MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6fe80a873fe3ee85a4885cbfec0fa7aad267432bcf867fe5e842e3fc8980093b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 6fe80a873fe3ee85a4885cbfec0fa7aad267432bcf867fe5e842e3fc8980093b
SHA3-384 hash: c627b225b55d0c211881de222d15d32293e3f258a7bb5ee7c5aa2393303634171def903f0d0788d5edc8f2caa290de58
SHA1 hash: bd86885318c2ae958bc9995e8a3faee909d6b645
MD5 hash: 3a6cca8516fbca5a2e979b8948880da4
humanhash: rugby-carolina-autumn-missouri
File name:bolts
Download: download sample
Signature CoinMiner
File size:1'982 bytes
First seen:2026-01-23 19:52:27 UTC
Last seen:2026-01-24 14:21:47 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:o9qMkpnIDd3Eo+h/s54NvIaNHnJl9vYp1MSQ7BVKfWayg2DND7DOcnMjStLkJi5m:o9qMyIB3ETK8VE9cBCsRHEi5m
TLSH T1D6418DBB54E37AA8349A69DEF263822855C0F58C5CE7578C790C6E35B345408F2257EC
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.194.92.35/nuts/poopf1f57eb28380e340acececdea76a5efb3617d597225c13be9a954cb159907be0 CoinMinerCoinMiner elf geofenced ua-wget USA x86

Intelligence


File Origin
# of uploads :
2
# of downloads :
87
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox coinminer
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-23T17:03:00Z UTC
Last seen:
2026-01-24T06:41:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=dc21d4f1-1800-0000-e932-8825cf0a0000 pid=2767 /usr/bin/sudo guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771 /tmp/sample.bin guuid=dc21d4f1-1800-0000-e932-8825cf0a0000 pid=2767->guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771 execve guuid=70f778f4-1800-0000-e932-8825d50a0000 pid=2773 /usr/bin/pgrep guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=70f778f4-1800-0000-e932-8825d50a0000 pid=2773 execve guuid=6892caf7-1800-0000-e932-8825de0a0000 pid=2782 /usr/bin/rm guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=6892caf7-1800-0000-e932-8825de0a0000 pid=2782 execve guuid=ae5f0bf8-1800-0000-e932-8825e00a0000 pid=2784 /usr/bin/pgrep guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=ae5f0bf8-1800-0000-e932-8825e00a0000 pid=2784 execve guuid=877a63fc-1800-0000-e932-8825ee0a0000 pid=2798 /usr/bin/pgrep guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=877a63fc-1800-0000-e932-8825ee0a0000 pid=2798 execve guuid=dced5400-1900-0000-e932-8825f10a0000 pid=2801 /usr/bin/pgrep guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=dced5400-1900-0000-e932-8825f10a0000 pid=2801 execve guuid=e4c54404-1900-0000-e932-8825fa0a0000 pid=2810 /usr/bin/pgrep guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=e4c54404-1900-0000-e932-8825fa0a0000 pid=2810 execve guuid=6dd4c006-1900-0000-e932-8825020b0000 pid=2818 /usr/bin/rm guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=6dd4c006-1900-0000-e932-8825020b0000 pid=2818 execve guuid=a99d1107-1900-0000-e932-8825030b0000 pid=2819 /usr/bin/pgrep guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=a99d1107-1900-0000-e932-8825030b0000 pid=2819 execve guuid=bb26150a-1900-0000-e932-88250a0b0000 pid=2826 /usr/bin/pgrep guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=bb26150a-1900-0000-e932-88250a0b0000 pid=2826 execve guuid=2c65870c-1900-0000-e932-8825120b0000 pid=2834 /usr/bin/rm guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=2c65870c-1900-0000-e932-8825120b0000 pid=2834 execve guuid=2493ce0c-1900-0000-e932-8825130b0000 pid=2835 /usr/bin/rm guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=2493ce0c-1900-0000-e932-8825130b0000 pid=2835 execve guuid=5633090d-1900-0000-e932-8825150b0000 pid=2837 /usr/bin/rm guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=5633090d-1900-0000-e932-8825150b0000 pid=2837 execve guuid=ebb6610d-1900-0000-e932-8825170b0000 pid=2839 /usr/bin/pgrep guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=ebb6610d-1900-0000-e932-8825170b0000 pid=2839 execve guuid=d3aa2511-1900-0000-e932-8825220b0000 pid=2850 /usr/bin/pgrep guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=d3aa2511-1900-0000-e932-8825220b0000 pid=2850 execve guuid=ef16f013-1900-0000-e932-8825290b0000 pid=2857 /usr/bin/rm guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=ef16f013-1900-0000-e932-8825290b0000 pid=2857 execve guuid=54f14b14-1900-0000-e932-88252c0b0000 pid=2860 /usr/bin/pgrep guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=54f14b14-1900-0000-e932-88252c0b0000 pid=2860 execve guuid=94539717-1900-0000-e932-8825340b0000 pid=2868 /usr/bin/rm guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=94539717-1900-0000-e932-8825340b0000 pid=2868 execve guuid=25c00018-1900-0000-e932-8825360b0000 pid=2870 /usr/bin/pgrep guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=25c00018-1900-0000-e932-8825360b0000 pid=2870 execve guuid=6bdf6d1b-1900-0000-e932-8825420b0000 pid=2882 /usr/bin/rm guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=6bdf6d1b-1900-0000-e932-8825420b0000 pid=2882 execve guuid=c950af1b-1900-0000-e932-8825430b0000 pid=2883 /usr/bin/rm guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=c950af1b-1900-0000-e932-8825430b0000 pid=2883 execve guuid=9b76ed1b-1900-0000-e932-8825450b0000 pid=2885 /usr/bin/pgrep guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=9b76ed1b-1900-0000-e932-8825450b0000 pid=2885 execve guuid=94de3a1e-1900-0000-e932-88254a0b0000 pid=2890 /usr/bin/pgrep guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=94de3a1e-1900-0000-e932-88254a0b0000 pid=2890 execve guuid=b5fb3423-1900-0000-e932-88255b0b0000 pid=2907 /usr/bin/pgrep guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=b5fb3423-1900-0000-e932-88255b0b0000 pid=2907 execve guuid=ffe56f25-1900-0000-e932-8825620b0000 pid=2914 /usr/bin/pgrep guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=ffe56f25-1900-0000-e932-8825620b0000 pid=2914 execve guuid=79dcd927-1900-0000-e932-88256b0b0000 pid=2923 /usr/bin/rm guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=79dcd927-1900-0000-e932-88256b0b0000 pid=2923 execve guuid=8f882828-1900-0000-e932-88256d0b0000 pid=2925 /usr/bin/rm guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=8f882828-1900-0000-e932-88256d0b0000 pid=2925 execve guuid=20336328-1900-0000-e932-88256e0b0000 pid=2926 /usr/bin/rm guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=20336328-1900-0000-e932-88256e0b0000 pid=2926 execve guuid=358aa228-1900-0000-e932-8825700b0000 pid=2928 /usr/bin/rm guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=358aa228-1900-0000-e932-8825700b0000 pid=2928 execve guuid=0c61dc28-1900-0000-e932-8825710b0000 pid=2929 /usr/bin/rm guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=0c61dc28-1900-0000-e932-8825710b0000 pid=2929 execve guuid=9e651929-1900-0000-e932-8825730b0000 pid=2931 /usr/bin/pgrep guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=9e651929-1900-0000-e932-8825730b0000 pid=2931 execve guuid=ecadfe2b-1900-0000-e932-88257a0b0000 pid=2938 /usr/bin/pgrep guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=ecadfe2b-1900-0000-e932-88257a0b0000 pid=2938 execve guuid=5c9ab82f-1900-0000-e932-8825850b0000 pid=2949 /usr/bin/pgrep guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=5c9ab82f-1900-0000-e932-8825850b0000 pid=2949 execve guuid=9fb0e732-1900-0000-e932-8825860b0000 pid=2950 /usr/bin/rm guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=9fb0e732-1900-0000-e932-8825860b0000 pid=2950 execve guuid=60d35533-1900-0000-e932-8825870b0000 pid=2951 /usr/bin/rm guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=60d35533-1900-0000-e932-8825870b0000 pid=2951 execve guuid=ac74a033-1900-0000-e932-8825890b0000 pid=2953 /usr/bin/rm delete-file guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=ac74a033-1900-0000-e932-8825890b0000 pid=2953 execve guuid=5423f233-1900-0000-e932-88258a0b0000 pid=2954 /usr/bin/pgrep guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=5423f233-1900-0000-e932-88258a0b0000 pid=2954 execve guuid=3fb04d37-1900-0000-e932-8825910b0000 pid=2961 /usr/bin/pgrep guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=3fb04d37-1900-0000-e932-8825910b0000 pid=2961 execve guuid=136d7c3b-1900-0000-e932-8825990b0000 pid=2969 /usr/bin/rm guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=136d7c3b-1900-0000-e932-8825990b0000 pid=2969 execve guuid=aeb1b23b-1900-0000-e932-88259a0b0000 pid=2970 /usr/bin/pgrep guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=aeb1b23b-1900-0000-e932-88259a0b0000 pid=2970 execve guuid=28b62e3e-1900-0000-e932-88259f0b0000 pid=2975 /usr/bin/pgrep guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=28b62e3e-1900-0000-e932-88259f0b0000 pid=2975 execve guuid=02c8ff40-1900-0000-e932-8825a40b0000 pid=2980 /usr/bin/rm guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=02c8ff40-1900-0000-e932-8825a40b0000 pid=2980 execve guuid=6dc55341-1900-0000-e932-8825a50b0000 pid=2981 /usr/bin/pgrep guuid=607e03f4-1800-0000-e932-8825d30a0000 pid=2771->guuid=6dc55341-1900-0000-e932-8825a50b0000 pid=2981 execve
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CoinMiner

sh 6fe80a873fe3ee85a4885cbfec0fa7aad267432bcf867fe5e842e3fc8980093b

(this sample)

  
Delivery method
Distributed via web download

Comments