MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 81260923a80e2a13088be82c23304c6f55980d0ce66d5c1848a59d9673d51677. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 81260923a80e2a13088be82c23304c6f55980d0ce66d5c1848a59d9673d51677
SHA3-384 hash: ad9d5d9e40c9329a9b7f394157199955367f659f1fb86c7c7c186ffff640d2cc61ffb1af44042aa4411c05a30365b38c
SHA1 hash: a9a75a2425dbc2af21eb699596a2e06ba8e88b6e
MD5 hash: bc95533f302f29b870c191323376cbfb
humanhash: batman-lemon-alaska-carolina
File name:mon.sh
Download: download sample
Signature CoinMiner
File size:5'055 bytes
First seen:2025-08-01 17:44:14 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:l06z0cic27PP7DTAiVjIAmx793jt0yjtgmu4IL1qFQ2Eha1d6z0cd:l080c9iPzDNjGd935XvIL1qFhEw1d808
TLSH T1DFA1954AF690C6B0389DC5A8A99B74863A06018B4E441D1DF86FF4887F5475871F83FF
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.248.53.119:8000/mon.sh1e891ab1521b27923233e694f60fdbf0e1b840e657d8b1ffdefd8b5ef5e38964 CoinMinerCoinMiner
http://ip-api.com/json/n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
32
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
fingerprint
Status:
terminated
Behavior Graph:
%3 guuid=690f9d97-1700-0000-f305-762b190a0000 pid=2585 /usr/bin/sudo guuid=31e8bc99-1700-0000-f305-762b210a0000 pid=2593 /tmp/sample.bin guuid=690f9d97-1700-0000-f305-762b190a0000 pid=2585->guuid=31e8bc99-1700-0000-f305-762b210a0000 pid=2593 execve guuid=3835b89a-1700-0000-f305-762b240a0000 pid=2596 /usr/bin/whoami guuid=31e8bc99-1700-0000-f305-762b210a0000 pid=2593->guuid=3835b89a-1700-0000-f305-762b240a0000 pid=2596 execve guuid=fb863a9b-1700-0000-f305-762b270a0000 pid=2599 /usr/bin/whoami guuid=31e8bc99-1700-0000-f305-762b210a0000 pid=2593->guuid=fb863a9b-1700-0000-f305-762b270a0000 pid=2599 execve guuid=c5ee959b-1700-0000-f305-762b290a0000 pid=2601 /usr/bin/whoami guuid=31e8bc99-1700-0000-f305-762b210a0000 pid=2593->guuid=c5ee959b-1700-0000-f305-762b290a0000 pid=2601 execve guuid=a6fc009c-1700-0000-f305-762b2b0a0000 pid=2603 /usr/bin/bash guuid=31e8bc99-1700-0000-f305-762b210a0000 pid=2593->guuid=a6fc009c-1700-0000-f305-762b2b0a0000 pid=2603 clone guuid=1851149c-1700-0000-f305-762b2c0a0000 pid=2604 /usr/bin/id guuid=31e8bc99-1700-0000-f305-762b210a0000 pid=2593->guuid=1851149c-1700-0000-f305-762b2c0a0000 pid=2604 execve guuid=f3a8969c-1700-0000-f305-762b2f0a0000 pid=2607 /usr/bin/systemctl guuid=31e8bc99-1700-0000-f305-762b210a0000 pid=2593->guuid=f3a8969c-1700-0000-f305-762b2f0a0000 pid=2607 execve guuid=95b6949e-1700-0000-f305-762b370a0000 pid=2615 /usr/bin/bash guuid=31e8bc99-1700-0000-f305-762b210a0000 pid=2593->guuid=95b6949e-1700-0000-f305-762b370a0000 pid=2615 clone guuid=18b5a09e-1700-0000-f305-762b380a0000 pid=2616 /usr/bin/grep guuid=31e8bc99-1700-0000-f305-762b210a0000 pid=2593->guuid=18b5a09e-1700-0000-f305-762b380a0000 pid=2616 execve guuid=99fff69e-1700-0000-f305-762b3a0a0000 pid=2618 /usr/bin/bash guuid=31e8bc99-1700-0000-f305-762b210a0000 pid=2593->guuid=99fff69e-1700-0000-f305-762b3a0a0000 pid=2618 clone guuid=d544059f-1700-0000-f305-762b3b0a0000 pid=2619 /usr/bin/bash guuid=31e8bc99-1700-0000-f305-762b210a0000 pid=2593->guuid=d544059f-1700-0000-f305-762b3b0a0000 pid=2619 clone guuid=d0e9629f-1700-0000-f305-762b3f0a0000 pid=2623 /usr/bin/ps guuid=31e8bc99-1700-0000-f305-762b210a0000 pid=2593->guuid=d0e9629f-1700-0000-f305-762b3f0a0000 pid=2623 execve guuid=8971699f-1700-0000-f305-762b400a0000 pid=2624 /usr/bin/mawk guuid=31e8bc99-1700-0000-f305-762b210a0000 pid=2593->guuid=8971699f-1700-0000-f305-762b400a0000 pid=2624 execve guuid=6c477f9f-1700-0000-f305-762b410a0000 pid=2625 /usr/bin/bash guuid=31e8bc99-1700-0000-f305-762b210a0000 pid=2593->guuid=6c477f9f-1700-0000-f305-762b410a0000 pid=2625 clone guuid=01e6fba2-1700-0000-f305-762b4d0a0000 pid=2637 /usr/bin/bash guuid=31e8bc99-1700-0000-f305-762b210a0000 pid=2593->guuid=01e6fba2-1700-0000-f305-762b4d0a0000 pid=2637 clone guuid=b1ab77a6-1700-0000-f305-762b5e0a0000 pid=2654 /usr/bin/bash guuid=31e8bc99-1700-0000-f305-762b210a0000 pid=2593->guuid=b1ab77a6-1700-0000-f305-762b5e0a0000 pid=2654 clone guuid=2dc647a7-1700-0000-f305-762b630a0000 pid=2659 /usr/bin/curl net send-data guuid=31e8bc99-1700-0000-f305-762b210a0000 pid=2593->guuid=2dc647a7-1700-0000-f305-762b630a0000 pid=2659 execve guuid=397e4fa7-1700-0000-f305-762b640a0000 pid=2660 /usr/bin/grep guuid=31e8bc99-1700-0000-f305-762b210a0000 pid=2593->guuid=397e4fa7-1700-0000-f305-762b640a0000 pid=2660 execve guuid=2368dcbd-1700-0000-f305-762ba50a0000 pid=2725 /usr/bin/wget net send-data write-file guuid=31e8bc99-1700-0000-f305-762b210a0000 pid=2593->guuid=2368dcbd-1700-0000-f305-762ba50a0000 pid=2725 execve guuid=faa68ace-1700-0000-f305-762bd30a0000 pid=2771 /usr/bin/chmod guuid=31e8bc99-1700-0000-f305-762b210a0000 pid=2593->guuid=faa68ace-1700-0000-f305-762bd30a0000 pid=2771 execve guuid=07cdccce-1700-0000-f305-762bd50a0000 pid=2773 /home/sandbox/run.sh guuid=31e8bc99-1700-0000-f305-762b210a0000 pid=2593->guuid=07cdccce-1700-0000-f305-762bd50a0000 pid=2773 execve guuid=88ff7d6a-1900-0000-f305-762b8f0d0000 pid=3471 /usr/bin/rm delete-file guuid=31e8bc99-1700-0000-f305-762b210a0000 pid=2593->guuid=88ff7d6a-1900-0000-f305-762b8f0d0000 pid=3471 execve guuid=d544da6a-1900-0000-f305-762b910d0000 pid=3473 /usr/bin/whoami guuid=31e8bc99-1700-0000-f305-762b210a0000 pid=2593->guuid=d544da6a-1900-0000-f305-762b910d0000 pid=3473 execve guuid=edfe3b6b-1900-0000-f305-762b930d0000 pid=3475 /usr/bin/whoami guuid=31e8bc99-1700-0000-f305-762b210a0000 pid=2593->guuid=edfe3b6b-1900-0000-f305-762b930d0000 pid=3475 execve guuid=a416956b-1900-0000-f305-762b950d0000 pid=3477 /usr/bin/whoami guuid=31e8bc99-1700-0000-f305-762b210a0000 pid=2593->guuid=a416956b-1900-0000-f305-762b950d0000 pid=3477 execve guuid=97c9069f-1700-0000-f305-762b3c0a0000 pid=2620 /usr/bin/bash guuid=99fff69e-1700-0000-f305-762b3a0a0000 pid=2618->guuid=97c9069f-1700-0000-f305-762b3c0a0000 pid=2620 clone guuid=c23a08a3-1700-0000-f305-762b4f0a0000 pid=2639 /usr/bin/pgrep guuid=01e6fba2-1700-0000-f305-762b4d0a0000 pid=2637->guuid=c23a08a3-1700-0000-f305-762b4f0a0000 pid=2639 execve guuid=e2490ea3-1700-0000-f305-762b500a0000 pid=2640 /usr/bin/bash guuid=01e6fba2-1700-0000-f305-762b4d0a0000 pid=2637->guuid=e2490ea3-1700-0000-f305-762b500a0000 pid=2640 clone guuid=41dab6a6-1700-0000-f305-762b5f0a0000 pid=2655 /usr/bin/grep guuid=b1ab77a6-1700-0000-f305-762b5e0a0000 pid=2654->guuid=41dab6a6-1700-0000-f305-762b5f0a0000 pid=2655 execve b60edd83-de97-543e-8c12-c815cb088ff2 ip-api.com:80 guuid=2dc647a7-1700-0000-f305-762b630a0000 pid=2659->b60edd83-de97-543e-8c12-c815cb088ff2 send: 79B guuid=2dc647a7-1700-0000-f305-762b630a0000 pid=2671 /usr/bin/curl dns net send-data guuid=2dc647a7-1700-0000-f305-762b630a0000 pid=2659->guuid=2dc647a7-1700-0000-f305-762b630a0000 pid=2671 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=2dc647a7-1700-0000-f305-762b630a0000 pid=2671->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 28B 2f67bf0f-8453-5800-9e7b-37101ce5849f 162.248.53.119:8000 guuid=2368dcbd-1700-0000-f305-762ba50a0000 pid=2725->2f67bf0f-8453-5800-9e7b-37101ce5849f send: 140B guuid=314722cf-1700-0000-f305-762bd60a0000 pid=2774 /usr/bin/systemctl guuid=07cdccce-1700-0000-f305-762bd50a0000 pid=2773->guuid=314722cf-1700-0000-f305-762bd60a0000 pid=2774 execve guuid=a87a1bd2-1700-0000-f305-762bd80a0000 pid=2776 /usr/bin/bash guuid=07cdccce-1700-0000-f305-762bd50a0000 pid=2773->guuid=a87a1bd2-1700-0000-f305-762bd80a0000 pid=2776 clone guuid=e9babed7-1700-0000-f305-762be40a0000 pid=2788 /usr/bin/bash guuid=07cdccce-1700-0000-f305-762bd50a0000 pid=2773->guuid=e9babed7-1700-0000-f305-762be40a0000 pid=2788 clone guuid=80195cd8-1700-0000-f305-762be90a0000 pid=2793 /usr/bin/id guuid=07cdccce-1700-0000-f305-762bd50a0000 pid=2773->guuid=80195cd8-1700-0000-f305-762be90a0000 pid=2793 execve guuid=e3ccb4d8-1700-0000-f305-762beb0a0000 pid=2795 /usr/bin/mkdir guuid=07cdccce-1700-0000-f305-762bd50a0000 pid=2773->guuid=e3ccb4d8-1700-0000-f305-762beb0a0000 pid=2795 execve guuid=82f71fd9-1700-0000-f305-762bed0a0000 pid=2797 /usr/bin/wget dns net send-data write-file guuid=07cdccce-1700-0000-f305-762bd50a0000 pid=2773->guuid=82f71fd9-1700-0000-f305-762bed0a0000 pid=2797 execve guuid=efeae908-1800-0000-f305-762b3d0b0000 pid=2877 /usr/bin/tar write-file guuid=07cdccce-1700-0000-f305-762bd50a0000 pid=2773->guuid=efeae908-1800-0000-f305-762b3d0b0000 pid=2877 execve guuid=3b1aa118-1800-0000-f305-762b680b0000 pid=2920 /usr/bin/mv guuid=07cdccce-1700-0000-f305-762bd50a0000 pid=2773->guuid=3b1aa118-1800-0000-f305-762b680b0000 pid=2920 execve guuid=4ee00c19-1800-0000-f305-762b690b0000 pid=2921 /usr/bin/rm guuid=07cdccce-1700-0000-f305-762bd50a0000 pid=2773->guuid=4ee00c19-1800-0000-f305-762b690b0000 pid=2921 execve guuid=a9886319-1800-0000-f305-762b6a0b0000 pid=2922 /usr/bin/chmod guuid=07cdccce-1700-0000-f305-762bd50a0000 pid=2773->guuid=a9886319-1800-0000-f305-762b6a0b0000 pid=2922 execve guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923 /usr/lib/dev/systemdev/systemd-mont mprotect-exec net send-data guuid=07cdccce-1700-0000-f305-762bd50a0000 pid=2773->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923 execve guuid=8159b419-1800-0000-f305-762b6c0b0000 pid=2924 /usr/bin/sleep guuid=07cdccce-1700-0000-f305-762bd50a0000 pid=2773->guuid=8159b419-1800-0000-f305-762b6c0b0000 pid=2924 execve guuid=c53dcf4a-1800-0000-f305-762bb30b0000 pid=2995 /usr/bin/ps guuid=07cdccce-1700-0000-f305-762bd50a0000 pid=2773->guuid=c53dcf4a-1800-0000-f305-762bb30b0000 pid=2995 execve guuid=dff29256-1800-0000-f305-762bd60b0000 pid=3030 /usr/bin/sleep guuid=07cdccce-1700-0000-f305-762bd50a0000 pid=2773->guuid=dff29256-1800-0000-f305-762bd60b0000 pid=3030 execve guuid=8186db63-1900-0000-f305-762b7f0d0000 pid=3455 /usr/bin/ps guuid=07cdccce-1700-0000-f305-762bd50a0000 pid=2773->guuid=8186db63-1900-0000-f305-762b7f0d0000 pid=3455 execve guuid=6fa1c169-1900-0000-f305-762b8a0d0000 pid=3466 /usr/bin/rm guuid=07cdccce-1700-0000-f305-762bd50a0000 pid=2773->guuid=6fa1c169-1900-0000-f305-762b8a0d0000 pid=3466 execve guuid=e8901b6a-1900-0000-f305-762b8d0d0000 pid=3469 /usr/bin/rm guuid=07cdccce-1700-0000-f305-762bd50a0000 pid=2773->guuid=e8901b6a-1900-0000-f305-762b8d0d0000 pid=3469 execve guuid=540129d2-1700-0000-f305-762bd90a0000 pid=2777 /usr/bin/wget dns net send-data guuid=a87a1bd2-1700-0000-f305-762bd80a0000 pid=2776->guuid=540129d2-1700-0000-f305-762bd90a0000 pid=2777 execve guuid=540129d2-1700-0000-f305-762bd90a0000 pid=2777->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B 0690ccd5-4816-5f11-94dc-7c585f38cdea ipv4.icanhazip.com:0 guuid=540129d2-1700-0000-f305-762bd90a0000 pid=2777->0690ccd5-4816-5f11-94dc-7c585f38cdea con d0ecfe49-aa79-583f-85c6-85ac97075256 ipv4.icanhazip.com:80 guuid=540129d2-1700-0000-f305-762bd90a0000 pid=2777->d0ecfe49-aa79-583f-85c6-85ac97075256 send: 133B guuid=656dcdd7-1700-0000-f305-762be50a0000 pid=2789 /usr/bin/bash guuid=e9babed7-1700-0000-f305-762be40a0000 pid=2788->guuid=656dcdd7-1700-0000-f305-762be50a0000 pid=2789 clone guuid=7577d6d7-1700-0000-f305-762be60a0000 pid=2790 /usr/bin/sed guuid=e9babed7-1700-0000-f305-762be40a0000 pid=2788->guuid=7577d6d7-1700-0000-f305-762be60a0000 pid=2790 execve guuid=f26eddd7-1700-0000-f305-762be70a0000 pid=2791 /usr/bin/cut guuid=e9babed7-1700-0000-f305-762be40a0000 pid=2788->guuid=f26eddd7-1700-0000-f305-762be70a0000 pid=2791 execve guuid=82f71fd9-1700-0000-f305-762bed0a0000 pid=2797->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 164B 75aab096-419b-50ef-be46-7d76b6a90e4c github.com:443 guuid=82f71fd9-1700-0000-f305-762bed0a0000 pid=2797->75aab096-419b-50ef-be46-7d76b6a90e4c send: 802B f8c5e44f-328d-5324-8bbd-da50752b9120 release-assets.githubusercontent.com:0 guuid=82f71fd9-1700-0000-f305-762bed0a0000 pid=2797->f8c5e44f-328d-5324-8bbd-da50752b9120 con f0eebea5-e97d-507c-a771-59cac353877c release-assets.githubusercontent.com:443 guuid=82f71fd9-1700-0000-f305-762bed0a0000 pid=2797->f0eebea5-e97d-507c-a771-59cac353877c send: 1664B guuid=99f03609-1800-0000-f305-762b3f0b0000 pid=2879 /usr/bin/gzip guuid=efeae908-1800-0000-f305-762b3d0b0000 pid=2877->guuid=99f03609-1800-0000-f305-762b3f0b0000 pid=2879 execve 27958174-7cd5-58aa-a656-dcfbbd6ab520 51.178.73.238:9118 guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->27958174-7cd5-58aa-a656-dcfbbd6ab520 send: 561B guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2929 /usr/lib/dev/systemdev/systemd-mont write-file zombie guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2929 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2930 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2930 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2932 /usr/lib/dev/systemdev/systemd-mont send-data guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2932 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2933 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2933 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2934 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2934 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2940 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2940 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2941 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2941 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2942 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2942 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2943 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2943 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2959 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2959 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2961 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2961 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2962 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2962 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2963 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2963 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2967 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2967 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2968 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2968 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2969 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2969 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2970 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2970 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2984 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2984 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2985 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2985 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2986 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2986 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2987 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2987 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3003 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3003 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3004 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3004 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3005 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3005 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3006 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3006 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3018 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3018 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3019 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3019 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3020 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3020 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3021 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3021 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3041 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3041 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3042 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3042 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3043 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3043 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3044 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3044 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3059 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3059 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3060 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3060 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3061 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3061 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3062 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3062 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3081 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3081 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3082 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3082 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3083 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3083 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3084 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3084 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3110 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3110 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3111 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3111 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3112 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3112 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3113 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3113 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3141 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3141 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3142 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3142 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3143 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3143 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3144 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3144 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3164 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3164 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3165 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3165 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3166 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3166 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3167 /usr/lib/dev/systemdev/systemd-mont guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2923->guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=3167 clone guuid=2c89a919-1800-0000-f305-762b6b0b0000 pid=2932->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 80B
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2025-08-01 17:44:23 UTC
File Type:
Text (Shell)
AV detection:
7 of 23 (30.43%)
Threat level:
  5/5
Result
Malware family:
xmrig_linux
Score:
  10/10
Tags:
family:xmrig family:xmrig_linux antivm defense_evasion discovery execution linux miner persistence privilege_escalation upx
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads CPU attributes
UPX packed file
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Enumerates running processes
Looks up external IP address via web service
Reads hardware information
File and Directory Permissions Modification
Executes dropped EXE
XMRig Miner payload
Xmrig family
Xmrig_linux family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments