MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 54a4c6f8c7fb5775caba77370549688598ea028b9974ccc19a4cc4052fbb895c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 54a4c6f8c7fb5775caba77370549688598ea028b9974ccc19a4cc4052fbb895c
SHA3-384 hash: d18d67b44e43322c1e53ef1add1e1297214dd97ac94ea61945ac80ab65245ddf4187a0698eeede84b3e84e363600b991
SHA1 hash: 63788feae40cbd17b450c8b54dbcd8f78cb38f38
MD5 hash: f2887cdeceba02c3518357f3f3fb1545
humanhash: spaghetti-monkey-bulldog-green
File name:minern.tgz
Download: download sample
File size:6'541'779 bytes
First seen:2026-07-05 15:29:21 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 196608:NL3fBgR75ute+r2f/t8bwwjA9jzuN1siTaiI:DgR75y1iKMO1siTS
TLSH T1C6663319ED25063CEA7839F725062FD0C7DBBCA6093393691992AF91DFD35B04631EA0
Magika gzip
Reporter BlinkzSec

Intelligence


File Origin
# of uploads :
1
# of downloads :
55
Origin country :
US US
File Archive Information

This file archive contains 29 file(s), sorted by their relevance:

File name:sshd
File size:5'138'368 bytes
SHA256 hash: 3bce8783cd9fd825ce06c8033717d84ffe7049d8a003ab9abc8fe09bb5a654d4
MD5 hash: cb0b9e14e96af0e25e134bf15ac94c40
MIME type:application/x-executable
File name:h64
File size:838'583 bytes
SHA256 hash: 7fe9d6d8b9390020862ca7dc9e69c1e2b676db5898e4bfad51d66250e9af3eaf
MD5 hash: c644c04bce21dacdeb1e6c14c081e359
MIME type:application/x-executable
File name:upd
File size:197 bytes
SHA256 hash: 2e4f0665c8ee636fd4c0cc7e7cbf45bf9f9071142ddc8412d928fc96288d687b
MD5 hash: e2affd51de506f3c996b73f04093eb33
MIME type:text/x-shellscript
File name:run
File size:496 bytes
SHA256 hash: f8b1367baad13d291d0c8b7b4ebeb2a6c64d53858d2f12e4474ee92a9cf0fa7c
MD5 hash: 645c130066fee21dc6334a3a2373fd36
MIME type:text/x-shellscript
File name:libkrb5support.so.0
File size:67'104 bytes
SHA256 hash: f5716915675aecb2407b8e8434ce0dff177cc1b3800112e3e58adc6c60755022
MD5 hash: 1c4e77b2ecd0dcf29419adc6b26bd0f9
MIME type:application/x-sharedlib
File name:librt.so.1
File size:43'776 bytes
SHA256 hash: 1041cef8e2ec46854416f37e040234a4cdbddcd954677a868d83c11733c0f4be
MD5 hash: 942fdb0335e6ef531316f53cf38b633f
MIME type:application/x-sharedlib
File name:libkrb5.so.3
File size:967'784 bytes
SHA256 hash: c4b4275848e17c10292a828178bbfff844d2b0abeee5a931e39c64d49612d573
MD5 hash: e2d8d50e5ee0b5072067cf59fe974c41
MIME type:application/x-sharedlib
File name:libnuma.so.1
File size:46'608 bytes
SHA256 hash: 9e22c8b34a6b740197821829815fc85fcb02a805be7489d184bd4169f7abd799
MD5 hash: 87b202915bccb3ee099589ec76a0b861
MIME type:application/x-sharedlib
File name:libresolv.so.2
File size:105'824 bytes
SHA256 hash: 4dbf06751ba5ed691772545bee3080af2580d6153f4e223ef9901cb97c5446f5
MD5 hash: 2fdfed59a04f11c7f63c2c6c978a2f62
MIME type:application/x-sharedlib
File name:libltdl.so.7
File size:41'272 bytes
SHA256 hash: 35340011d836f040b8bd85727358c55a8adf7c8a10b13720859712498f04038a
MD5 hash: 0df5f4fd2db0616bf913df5ad673dbde
MIME type:application/x-sharedlib
File name:libdl.so.2
File size:19'288 bytes
SHA256 hash: 07a203b67ebcc0802b64cd48f59b1db58d35fa77dd8dffefb58e0c73504f3c70
MD5 hash: 48375ee2b21308a1c685cb542d8607cd
MIME type:application/x-sharedlib
File name:ld-linux-x86-64.so.2
File size:164'240 bytes
SHA256 hash: 9fde35e93ad8096fb21a0e56ff62968b9f9a53c80e5c5904154ce6af1d788e6c
MD5 hash: 41f0c69459cd4a674b499167da121544
MIME type:application/x-sharedlib
File name:libhwloc.so.5
File size:254'392 bytes
SHA256 hash: 8a7ce5b6441fadb5107d1aa4e0a07110664fcaff423b680ba140faff2e921e49
MD5 hash: 59cbe187679164891a9a2f3175ca9781
MIME type:application/x-sharedlib
File name:libk5crypto.so.3
File size:210'784 bytes
SHA256 hash: 99d9cebba553826bfbf147638b75f02522c347b751e9a09074d49478a6f5fed7
MD5 hash: c97a1089aab96b09d6e0baa9d9ac05ec
MIME type:application/x-sharedlib
File name:libm.so.6
File size:1'137'024 bytes
SHA256 hash: 9f48b29122c394356d224c218aff511bf0ff62340b6c49c6c88921d79488d8fd
MD5 hash: 7332a493c02e5d64d5fb61cb6da8222f
MIME type:application/x-sharedlib
File name:libgssapi_krb5.so.2
File size:320'784 bytes
SHA256 hash: 92a3b421554f35bd107263f2617e202d0912db9b721b520b46493bcc2502da42
MD5 hash: 131c57b3f947067a83635d1556eedfa7
MIME type:application/x-sharedlib
File name:a
File size:400 bytes
SHA256 hash: 97237a0edc44ca19d16ddd72cac78e53b4826de1053bba3e01c52ecd04927336
MD5 hash: d3cc517dc87af108774c5698499d0444
MIME type:text/plain
File name:libgcc_s.so.1
File size:88'776 bytes
SHA256 hash: 3ca5b4cf347704ae431053ebb5e1b0bfa92448efe058d5ac58fd385a39b86a0c
MD5 hash: 50ab1ad948f7706f4385ab8033ae0ce8
MIME type:application/x-sharedlib
File name:libkeyutils.so.1
File size:15'688 bytes
SHA256 hash: dfe70bd63f57aa3fc805f88ffb04b9440794faacbf7cffd080fc68984d25f3fb
MD5 hash: b9cb197dc16e99f25498a0643b7bb3e4
MIME type:application/x-sharedlib
File name:libcrypto.so.10
File size:2'521'144 bytes
SHA256 hash: 957ef7816386e03c1b248dd9974829f7be199745a05f4cdae489f1e3d7073d65
MD5 hash: 0115756fd1e4e4eeba6dce47a78d9c99
MIME type:application/x-sharedlib
File name:libpthread.so.0
File size:142'232 bytes
SHA256 hash: b92b1625ae1b82d8b5b26cf066639f46f8c8b092dc1b94454335cecdeb4a64d5
MD5 hash: 57309335ccbfab99827a82ae3cde7c96
MIME type:application/x-sharedlib
File name:libcom_err.so.2
File size:15'920 bytes
SHA256 hash: 20a7370a4b8935aa989df63d5e6e540dbebded1392501d70bd05850eda59a8df
MD5 hash: 44022d3ad04f8fb0fc679df2f0faf883
MIME type:application/x-sharedlib
File name:libssl.so.10
File size:470'376 bytes
SHA256 hash: 84c8c57bba0cfb2c0237879d5dd0c803932ead2916d5d6b1647588ca73610e40
MD5 hash: f9132cbde431c30de32bf4f6c92130fe
MIME type:application/x-sharedlib
File name:bash
File size:211 bytes
SHA256 hash: 30068f74ddd41f4c343ca6b105f63466706f2af1b0c8c2a42e8b8703d0e8975f
MD5 hash: fca6f005f0c818146f5f710a10049f2a
MIME type:text/x-shellscript
File name:libselinux.so.1
File size:155'784 bytes
SHA256 hash: 8db37e25fa2bbddd1be359d29b760537390194c1d18ba9bad6ff0f1383626dfe
MD5 hash: e3706e3e568713cc820612ebf7324374
MIME type:application/x-sharedlib
File name:libpcre.so.1
File size:402'384 bytes
SHA256 hash: 9513aab50d64bb4655550e1ba0c62fbcf6e7cbe0d64cba0814224d2631a85027
MD5 hash: bcbb7c51ebe503462b8bd5830b3217a7
MIME type:application/x-sharedlib
File name:libz.so.1
File size:90'248 bytes
SHA256 hash: d8a329deb19a0fde9819c11c0ccb26c2c1ee8e968e44a973c255c16f83fbf414
MD5 hash: c80358226abb9ea1b5d76bc10844084d
MIME type:application/x-sharedlib
File name:libc.so.6
File size:2'156'160 bytes
SHA256 hash: 739ef315dc7654aa670a4215f0bf2dc2a8b99472ca7d52e34d952864b6f932b6
MD5 hash: 45136f7d86b30c856c1fe6ebe7ca1782
MIME type:application/x-sharedlib
File name:x
File size:24 bytes
SHA256 hash: 6e80a9d843faf27e239b1a767d29c7443972be1ddf5ff5f5f9fc9a2b55a161f5
MD5 hash: a127fa3c580e908390200dd936868e29
MIME type:text/plain
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
gz
First seen:
2026-07-05T12:38:00Z UTC
Last seen:
2026-07-07T02:09:00Z UTC
Hits:
~10
Gathering data
Threat name:
Linux.Coinminer.XMRig
Status:
Malicious
First seen:
2026-05-14 10:00:07 UTC
File Type:
Binary (Archive)
Extracted files:
31
AV detection:
20 of 24 (83.33%)
Threat level:
  4/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:upxHook
Author:@r3dbU7z
Description:Detect artifacts from 'upxHook' - modification of UPX packer
Reference:https://bazaar.abuse.ch/sample/6352be8aa5d8063673aa428c3807228c40505004320232a23d99ebd9ef48478a/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

gz 54a4c6f8c7fb5775caba77370549688598ea028b9974ccc19a4cc4052fbb895c

(this sample)

  
Delivery method
Distributed via web download

Comments