MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 752774904729917a1ca3be159a4dcfc4f1e21f1869952838734916bb6b7d1047. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 752774904729917a1ca3be159a4dcfc4f1e21f1869952838734916bb6b7d1047
SHA3-384 hash: e84bad1e9f5a903c0dd446537df4c5138b106bb79b23ff4fce4bfda456329b86770e66477c003a10eb4248af93a68342
SHA1 hash: 47e1dcd61edd59e21e2761e7f086ac5c4b3ee33f
MD5 hash: 125cd3c2183bcf9522637b6b6a772453
humanhash: diet-six-wisconsin-summer
File name:aq.sh
Download: download sample
Signature CoinMiner
File size:444 bytes
First seen:2025-06-17 05:28:37 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:3WKDbnPZ7XOpue8f+AiJKq7bnQL7bnYMHqwYf+Y:GIbRi4wPPQLPYUYf+Y
TLSH T1E9F05CD8DA65EC7060950DEBF19BD404C9C6DBC96B975C14A6D028BF481D8047396F27
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://158.51.126.131/ibark4funn/an/aCoinMiner

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=9f8eb531-1800-0000-94da-03ab08080000 pid=2056 /usr/bin/sudo guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062 /tmp/sample.bin guuid=9f8eb531-1800-0000-94da-03ab08080000 pid=2056->guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062 execve guuid=e6a37234-1800-0000-94da-03ab10080000 pid=2064 /usr/bin/rm delete-file guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=e6a37234-1800-0000-94da-03ab10080000 pid=2064 execve guuid=6080cc34-1800-0000-94da-03ab12080000 pid=2066 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=6080cc34-1800-0000-94da-03ab12080000 pid=2066 execve guuid=71bc3135-1800-0000-94da-03ab14080000 pid=2068 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=71bc3135-1800-0000-94da-03ab14080000 pid=2068 execve guuid=9300a235-1800-0000-94da-03ab15080000 pid=2069 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=9300a235-1800-0000-94da-03ab15080000 pid=2069 execve guuid=e4371536-1800-0000-94da-03ab17080000 pid=2071 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=e4371536-1800-0000-94da-03ab17080000 pid=2071 execve guuid=671e8736-1800-0000-94da-03ab18080000 pid=2072 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=671e8736-1800-0000-94da-03ab18080000 pid=2072 execve guuid=dc130a37-1800-0000-94da-03ab19080000 pid=2073 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=dc130a37-1800-0000-94da-03ab19080000 pid=2073 execve guuid=cd687b37-1800-0000-94da-03ab1a080000 pid=2074 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=cd687b37-1800-0000-94da-03ab1a080000 pid=2074 execve guuid=05580538-1800-0000-94da-03ab1b080000 pid=2075 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=05580538-1800-0000-94da-03ab1b080000 pid=2075 execve guuid=5f9cde38-1800-0000-94da-03ab1f080000 pid=2079 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=5f9cde38-1800-0000-94da-03ab1f080000 pid=2079 execve guuid=fae06239-1800-0000-94da-03ab21080000 pid=2081 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=fae06239-1800-0000-94da-03ab21080000 pid=2081 execve guuid=c6d2d239-1800-0000-94da-03ab23080000 pid=2083 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=c6d2d239-1800-0000-94da-03ab23080000 pid=2083 execve guuid=e893333a-1800-0000-94da-03ab25080000 pid=2085 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=e893333a-1800-0000-94da-03ab25080000 pid=2085 execve guuid=e510ad3a-1800-0000-94da-03ab27080000 pid=2087 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=e510ad3a-1800-0000-94da-03ab27080000 pid=2087 execve guuid=8684683b-1800-0000-94da-03ab28080000 pid=2088 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=8684683b-1800-0000-94da-03ab28080000 pid=2088 execve guuid=4c7add3b-1800-0000-94da-03ab29080000 pid=2089 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=4c7add3b-1800-0000-94da-03ab29080000 pid=2089 execve guuid=4ab17c3c-1800-0000-94da-03ab2b080000 pid=2091 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=4ab17c3c-1800-0000-94da-03ab2b080000 pid=2091 execve guuid=b34bee3c-1800-0000-94da-03ab2e080000 pid=2094 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=b34bee3c-1800-0000-94da-03ab2e080000 pid=2094 execve guuid=61ff463d-1800-0000-94da-03ab30080000 pid=2096 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=61ff463d-1800-0000-94da-03ab30080000 pid=2096 execve guuid=376da23d-1800-0000-94da-03ab32080000 pid=2098 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=376da23d-1800-0000-94da-03ab32080000 pid=2098 execve guuid=07ee403e-1800-0000-94da-03ab34080000 pid=2100 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=07ee403e-1800-0000-94da-03ab34080000 pid=2100 execve guuid=81f9dc3e-1800-0000-94da-03ab37080000 pid=2103 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=81f9dc3e-1800-0000-94da-03ab37080000 pid=2103 execve guuid=9df05d3f-1800-0000-94da-03ab38080000 pid=2104 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=9df05d3f-1800-0000-94da-03ab38080000 pid=2104 execve guuid=4fe9cf3f-1800-0000-94da-03ab3a080000 pid=2106 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=4fe9cf3f-1800-0000-94da-03ab3a080000 pid=2106 execve guuid=48a64e40-1800-0000-94da-03ab3b080000 pid=2107 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=48a64e40-1800-0000-94da-03ab3b080000 pid=2107 execve guuid=147fd340-1800-0000-94da-03ab3c080000 pid=2108 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=147fd340-1800-0000-94da-03ab3c080000 pid=2108 execve guuid=8af94841-1800-0000-94da-03ab3d080000 pid=2109 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=8af94841-1800-0000-94da-03ab3d080000 pid=2109 execve guuid=6038ae41-1800-0000-94da-03ab3f080000 pid=2111 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=6038ae41-1800-0000-94da-03ab3f080000 pid=2111 execve guuid=1ef20f42-1800-0000-94da-03ab41080000 pid=2113 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=1ef20f42-1800-0000-94da-03ab41080000 pid=2113 execve guuid=3ffa7242-1800-0000-94da-03ab43080000 pid=2115 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=3ffa7242-1800-0000-94da-03ab43080000 pid=2115 execve guuid=6fa2c542-1800-0000-94da-03ab45080000 pid=2117 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=6fa2c542-1800-0000-94da-03ab45080000 pid=2117 execve guuid=fc5d2643-1800-0000-94da-03ab47080000 pid=2119 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=fc5d2643-1800-0000-94da-03ab47080000 pid=2119 execve guuid=004e8843-1800-0000-94da-03ab49080000 pid=2121 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=004e8843-1800-0000-94da-03ab49080000 pid=2121 execve guuid=5795e243-1800-0000-94da-03ab4b080000 pid=2123 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=5795e243-1800-0000-94da-03ab4b080000 pid=2123 execve guuid=4f6e4244-1800-0000-94da-03ab4d080000 pid=2125 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=4f6e4244-1800-0000-94da-03ab4d080000 pid=2125 execve guuid=e4559c44-1800-0000-94da-03ab4f080000 pid=2127 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=e4559c44-1800-0000-94da-03ab4f080000 pid=2127 execve guuid=69b91845-1800-0000-94da-03ab51080000 pid=2129 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=69b91845-1800-0000-94da-03ab51080000 pid=2129 execve guuid=beb18f45-1800-0000-94da-03ab53080000 pid=2131 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=beb18f45-1800-0000-94da-03ab53080000 pid=2131 execve guuid=97171e46-1800-0000-94da-03ab54080000 pid=2132 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=97171e46-1800-0000-94da-03ab54080000 pid=2132 execve guuid=ca8b8046-1800-0000-94da-03ab57080000 pid=2135 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=ca8b8046-1800-0000-94da-03ab57080000 pid=2135 execve guuid=f4d4de46-1800-0000-94da-03ab59080000 pid=2137 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=f4d4de46-1800-0000-94da-03ab59080000 pid=2137 execve guuid=73dd3e47-1800-0000-94da-03ab5b080000 pid=2139 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=73dd3e47-1800-0000-94da-03ab5b080000 pid=2139 execve guuid=60c59947-1800-0000-94da-03ab5d080000 pid=2141 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=60c59947-1800-0000-94da-03ab5d080000 pid=2141 execve guuid=2e780748-1800-0000-94da-03ab5f080000 pid=2143 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=2e780748-1800-0000-94da-03ab5f080000 pid=2143 execve guuid=0d5f7648-1800-0000-94da-03ab61080000 pid=2145 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=0d5f7648-1800-0000-94da-03ab61080000 pid=2145 execve guuid=f44e2949-1800-0000-94da-03ab62080000 pid=2146 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=f44e2949-1800-0000-94da-03ab62080000 pid=2146 execve guuid=dffec849-1800-0000-94da-03ab65080000 pid=2149 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=dffec849-1800-0000-94da-03ab65080000 pid=2149 execve guuid=bbbd674a-1800-0000-94da-03ab69080000 pid=2153 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=bbbd674a-1800-0000-94da-03ab69080000 pid=2153 execve guuid=f457d54a-1800-0000-94da-03ab6b080000 pid=2155 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=f457d54a-1800-0000-94da-03ab6b080000 pid=2155 execve guuid=a739d04b-1800-0000-94da-03ab6e080000 pid=2158 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=a739d04b-1800-0000-94da-03ab6e080000 pid=2158 execve guuid=27c4624c-1800-0000-94da-03ab71080000 pid=2161 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=27c4624c-1800-0000-94da-03ab71080000 pid=2161 execve guuid=6a00e84c-1800-0000-94da-03ab74080000 pid=2164 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=6a00e84c-1800-0000-94da-03ab74080000 pid=2164 execve guuid=2683454d-1800-0000-94da-03ab76080000 pid=2166 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=2683454d-1800-0000-94da-03ab76080000 pid=2166 execve guuid=7ef7a14d-1800-0000-94da-03ab78080000 pid=2168 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=7ef7a14d-1800-0000-94da-03ab78080000 pid=2168 execve guuid=302efc4d-1800-0000-94da-03ab7a080000 pid=2170 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=302efc4d-1800-0000-94da-03ab7a080000 pid=2170 execve guuid=19266a4e-1800-0000-94da-03ab7d080000 pid=2173 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=19266a4e-1800-0000-94da-03ab7d080000 pid=2173 execve guuid=023bcf4e-1800-0000-94da-03ab7f080000 pid=2175 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=023bcf4e-1800-0000-94da-03ab7f080000 pid=2175 execve guuid=bff3314f-1800-0000-94da-03ab82080000 pid=2178 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=bff3314f-1800-0000-94da-03ab82080000 pid=2178 execve guuid=422ea64f-1800-0000-94da-03ab83080000 pid=2179 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=422ea64f-1800-0000-94da-03ab83080000 pid=2179 execve guuid=d927fd4f-1800-0000-94da-03ab85080000 pid=2181 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=d927fd4f-1800-0000-94da-03ab85080000 pid=2181 execve guuid=ec0b6750-1800-0000-94da-03ab88080000 pid=2184 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=ec0b6750-1800-0000-94da-03ab88080000 pid=2184 execve guuid=b524bb50-1800-0000-94da-03ab89080000 pid=2185 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=b524bb50-1800-0000-94da-03ab89080000 pid=2185 execve guuid=8f187851-1800-0000-94da-03ab8d080000 pid=2189 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=8f187851-1800-0000-94da-03ab8d080000 pid=2189 execve guuid=335bd151-1800-0000-94da-03ab90080000 pid=2192 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=335bd151-1800-0000-94da-03ab90080000 pid=2192 execve guuid=e4893652-1800-0000-94da-03ab92080000 pid=2194 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=e4893652-1800-0000-94da-03ab92080000 pid=2194 execve guuid=b24ba452-1800-0000-94da-03ab95080000 pid=2197 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=b24ba452-1800-0000-94da-03ab95080000 pid=2197 execve guuid=a0416353-1800-0000-94da-03ab98080000 pid=2200 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=a0416353-1800-0000-94da-03ab98080000 pid=2200 execve guuid=8744ea53-1800-0000-94da-03ab9b080000 pid=2203 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=8744ea53-1800-0000-94da-03ab9b080000 pid=2203 execve guuid=8cf07554-1800-0000-94da-03ab9e080000 pid=2206 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=8cf07554-1800-0000-94da-03ab9e080000 pid=2206 execve guuid=4f1e0355-1800-0000-94da-03aba1080000 pid=2209 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=4f1e0355-1800-0000-94da-03aba1080000 pid=2209 execve guuid=05018f55-1800-0000-94da-03aba4080000 pid=2212 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=05018f55-1800-0000-94da-03aba4080000 pid=2212 execve guuid=55151656-1800-0000-94da-03aba7080000 pid=2215 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=55151656-1800-0000-94da-03aba7080000 pid=2215 execve guuid=92b6a156-1800-0000-94da-03abab080000 pid=2219 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=92b6a156-1800-0000-94da-03abab080000 pid=2219 execve guuid=e18c2757-1800-0000-94da-03abad080000 pid=2221 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=e18c2757-1800-0000-94da-03abad080000 pid=2221 execve guuid=e2e78757-1800-0000-94da-03abaf080000 pid=2223 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=e2e78757-1800-0000-94da-03abaf080000 pid=2223 execve guuid=f65df457-1800-0000-94da-03abb2080000 pid=2226 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=f65df457-1800-0000-94da-03abb2080000 pid=2226 execve guuid=aaea5858-1800-0000-94da-03abb4080000 pid=2228 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=aaea5858-1800-0000-94da-03abb4080000 pid=2228 execve guuid=6992c558-1800-0000-94da-03abb6080000 pid=2230 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=6992c558-1800-0000-94da-03abb6080000 pid=2230 execve guuid=99762159-1800-0000-94da-03abb8080000 pid=2232 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=99762159-1800-0000-94da-03abb8080000 pid=2232 execve guuid=b95a7859-1800-0000-94da-03abbb080000 pid=2235 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=b95a7859-1800-0000-94da-03abbb080000 pid=2235 execve guuid=5e26d959-1800-0000-94da-03abbd080000 pid=2237 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=5e26d959-1800-0000-94da-03abbd080000 pid=2237 execve guuid=327e3e5a-1800-0000-94da-03abc0080000 pid=2240 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=327e3e5a-1800-0000-94da-03abc0080000 pid=2240 execve guuid=d916df5a-1800-0000-94da-03abc3080000 pid=2243 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=d916df5a-1800-0000-94da-03abc3080000 pid=2243 execve guuid=4e8e415b-1800-0000-94da-03abc5080000 pid=2245 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=4e8e415b-1800-0000-94da-03abc5080000 pid=2245 execve guuid=c840ce5b-1800-0000-94da-03abc8080000 pid=2248 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=c840ce5b-1800-0000-94da-03abc8080000 pid=2248 execve guuid=aac82f5c-1800-0000-94da-03abcb080000 pid=2251 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=aac82f5c-1800-0000-94da-03abcb080000 pid=2251 execve guuid=7a049a5c-1800-0000-94da-03abcd080000 pid=2253 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=7a049a5c-1800-0000-94da-03abcd080000 pid=2253 execve guuid=1102015d-1800-0000-94da-03abcf080000 pid=2255 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=1102015d-1800-0000-94da-03abcf080000 pid=2255 execve guuid=494e635d-1800-0000-94da-03abd2080000 pid=2258 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=494e635d-1800-0000-94da-03abd2080000 pid=2258 execve guuid=e11ac55d-1800-0000-94da-03abd4080000 pid=2260 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=e11ac55d-1800-0000-94da-03abd4080000 pid=2260 execve guuid=0716225e-1800-0000-94da-03abd7080000 pid=2263 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=0716225e-1800-0000-94da-03abd7080000 pid=2263 execve guuid=05f7025f-1800-0000-94da-03abdb080000 pid=2267 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=05f7025f-1800-0000-94da-03abdb080000 pid=2267 execve guuid=9ca6635f-1800-0000-94da-03abdd080000 pid=2269 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=9ca6635f-1800-0000-94da-03abdd080000 pid=2269 execve guuid=baddc45f-1800-0000-94da-03abdf080000 pid=2271 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=baddc45f-1800-0000-94da-03abdf080000 pid=2271 execve guuid=b2132060-1800-0000-94da-03abe2080000 pid=2274 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=b2132060-1800-0000-94da-03abe2080000 pid=2274 execve guuid=3f0a7f60-1800-0000-94da-03abe4080000 pid=2276 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=3f0a7f60-1800-0000-94da-03abe4080000 pid=2276 execve guuid=954ed460-1800-0000-94da-03abe6080000 pid=2278 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=954ed460-1800-0000-94da-03abe6080000 pid=2278 execve guuid=ee113361-1800-0000-94da-03abe9080000 pid=2281 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=ee113361-1800-0000-94da-03abe9080000 pid=2281 execve guuid=a2b79761-1800-0000-94da-03abeb080000 pid=2283 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=a2b79761-1800-0000-94da-03abeb080000 pid=2283 execve guuid=ce5bf361-1800-0000-94da-03abed080000 pid=2285 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=ce5bf361-1800-0000-94da-03abed080000 pid=2285 execve guuid=a4695162-1800-0000-94da-03abf0080000 pid=2288 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=a4695162-1800-0000-94da-03abf0080000 pid=2288 execve guuid=3cb9ae62-1800-0000-94da-03abf2080000 pid=2290 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=3cb9ae62-1800-0000-94da-03abf2080000 pid=2290 execve guuid=c6050d63-1800-0000-94da-03abf4080000 pid=2292 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=c6050d63-1800-0000-94da-03abf4080000 pid=2292 execve guuid=40ed6263-1800-0000-94da-03abf6080000 pid=2294 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=40ed6263-1800-0000-94da-03abf6080000 pid=2294 execve guuid=82a1cf63-1800-0000-94da-03abf9080000 pid=2297 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=82a1cf63-1800-0000-94da-03abf9080000 pid=2297 execve guuid=b6b94464-1800-0000-94da-03abfc080000 pid=2300 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=b6b94464-1800-0000-94da-03abfc080000 pid=2300 execve guuid=35faaf64-1800-0000-94da-03abff080000 pid=2303 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=35faaf64-1800-0000-94da-03abff080000 pid=2303 execve guuid=b4731265-1800-0000-94da-03ab01090000 pid=2305 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=b4731265-1800-0000-94da-03ab01090000 pid=2305 execve guuid=1a206e65-1800-0000-94da-03ab04090000 pid=2308 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=1a206e65-1800-0000-94da-03ab04090000 pid=2308 execve guuid=c873cb65-1800-0000-94da-03ab06090000 pid=2310 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=c873cb65-1800-0000-94da-03ab06090000 pid=2310 execve guuid=865d4066-1800-0000-94da-03ab09090000 pid=2313 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=865d4066-1800-0000-94da-03ab09090000 pid=2313 execve guuid=3eb7f766-1800-0000-94da-03ab0c090000 pid=2316 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=3eb7f766-1800-0000-94da-03ab0c090000 pid=2316 execve guuid=5c685367-1800-0000-94da-03ab0f090000 pid=2319 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=5c685367-1800-0000-94da-03ab0f090000 pid=2319 execve guuid=7eccac67-1800-0000-94da-03ab11090000 pid=2321 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=7eccac67-1800-0000-94da-03ab11090000 pid=2321 execve guuid=f0b90968-1800-0000-94da-03ab13090000 pid=2323 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=f0b90968-1800-0000-94da-03ab13090000 pid=2323 execve guuid=eba25f68-1800-0000-94da-03ab16090000 pid=2326 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=eba25f68-1800-0000-94da-03ab16090000 pid=2326 execve guuid=acfbba68-1800-0000-94da-03ab18090000 pid=2328 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=acfbba68-1800-0000-94da-03ab18090000 pid=2328 execve guuid=067d1469-1800-0000-94da-03ab1a090000 pid=2330 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=067d1469-1800-0000-94da-03ab1a090000 pid=2330 execve guuid=35f97a69-1800-0000-94da-03ab1c090000 pid=2332 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=35f97a69-1800-0000-94da-03ab1c090000 pid=2332 execve guuid=d55ad569-1800-0000-94da-03ab1e090000 pid=2334 /usr/bin/ls guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=d55ad569-1800-0000-94da-03ab1e090000 pid=2334 execve guuid=0383366a-1800-0000-94da-03ab20090000 pid=2336 /usr/bin/dash guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=0383366a-1800-0000-94da-03ab20090000 pid=2336 clone guuid=3cc7c7ca-1800-0000-94da-03abdc090000 pid=2524 /usr/bin/chmod guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=3cc7c7ca-1800-0000-94da-03abdc090000 pid=2524 execve guuid=99ff0dcb-1800-0000-94da-03abde090000 pid=2526 /home/ntpclient mprotect-exec guuid=d30a0234-1800-0000-94da-03ab0e080000 pid=2062->guuid=99ff0dcb-1800-0000-94da-03abde090000 pid=2526 execve guuid=10c6446a-1800-0000-94da-03ab21090000 pid=2337 /usr/bin/curl net send-data write-file guuid=0383366a-1800-0000-94da-03ab20090000 pid=2336->guuid=10c6446a-1800-0000-94da-03ab21090000 pid=2337 execve 2beca644-24da-5e18-bc49-c06b8c4a111d 158.51.126.131:80 guuid=10c6446a-1800-0000-94da-03ab21090000 pid=2337->2beca644-24da-5e18-bc49-c06b8c4a111d send: 87B guuid=1d5fffcc-1800-0000-94da-03abe4090000 pid=2532 /home/ntpclient zombie guuid=99ff0dcb-1800-0000-94da-03abde090000 pid=2526->guuid=1d5fffcc-1800-0000-94da-03abe4090000 pid=2532 clone guuid=051029cd-1800-0000-94da-03abe5090000 pid=2533 /home/ntpclient guuid=1d5fffcc-1800-0000-94da-03abe4090000 pid=2532->guuid=051029cd-1800-0000-94da-03abe5090000 pid=2533 clone guuid=051029cd-1800-0000-94da-03abe5090000 pid=2537 /home/ntpclient guuid=051029cd-1800-0000-94da-03abe5090000 pid=2533->guuid=051029cd-1800-0000-94da-03abe5090000 pid=2537 clone guuid=051029cd-1800-0000-94da-03abe5090000 pid=2538 /home/ntpclient guuid=051029cd-1800-0000-94da-03abe5090000 pid=2533->guuid=051029cd-1800-0000-94da-03abe5090000 pid=2538 clone guuid=051029cd-1800-0000-94da-03abe5090000 pid=2539 /home/ntpclient guuid=051029cd-1800-0000-94da-03abe5090000 pid=2533->guuid=051029cd-1800-0000-94da-03abe5090000 pid=2539 clone guuid=051029cd-1800-0000-94da-03abe5090000 pid=2540 /home/ntpclient guuid=051029cd-1800-0000-94da-03abe5090000 pid=2533->guuid=051029cd-1800-0000-94da-03abe5090000 pid=2540 clone guuid=051029cd-1800-0000-94da-03abe5090000 pid=2542 /home/ntpclient guuid=051029cd-1800-0000-94da-03abe5090000 pid=2533->guuid=051029cd-1800-0000-94da-03abe5090000 pid=2542 clone
Threat name:
Script.Trojan.Multiverze
Status:
Malicious
First seen:
2025-06-17 05:33:01 UTC
File Type:
Text (Shell)
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CoinMiner

sh 752774904729917a1ca3be159a4dcfc4f1e21f1869952838734916bb6b7d1047

(this sample)

  
Delivery method
Distributed via web download

Comments