MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7a1fb6fb2e7fce5634ef1ff254f013e509c17b27b08584d93b075c0cae81f5f5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 6


Intelligence 6 IOCs YARA 23 File information Comments

SHA256 hash: 7a1fb6fb2e7fce5634ef1ff254f013e509c17b27b08584d93b075c0cae81f5f5
SHA3-384 hash: 881eb690d176ac470d53f8ec8d8eebf5713fb57513ae5c9c7d87651632b35ad36a6a4931c0cb355b2ce1dcae809f04f1
SHA1 hash: 50d282ab72b1300e9c0bc33dcb7bebcf597d29bf
MD5 hash: cd384bf825bd0d0ac43a2e7eae767070
humanhash: triple-indigo-yankee-fifteen
File name:px1
Download: download sample
Signature CoinMiner
File size:8'287'476 bytes
First seen:2025-12-30 19:59:24 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 98304:sINkscufZcqSGWMqJjWzMXke2zcEm7NG5uzTn+HO2GjZdXEQBtoFtR:sOcVGWVJWohQm7G+TnoOpZd0GtoFf
TLSH T130868D03EC9559E9C0EE92318A769252BB71BC451B2123D73B90F3382F77BD4AA79740
telfhash t1301453939c62bf6b4fc403229cf5d5c49357d04b08937ba86fb08336d4eb489a5b935a
gimphash e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:CoinMiner elf

Intelligence


File Origin
# of uploads :
1
# of downloads :
25
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
base64 crypto expand golang lolbin
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=b2c7426b-1a00-0000-2082-b24e390a0000 pid=2617 /usr/bin/sudo guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2628 /tmp/sample.bin net send-data write-file guuid=b2c7426b-1a00-0000-2082-b24e390a0000 pid=2617->guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2628 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2628->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 39B 75aab096-419b-50ef-be46-7d76b6a90e4c github.com:443 guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2628->75aab096-419b-50ef-be46-7d76b6a90e4c send: 1516B f0eebea5-e97d-507c-a771-59cac353877c release-assets.githubusercontent.com:443 guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2628->f0eebea5-e97d-507c-a771-59cac353877c send: 384B guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2641 /tmp/sample.bin guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2628->guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2641 clone guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2642 /tmp/sample.bin dns net send-data write-file guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2628->guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2642 clone guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2643 /tmp/sample.bin net send-data write-file guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2628->guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2643 clone guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2644 /tmp/sample.bin dns net send-data write-file guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2628->guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2644 clone guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2722 /tmp/sample.bin net send-data write-file guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2628->guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2722 clone guuid=0209ddbc-1a00-0000-2082-b24ed50a0000 pid=2773 /tmp/sample.bin guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2628->guuid=0209ddbc-1a00-0000-2082-b24ed50a0000 pid=2773 clone guuid=daa2ebbc-1a00-0000-2082-b24ed60a0000 pid=2774 /usr/bin/tar write-file guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2628->guuid=daa2ebbc-1a00-0000-2082-b24ed60a0000 pid=2774 execve guuid=a76521df-1a00-0000-2082-b24efe0a0000 pid=2814 /usr/bin/chmod guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2628->guuid=a76521df-1a00-0000-2082-b24efe0a0000 pid=2814 execve guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816 /home/sandbox/xmrig-6.24.0/xmrig mprotect-exec net send-data guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2628->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816 execve guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2642->75aab096-419b-50ef-be46-7d76b6a90e4c send: 299B guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2642->f0eebea5-e97d-507c-a771-59cac353877c send: 1801B 288774ae-e001-5e29-b763-4b4e54e441c6 release-assets.githubusercontent.com:53 guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2642->288774ae-e001-5e29-b763-4b4e54e441c6 con guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2643->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 39B guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2643->f0eebea5-e97d-507c-a771-59cac353877c send: 288B guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2644->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 65B guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2644->75aab096-419b-50ef-be46-7d76b6a90e4c send: 31B guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2644->f0eebea5-e97d-507c-a771-59cac353877c send: 3631B guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2722->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 65B guuid=b3273e6f-1a00-0000-2082-b24e440a0000 pid=2722->f0eebea5-e97d-507c-a771-59cac353877c send: 2118B guuid=368fe5bd-1a00-0000-2082-b24ed80a0000 pid=2776 /usr/bin/gzip guuid=daa2ebbc-1a00-0000-2082-b24ed60a0000 pid=2774->guuid=368fe5bd-1a00-0000-2082-b24ed80a0000 pid=2776 execve 3272d082-ef6d-599c-8be1-ef6a454a58a1 195.24.236.148:110 guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->3272d082-ef6d-599c-8be1-ef6a454a58a1 send: 452B guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2822 /home/sandbox/xmrig-6.24.0/xmrig write-file guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2822 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2823 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2823 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2824 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2824 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2825 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2825 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2826 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2826 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2828 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2828 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2829 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2829 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2830 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2830 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2831 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2831 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2842 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2842 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2844 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2844 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2845 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2845 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2846 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2846 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2857 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2857 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2858 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2858 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2859 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2859 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2860 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2860 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2870 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2870 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2871 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2871 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2872 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2872 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2873 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2873 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2883 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2883 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2884 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2884 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2885 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2885 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2886 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2886 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2902 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2902 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2903 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2903 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2904 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2904 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2905 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2905 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2922 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2922 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2923 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2923 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2924 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2924 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2925 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2925 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2945 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2945 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2947 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2947 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2948 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2948 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2949 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2949 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2961 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2961 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2962 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2962 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2963 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2963 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2964 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2964 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2978 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2978 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2979 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2979 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2980 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2980 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2981 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2981 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2982 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2982 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2983 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2983 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2984 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2984 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2985 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2985 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2994 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2994 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2995 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2995 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2996 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2996 clone guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2997 /home/sandbox/xmrig-6.24.0/xmrig guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2816->guuid=c6f967df-1a00-0000-2082-b24e000b0000 pid=2997 clone
Result
Threat name:
n/a
Detection:
suspicious
Classification:
mine
Score:
22 / 100
Signature
Stdout / stderr contain strings indicative of a mining client
Behaviour
Behavior Graph:
Result
Malware family:
xmrig_linux
Score:
  10/10
Tags:
family:xmrig family:xmrig_linux antivm discovery linux miner
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads CPU attributes
Checks hardware identifiers (DMI)
Reads hardware information
Executes dropped EXE
XMRig Miner payload
Xmrig family
Xmrig_linux family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:DetectGoMethodSignatures
Author:Wyatt Tauber
Description:Detects Go method signatures in unpacked Go binaries
Rule name:Detect_Go_GOMAXPROCS
Author:Obscurity Labs LLC
Description:Detects Go binaries by the presence of runtime.GOMAXPROCS in the runtime metadata
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:enterpriseunix2
Author:Tim Brown @timb_machine
Description:Enterprise UNIX
Rule name:F01_s1ckrule
Author:s1ckb017
Rule name:GoBinTest
Rule name:golang
Rule name:golang_binary_string
Description:Golang strings present
Rule name:golang_duffcopy_amd64
Rule name:Golang_Find_CSC846
Author:Ashar Siddiqui
Description:Find Go Signatuers
Rule name:Golang_Find_CSC846_Simple
Author:Ashar Siddiqui
Description:Find Go Signatuers
Rule name:identity_golang
Author:Eric Yocam
Description:find Golang malware
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:ProgramLanguage_Golang
Author:albertzsigovits
Description:Application written in Golang programming language
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CoinMiner

elf 7a1fb6fb2e7fce5634ef1ff254f013e509c17b27b08584d93b075c0cae81f5f5

(this sample)

  
Delivery method
Distributed via web download

Comments