9087b22beca1d6b27da7b678f6d22781491f7865ea8f5b86928c2b

  
Delivery method
Distributed via web download
  
Dropping
MD5 1ea1691220acb93328f95cae436926ad
  
Dropping
SHA256 7072c8ec2f9087b22beca1d6b27da7b678f6d22781491f7865ea8f5b86928c2b

Comments