MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7459a2c14c1ca4e00c4e170071d7005a78a2b76ca30f8b57d064b158d3890c8a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 4


Intelligence 4 IOCs YARA 2 File information Comments

SHA256 hash: 7459a2c14c1ca4e00c4e170071d7005a78a2b76ca30f8b57d064b158d3890c8a
SHA3-384 hash: 3ef0303131075b0757a11c8b2fad32a93d5a2f9f84e01565e4a83665a9bccb496de1902112a86a50aff3d6928234694a
SHA1 hash: a682b9ac14359893eb2b1ebf194948b1d19bb5dd
MD5 hash: 7206bde4a01b19a8c1d52057b9bce183
humanhash: harry-oven-kilo-maine
File name:run.sh
Download: download sample
Signature CoinMiner
File size:6'368 bytes
First seen:2025-07-16 02:32:57 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 192:2I848jzDN1eEXOKD5grqaGayH+4MeYHPMNZlu:yvnS9c9SPyu
TLSH T1B6D18305FBC095B415D9C168094A1980694B91173E092C28FCEDB6A9FF28B6C32FDBE7
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.248.53.119:8000/mon.sh1e891ab1521b27923233e694f60fdbf0e1b840e657d8b1ffdefd8b5ef5e38964 CoinMinerCoinMiner
http://162.248.53.119:8000/yes.tar.gzn/an/aopendir
https://github.com/xmrig/xmrig/releases/download/v6.24.0/xmrig-6.24.0-linux-static-x64.tar.gzn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
34
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=84711c0a-1700-0000-acfa-e09d100d0000 pid=3344 /usr/bin/sudo guuid=21808d0c-1700-0000-acfa-e09d160d0000 pid=3350 /tmp/sample.bin guuid=84711c0a-1700-0000-acfa-e09d100d0000 pid=3344->guuid=21808d0c-1700-0000-acfa-e09d160d0000 pid=3350 execve guuid=832afb0c-1700-0000-acfa-e09d190d0000 pid=3353 /usr/bin/systemctl guuid=21808d0c-1700-0000-acfa-e09d160d0000 pid=3350->guuid=832afb0c-1700-0000-acfa-e09d190d0000 pid=3353 execve guuid=3b30700e-1700-0000-acfa-e09d1f0d0000 pid=3359 /usr/bin/bash guuid=21808d0c-1700-0000-acfa-e09d160d0000 pid=3350->guuid=3b30700e-1700-0000-acfa-e09d1f0d0000 pid=3359 clone guuid=6ccdcb14-1700-0000-acfa-e09d300d0000 pid=3376 /usr/bin/bash guuid=21808d0c-1700-0000-acfa-e09d160d0000 pid=3350->guuid=6ccdcb14-1700-0000-acfa-e09d300d0000 pid=3376 clone guuid=8117d315-1700-0000-acfa-e09d370d0000 pid=3383 /usr/bin/id guuid=21808d0c-1700-0000-acfa-e09d160d0000 pid=3350->guuid=8117d315-1700-0000-acfa-e09d370d0000 pid=3383 execve guuid=b8c3ad16-1700-0000-acfa-e09d3b0d0000 pid=3387 /usr/bin/mkdir guuid=21808d0c-1700-0000-acfa-e09d160d0000 pid=3350->guuid=b8c3ad16-1700-0000-acfa-e09d3b0d0000 pid=3387 execve guuid=2e4b3317-1700-0000-acfa-e09d3d0d0000 pid=3389 /usr/bin/wget dns net send-data write-file guuid=21808d0c-1700-0000-acfa-e09d160d0000 pid=3350->guuid=2e4b3317-1700-0000-acfa-e09d3d0d0000 pid=3389 execve guuid=32e9313b-1700-0000-acfa-e09da80d0000 pid=3496 /usr/bin/tar write-file guuid=21808d0c-1700-0000-acfa-e09d160d0000 pid=3350->guuid=32e9313b-1700-0000-acfa-e09da80d0000 pid=3496 execve guuid=2f153046-1700-0000-acfa-e09dcd0d0000 pid=3533 /usr/bin/mv guuid=21808d0c-1700-0000-acfa-e09d160d0000 pid=3350->guuid=2f153046-1700-0000-acfa-e09dcd0d0000 pid=3533 execve guuid=68388646-1700-0000-acfa-e09dd00d0000 pid=3536 /usr/bin/rm guuid=21808d0c-1700-0000-acfa-e09d160d0000 pid=3350->guuid=68388646-1700-0000-acfa-e09dd00d0000 pid=3536 execve guuid=1234bd46-1700-0000-acfa-e09dd10d0000 pid=3537 /usr/bin/chmod guuid=21808d0c-1700-0000-acfa-e09d160d0000 pid=3350->guuid=1234bd46-1700-0000-acfa-e09dd10d0000 pid=3537 execve guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538 /usr/lib/dev/systemdev/systemd-mont mprotect-exec net send-data guuid=21808d0c-1700-0000-acfa-e09d160d0000 pid=3350->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538 execve guuid=b1b41b47-1700-0000-acfa-e09dd30d0000 pid=3539 /usr/bin/sleep guuid=21808d0c-1700-0000-acfa-e09d160d0000 pid=3350->guuid=b1b41b47-1700-0000-acfa-e09dd30d0000 pid=3539 execve guuid=8660d665-1700-0000-acfa-e09d370e0000 pid=3639 /usr/bin/ps guuid=21808d0c-1700-0000-acfa-e09d160d0000 pid=3350->guuid=8660d665-1700-0000-acfa-e09d370e0000 pid=3639 execve guuid=837f5271-1700-0000-acfa-e09d610e0000 pid=3681 /usr/bin/sleep guuid=21808d0c-1700-0000-acfa-e09d160d0000 pid=3350->guuid=837f5271-1700-0000-acfa-e09d610e0000 pid=3681 execve guuid=e2a9977e-1800-0000-acfa-e09d23110000 pid=4387 /usr/bin/ps guuid=21808d0c-1700-0000-acfa-e09d160d0000 pid=3350->guuid=e2a9977e-1800-0000-acfa-e09d23110000 pid=4387 execve guuid=db5a9186-1800-0000-acfa-e09d24110000 pid=4388 /usr/bin/rm guuid=21808d0c-1700-0000-acfa-e09d160d0000 pid=3350->guuid=db5a9186-1800-0000-acfa-e09d24110000 pid=4388 execve guuid=16d4d887-1800-0000-acfa-e09d25110000 pid=4389 /usr/bin/rm guuid=21808d0c-1700-0000-acfa-e09d160d0000 pid=3350->guuid=16d4d887-1800-0000-acfa-e09d25110000 pid=4389 execve guuid=54a0820e-1700-0000-acfa-e09d200d0000 pid=3360 /usr/bin/wget dns net send-data guuid=3b30700e-1700-0000-acfa-e09d1f0d0000 pid=3359->guuid=54a0820e-1700-0000-acfa-e09d200d0000 pid=3360 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=54a0820e-1700-0000-acfa-e09d200d0000 pid=3360->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B 0690ccd5-4816-5f11-94dc-7c585f38cdea ipv4.icanhazip.com:0 guuid=54a0820e-1700-0000-acfa-e09d200d0000 pid=3360->0690ccd5-4816-5f11-94dc-7c585f38cdea con d0ecfe49-aa79-583f-85c6-85ac97075256 ipv4.icanhazip.com:80 guuid=54a0820e-1700-0000-acfa-e09d200d0000 pid=3360->d0ecfe49-aa79-583f-85c6-85ac97075256 send: 133B guuid=5760d814-1700-0000-acfa-e09d310d0000 pid=3377 /usr/bin/bash guuid=6ccdcb14-1700-0000-acfa-e09d300d0000 pid=3376->guuid=5760d814-1700-0000-acfa-e09d310d0000 pid=3377 clone guuid=791ce114-1700-0000-acfa-e09d320d0000 pid=3378 /usr/bin/sed guuid=6ccdcb14-1700-0000-acfa-e09d300d0000 pid=3376->guuid=791ce114-1700-0000-acfa-e09d320d0000 pid=3378 execve guuid=00d0e814-1700-0000-acfa-e09d330d0000 pid=3379 /usr/bin/cut guuid=6ccdcb14-1700-0000-acfa-e09d300d0000 pid=3376->guuid=00d0e814-1700-0000-acfa-e09d330d0000 pid=3379 execve guuid=2e4b3317-1700-0000-acfa-e09d3d0d0000 pid=3389->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 164B 75aab096-419b-50ef-be46-7d76b6a90e4c github.com:443 guuid=2e4b3317-1700-0000-acfa-e09d3d0d0000 pid=3389->75aab096-419b-50ef-be46-7d76b6a90e4c send: 802B f8c5e44f-328d-5324-8bbd-da50752b9120 release-assets.githubusercontent.com:0 guuid=2e4b3317-1700-0000-acfa-e09d3d0d0000 pid=3389->f8c5e44f-328d-5324-8bbd-da50752b9120 con f0eebea5-e97d-507c-a771-59cac353877c release-assets.githubusercontent.com:443 guuid=2e4b3317-1700-0000-acfa-e09d3d0d0000 pid=3389->f0eebea5-e97d-507c-a771-59cac353877c send: 1662B guuid=a84d823b-1700-0000-acfa-e09dac0d0000 pid=3500 /usr/bin/gzip guuid=32e9313b-1700-0000-acfa-e09da80d0000 pid=3496->guuid=a84d823b-1700-0000-acfa-e09dac0d0000 pid=3500 execve 5b34c3af-d415-55dd-bdb3-d684a2b53711 116.202.3.220:23656 guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->5b34c3af-d415-55dd-bdb3-d684a2b53711 send: 489B guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3541 /usr/lib/dev/systemdev/systemd-mont write-file zombie guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3541 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3542 /usr/lib/dev/systemdev/systemd-mont send-data guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3542 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3543 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3543 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3544 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3544 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3545 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3545 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3563 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3563 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3564 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3564 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3565 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3565 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3566 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3566 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3583 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3583 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3584 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3584 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3585 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3585 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3586 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3586 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3605 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3605 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3607 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3607 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3608 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3608 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3609 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3609 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3625 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3625 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3626 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3626 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3627 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3627 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3628 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3628 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3647 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3647 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3649 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3649 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3650 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3650 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3651 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3651 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3670 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3670 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3671 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3671 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3672 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3672 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3673 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3673 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3688 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3688 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3689 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3689 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3690 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3690 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3691 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3691 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3709 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3709 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3710 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3710 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3711 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3711 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3712 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3712 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3713 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3713 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3714 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3714 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3715 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3715 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3716 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3716 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3728 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3728 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3729 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3729 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3730 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3730 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3731 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3731 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3743 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3743 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3744 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3744 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3745 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3745 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3746 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3746 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3765 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3765 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3766 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3766 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3767 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3767 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3768 /usr/lib/dev/systemdev/systemd-mont guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3538->guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3768 clone guuid=b19e0d47-1700-0000-acfa-e09dd20d0000 pid=3542->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B
Threat name:
Script.Trojan.Heuristic
Status:
Malicious
First seen:
2025-07-16 02:07:41 UTC
File Type:
Text (Shell)
AV detection:
5 of 38 (13.16%)
Threat level:
  2/5
Result
Malware family:
xmrig_linux
Score:
  10/10
Tags:
family:xmrig family:xmrig_linux antivm defense_evasion discovery linux miner
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads CPU attributes
Checks hardware identifiers (DMI)
Enumerates running processes
Reads hardware information
File and Directory Permissions Modification
Executes dropped EXE
XMRig Miner payload
Xmrig family
Xmrig_linux family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_SH_CryptoMiner_Indicators_Dec20_1
Author:Florian Roth (Nextron Systems)
Description:Detects helper script used in a crypto miner campaign
Reference:https://www.intezer.com/blog/research/new-golang-worm-drops-xmrig-miner-on-servers/
Rule name:SUSP_LNX_SH_CryptoMiner_Indicators_Dec20_1_RID364E
Author:Florian Roth
Description:Detects helper script used in a crypto miner campaign
Reference:https://www.intezer.com/blog/research/new-golang-worm-drops-xmrig-miner-on-servers/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments