MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 770182c8ac916900bf5e9728e8e1c5d03bf05a502adfb559dcdf5245ac88d23b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 770182c8ac916900bf5e9728e8e1c5d03bf05a502adfb559dcdf5245ac88d23b
SHA3-384 hash: 4feed2e6a7a3798be55e564e325f435cb24c9fa57974b0805ac1a3c936874265b34fb48c53976f325f99bcd8f7c2ecf4
SHA1 hash: 1804893047e12e7b71131a9350dcdf7633ccd7f9
MD5 hash: 6c3643fb0823ad9c15f53164fb719488
humanhash: item-fanta-table-tango
File name:mon.sh
Download: download sample
Signature CoinMiner
File size:4'568 bytes
First seen:2025-06-12 17:22:12 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:l06z0cic27rP7DTAiVjQR793jt0yjtgmu4IL1Sd6z0cd:l080c9irzDNjQ9935XvIL1Sd80cd
TLSH T1B791764AF690CAF03C9DC5A8999B6485390601879D040D1EF82EF59D7F5479CB0F87AF
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.248.53.119:8000/mon.sh778ec852860f474f7172948a24cf5cccdcef4f644db42dceefaff5b08ac556fd CoinMinerCoinMiner
http://ip-api.com/json/n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
163
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
96.5%
Tags:
cryptominer agent virus
Status:
terminated
Behavior Graph:
%3 guuid=f35b4f19-1900-0000-f7d8-65351f0b0000 pid=2847 /usr/bin/sudo guuid=f50a351b-1900-0000-f7d8-6535240b0000 pid=2852 /tmp/sample.bin guuid=f35b4f19-1900-0000-f7d8-65351f0b0000 pid=2847->guuid=f50a351b-1900-0000-f7d8-6535240b0000 pid=2852 execve guuid=c989171c-1900-0000-f7d8-6535260b0000 pid=2854 /usr/bin/whoami guuid=f50a351b-1900-0000-f7d8-6535240b0000 pid=2852->guuid=c989171c-1900-0000-f7d8-6535260b0000 pid=2854 execve guuid=2520a71c-1900-0000-f7d8-6535280b0000 pid=2856 /usr/bin/whoami guuid=f50a351b-1900-0000-f7d8-6535240b0000 pid=2852->guuid=2520a71c-1900-0000-f7d8-6535280b0000 pid=2856 execve guuid=75ce2e1d-1900-0000-f7d8-65352b0b0000 pid=2859 /usr/bin/whoami guuid=f50a351b-1900-0000-f7d8-6535240b0000 pid=2852->guuid=75ce2e1d-1900-0000-f7d8-65352b0b0000 pid=2859 execve guuid=cfe2991d-1900-0000-f7d8-65352e0b0000 pid=2862 /usr/bin/bash guuid=f50a351b-1900-0000-f7d8-6535240b0000 pid=2852->guuid=cfe2991d-1900-0000-f7d8-65352e0b0000 pid=2862 clone guuid=7d70b01d-1900-0000-f7d8-65352f0b0000 pid=2863 /usr/bin/id guuid=f50a351b-1900-0000-f7d8-6535240b0000 pid=2852->guuid=7d70b01d-1900-0000-f7d8-65352f0b0000 pid=2863 execve guuid=8a1aa31e-1900-0000-f7d8-6535330b0000 pid=2867 /usr/bin/systemctl guuid=f50a351b-1900-0000-f7d8-6535240b0000 pid=2852->guuid=8a1aa31e-1900-0000-f7d8-6535330b0000 pid=2867 execve guuid=26441621-1900-0000-f7d8-65353b0b0000 pid=2875 /usr/bin/bash guuid=f50a351b-1900-0000-f7d8-6535240b0000 pid=2852->guuid=26441621-1900-0000-f7d8-65353b0b0000 pid=2875 clone guuid=96672621-1900-0000-f7d8-65353c0b0000 pid=2876 /usr/bin/grep guuid=f50a351b-1900-0000-f7d8-6535240b0000 pid=2852->guuid=96672621-1900-0000-f7d8-65353c0b0000 pid=2876 execve guuid=f6a1cd21-1900-0000-f7d8-65353f0b0000 pid=2879 /usr/bin/bash guuid=f50a351b-1900-0000-f7d8-6535240b0000 pid=2852->guuid=f6a1cd21-1900-0000-f7d8-65353f0b0000 pid=2879 clone guuid=da18d521-1900-0000-f7d8-6535400b0000 pid=2880 /usr/bin/bash guuid=f50a351b-1900-0000-f7d8-6535240b0000 pid=2852->guuid=da18d521-1900-0000-f7d8-6535400b0000 pid=2880 clone guuid=485e2b22-1900-0000-f7d8-6535420b0000 pid=2882 /usr/bin/ps guuid=f50a351b-1900-0000-f7d8-6535240b0000 pid=2852->guuid=485e2b22-1900-0000-f7d8-6535420b0000 pid=2882 execve guuid=c9473722-1900-0000-f7d8-6535440b0000 pid=2884 /usr/bin/mawk guuid=f50a351b-1900-0000-f7d8-6535240b0000 pid=2852->guuid=c9473722-1900-0000-f7d8-6535440b0000 pid=2884 execve guuid=a7bb3d22-1900-0000-f7d8-6535450b0000 pid=2885 /usr/bin/bash guuid=f50a351b-1900-0000-f7d8-6535240b0000 pid=2852->guuid=a7bb3d22-1900-0000-f7d8-6535450b0000 pid=2885 clone guuid=0e109227-1900-0000-f7d8-6535520b0000 pid=2898 /usr/bin/bash guuid=f50a351b-1900-0000-f7d8-6535240b0000 pid=2852->guuid=0e109227-1900-0000-f7d8-6535520b0000 pid=2898 clone guuid=1771282c-1900-0000-f7d8-65355c0b0000 pid=2908 /usr/bin/curl net send-data guuid=f50a351b-1900-0000-f7d8-6535240b0000 pid=2852->guuid=1771282c-1900-0000-f7d8-65355c0b0000 pid=2908 execve guuid=74cd312c-1900-0000-f7d8-65355d0b0000 pid=2909 /usr/bin/grep guuid=f50a351b-1900-0000-f7d8-6535240b0000 pid=2852->guuid=74cd312c-1900-0000-f7d8-65355d0b0000 pid=2909 execve guuid=71c10643-1900-0000-f7d8-6535770b0000 pid=2935 /usr/bin/wget net send-data write-file guuid=f50a351b-1900-0000-f7d8-6535240b0000 pid=2852->guuid=71c10643-1900-0000-f7d8-6535770b0000 pid=2935 execve guuid=a86dfa55-1900-0000-f7d8-6535860b0000 pid=2950 /usr/bin/chmod guuid=f50a351b-1900-0000-f7d8-6535240b0000 pid=2852->guuid=a86dfa55-1900-0000-f7d8-6535860b0000 pid=2950 execve guuid=31866756-1900-0000-f7d8-6535870b0000 pid=2951 /home/sandbox/run.sh guuid=f50a351b-1900-0000-f7d8-6535240b0000 pid=2852->guuid=31866756-1900-0000-f7d8-6535870b0000 pid=2951 execve guuid=06ece221-1900-0000-f7d8-6535410b0000 pid=2881 /usr/bin/bash guuid=f6a1cd21-1900-0000-f7d8-65353f0b0000 pid=2879->guuid=06ece221-1900-0000-f7d8-6535410b0000 pid=2881 clone guuid=a1689c27-1900-0000-f7d8-6535530b0000 pid=2899 /usr/bin/ps guuid=0e109227-1900-0000-f7d8-6535520b0000 pid=2898->guuid=a1689c27-1900-0000-f7d8-6535530b0000 pid=2899 execve guuid=d680a127-1900-0000-f7d8-6535540b0000 pid=2900 /usr/bin/grep guuid=0e109227-1900-0000-f7d8-6535520b0000 pid=2898->guuid=d680a127-1900-0000-f7d8-6535540b0000 pid=2900 execve guuid=2cdca727-1900-0000-f7d8-6535550b0000 pid=2901 /usr/bin/grep guuid=0e109227-1900-0000-f7d8-6535520b0000 pid=2898->guuid=2cdca727-1900-0000-f7d8-6535550b0000 pid=2901 execve guuid=84faad27-1900-0000-f7d8-6535560b0000 pid=2902 /usr/bin/wc guuid=0e109227-1900-0000-f7d8-6535520b0000 pid=2898->guuid=84faad27-1900-0000-f7d8-6535560b0000 pid=2902 execve b60edd83-de97-543e-8c12-c815cb088ff2 ip-api.com:80 guuid=1771282c-1900-0000-f7d8-65355c0b0000 pid=2908->b60edd83-de97-543e-8c12-c815cb088ff2 send: 79B guuid=1771282c-1900-0000-f7d8-65355c0b0000 pid=2917 /usr/bin/curl dns net send-data guuid=1771282c-1900-0000-f7d8-65355c0b0000 pid=2908->guuid=1771282c-1900-0000-f7d8-65355c0b0000 pid=2917 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=1771282c-1900-0000-f7d8-65355c0b0000 pid=2917->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 28B 2f67bf0f-8453-5800-9e7b-37101ce5849f 162.248.53.119:8000 guuid=71c10643-1900-0000-f7d8-6535770b0000 pid=2935->2f67bf0f-8453-5800-9e7b-37101ce5849f send: 140B guuid=d87be856-1900-0000-f7d8-6535880b0000 pid=2952 /usr/bin/systemctl guuid=31866756-1900-0000-f7d8-6535870b0000 pid=2951->guuid=d87be856-1900-0000-f7d8-6535880b0000 pid=2952 execve guuid=8e886358-1900-0000-f7d8-65358a0b0000 pid=2954 /usr/bin/bash guuid=31866756-1900-0000-f7d8-6535870b0000 pid=2951->guuid=8e886358-1900-0000-f7d8-65358a0b0000 pid=2954 clone guuid=ec20515f-1900-0000-f7d8-6535990b0000 pid=2969 /usr/bin/bash guuid=31866756-1900-0000-f7d8-6535870b0000 pid=2951->guuid=ec20515f-1900-0000-f7d8-6535990b0000 pid=2969 clone guuid=a89a1960-1900-0000-f7d8-65359f0b0000 pid=2975 /usr/bin/id guuid=31866756-1900-0000-f7d8-6535870b0000 pid=2951->guuid=a89a1960-1900-0000-f7d8-65359f0b0000 pid=2975 execve guuid=5a299260-1900-0000-f7d8-6535a10b0000 pid=2977 /usr/bin/mkdir guuid=31866756-1900-0000-f7d8-6535870b0000 pid=2951->guuid=5a299260-1900-0000-f7d8-6535a10b0000 pid=2977 execve guuid=b54c0861-1900-0000-f7d8-6535a30b0000 pid=2979 /usr/bin/wget guuid=31866756-1900-0000-f7d8-6535870b0000 pid=2951->guuid=b54c0861-1900-0000-f7d8-6535a30b0000 pid=2979 execve guuid=16487b58-1900-0000-f7d8-65358b0b0000 pid=2955 /usr/bin/wget dns net send-data guuid=8e886358-1900-0000-f7d8-65358a0b0000 pid=2954->guuid=16487b58-1900-0000-f7d8-65358b0b0000 pid=2955 execve guuid=16487b58-1900-0000-f7d8-65358b0b0000 pid=2955->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B 0690ccd5-4816-5f11-94dc-7c585f38cdea ipv4.icanhazip.com:0 guuid=16487b58-1900-0000-f7d8-65358b0b0000 pid=2955->0690ccd5-4816-5f11-94dc-7c585f38cdea con d0ecfe49-aa79-583f-85c6-85ac97075256 ipv4.icanhazip.com:80 guuid=16487b58-1900-0000-f7d8-65358b0b0000 pid=2955->d0ecfe49-aa79-583f-85c6-85ac97075256 send: 133B guuid=6b63605f-1900-0000-f7d8-65359a0b0000 pid=2970 /usr/bin/bash guuid=ec20515f-1900-0000-f7d8-6535990b0000 pid=2969->guuid=6b63605f-1900-0000-f7d8-65359a0b0000 pid=2970 clone guuid=657e6c5f-1900-0000-f7d8-65359b0b0000 pid=2971 /usr/bin/sed guuid=ec20515f-1900-0000-f7d8-6535990b0000 pid=2969->guuid=657e6c5f-1900-0000-f7d8-65359b0b0000 pid=2971 execve guuid=eb0a7e5f-1900-0000-f7d8-65359c0b0000 pid=2972 /usr/bin/cut guuid=ec20515f-1900-0000-f7d8-6535990b0000 pid=2969->guuid=eb0a7e5f-1900-0000-f7d8-65359c0b0000 pid=2972 execve
Threat name:
Linux.Downloader.SAgnt
Status:
Malicious
First seen:
2025-06-12 17:22:43 UTC
File Type:
Text (Shell)
AV detection:
8 of 38 (21.05%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:xmrig antivm defense_evasion discovery execution linux miner persistence privilege_escalation rootkit upx
Behaviour
Enumerates kernel/hardware configuration
Process Discovery
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
Reads CPU attributes
UPX packed file
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Enumerates running processes
Looks up external IP address via web service
Reads hardware information
File and Directory Permissions Modification
Executes dropped EXE
Loads a kernel module
XMRig Miner payload
Xmrig family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments