MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8406aec7d259f209128df3f47514031fbeba1630df9209de78ed5bfb1952f16b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 8406aec7d259f209128df3f47514031fbeba1630df9209de78ed5bfb1952f16b
SHA3-384 hash: eaa1ab059510d642a76dec0c19fef6eb4f58e2ffcecdedb56a9418032cffab135c0a89b3bee96c4b47d8e51b65d3ca5f
SHA1 hash: 84ddd62dd2989c3974ebc434bc34d212ccbe5885
MD5 hash: baa8d4dd8011c8f96ae12b8a57f31b9c
humanhash: nine-uncle-red-two
File name:mon.sh
Download: download sample
Signature CoinMiner
File size:4'629 bytes
First seen:2025-07-11 11:56:16 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:l06z0cic27UP7DTAiVjDAmx793jt0yjtgmu4IL1Sd6z0cd:l080c9iUzDNjdd935XvIL1Sd80cd
TLSH T1F9A1734AF690CAB0389DC1A8A99B6485290642875E041D1DF82EF4987F5479C71F87EF
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.248.53.119:8000/mon.sh1e891ab1521b27923233e694f60fdbf0e1b840e657d8b1ffdefd8b5ef5e38964 CoinMinerCoinMiner
http://ip-api.com/json/n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
33
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
fingerprint
Status:
terminated
Behavior Graph:
%3 guuid=df436235-1a00-0000-12ab-3fb4fd0b0000 pid=3069 /usr/bin/sudo guuid=ec890837-1a00-0000-12ab-3fb4020c0000 pid=3074 /tmp/sample.bin guuid=df436235-1a00-0000-12ab-3fb4fd0b0000 pid=3069->guuid=ec890837-1a00-0000-12ab-3fb4020c0000 pid=3074 execve guuid=e28b5237-1a00-0000-12ab-3fb4050c0000 pid=3077 /usr/bin/whoami guuid=ec890837-1a00-0000-12ab-3fb4020c0000 pid=3074->guuid=e28b5237-1a00-0000-12ab-3fb4050c0000 pid=3077 execve guuid=eeaa1638-1a00-0000-12ab-3fb4070c0000 pid=3079 /usr/bin/whoami guuid=ec890837-1a00-0000-12ab-3fb4020c0000 pid=3074->guuid=eeaa1638-1a00-0000-12ab-3fb4070c0000 pid=3079 execve guuid=07c88438-1a00-0000-12ab-3fb4080c0000 pid=3080 /usr/bin/whoami guuid=ec890837-1a00-0000-12ab-3fb4020c0000 pid=3074->guuid=07c88438-1a00-0000-12ab-3fb4080c0000 pid=3080 execve guuid=e0b80e39-1a00-0000-12ab-3fb4090c0000 pid=3081 /usr/bin/bash guuid=ec890837-1a00-0000-12ab-3fb4020c0000 pid=3074->guuid=e0b80e39-1a00-0000-12ab-3fb4090c0000 pid=3081 clone guuid=f1863b39-1a00-0000-12ab-3fb40a0c0000 pid=3082 /usr/bin/id guuid=ec890837-1a00-0000-12ab-3fb4020c0000 pid=3074->guuid=f1863b39-1a00-0000-12ab-3fb40a0c0000 pid=3082 execve guuid=b1feec39-1a00-0000-12ab-3fb40b0c0000 pid=3083 /usr/bin/systemctl guuid=ec890837-1a00-0000-12ab-3fb4020c0000 pid=3074->guuid=b1feec39-1a00-0000-12ab-3fb40b0c0000 pid=3083 execve guuid=da20f73c-1a00-0000-12ab-3fb4140c0000 pid=3092 /usr/bin/bash guuid=ec890837-1a00-0000-12ab-3fb4020c0000 pid=3074->guuid=da20f73c-1a00-0000-12ab-3fb4140c0000 pid=3092 clone guuid=723e0d3d-1a00-0000-12ab-3fb4150c0000 pid=3093 /usr/bin/grep guuid=ec890837-1a00-0000-12ab-3fb4020c0000 pid=3074->guuid=723e0d3d-1a00-0000-12ab-3fb4150c0000 pid=3093 execve guuid=e9dbd13d-1a00-0000-12ab-3fb4170c0000 pid=3095 /usr/bin/bash guuid=ec890837-1a00-0000-12ab-3fb4020c0000 pid=3074->guuid=e9dbd13d-1a00-0000-12ab-3fb4170c0000 pid=3095 clone guuid=77b3d93d-1a00-0000-12ab-3fb4190c0000 pid=3097 /usr/bin/bash guuid=ec890837-1a00-0000-12ab-3fb4020c0000 pid=3074->guuid=77b3d93d-1a00-0000-12ab-3fb4190c0000 pid=3097 clone guuid=f1cc0e3e-1a00-0000-12ab-3fb41b0c0000 pid=3099 /usr/bin/ps guuid=ec890837-1a00-0000-12ab-3fb4020c0000 pid=3074->guuid=f1cc0e3e-1a00-0000-12ab-3fb41b0c0000 pid=3099 execve guuid=6581153e-1a00-0000-12ab-3fb41c0c0000 pid=3100 /usr/bin/mawk guuid=ec890837-1a00-0000-12ab-3fb4020c0000 pid=3074->guuid=6581153e-1a00-0000-12ab-3fb41c0c0000 pid=3100 execve guuid=cac01a3e-1a00-0000-12ab-3fb41d0c0000 pid=3101 /usr/bin/bash guuid=ec890837-1a00-0000-12ab-3fb4020c0000 pid=3074->guuid=cac01a3e-1a00-0000-12ab-3fb41d0c0000 pid=3101 clone guuid=6519c943-1a00-0000-12ab-3fb42a0c0000 pid=3114 /usr/bin/bash guuid=ec890837-1a00-0000-12ab-3fb4020c0000 pid=3074->guuid=6519c943-1a00-0000-12ab-3fb42a0c0000 pid=3114 clone guuid=c6e52847-1a00-0000-12ab-3fb4350c0000 pid=3125 /usr/bin/curl net send-data guuid=ec890837-1a00-0000-12ab-3fb4020c0000 pid=3074->guuid=c6e52847-1a00-0000-12ab-3fb4350c0000 pid=3125 execve guuid=b8733547-1a00-0000-12ab-3fb4360c0000 pid=3126 /usr/bin/grep guuid=ec890837-1a00-0000-12ab-3fb4020c0000 pid=3074->guuid=b8733547-1a00-0000-12ab-3fb4360c0000 pid=3126 execve guuid=ff9b2f57-1a00-0000-12ab-3fb4600c0000 pid=3168 /usr/bin/wget net send-data write-file guuid=ec890837-1a00-0000-12ab-3fb4020c0000 pid=3074->guuid=ff9b2f57-1a00-0000-12ab-3fb4600c0000 pid=3168 execve guuid=fcb1ce67-1a00-0000-12ab-3fb47b0c0000 pid=3195 /usr/bin/chmod guuid=ec890837-1a00-0000-12ab-3fb4020c0000 pid=3074->guuid=fcb1ce67-1a00-0000-12ab-3fb47b0c0000 pid=3195 execve guuid=5ca73068-1a00-0000-12ab-3fb47c0c0000 pid=3196 /home/sandbox/run.sh guuid=ec890837-1a00-0000-12ab-3fb4020c0000 pid=3074->guuid=5ca73068-1a00-0000-12ab-3fb47c0c0000 pid=3196 execve guuid=b1c70011-1c00-0000-12ab-3fb4a10f0000 pid=4001 /usr/bin/rm delete-file guuid=ec890837-1a00-0000-12ab-3fb4020c0000 pid=3074->guuid=b1c70011-1c00-0000-12ab-3fb4a10f0000 pid=4001 execve guuid=e8fe7011-1c00-0000-12ab-3fb4a30f0000 pid=4003 /usr/bin/whoami guuid=ec890837-1a00-0000-12ab-3fb4020c0000 pid=3074->guuid=e8fe7011-1c00-0000-12ab-3fb4a30f0000 pid=4003 execve guuid=f4e2e111-1c00-0000-12ab-3fb4a40f0000 pid=4004 /usr/bin/whoami guuid=ec890837-1a00-0000-12ab-3fb4020c0000 pid=3074->guuid=f4e2e111-1c00-0000-12ab-3fb4a40f0000 pid=4004 execve guuid=593e4e12-1c00-0000-12ab-3fb4a60f0000 pid=4006 /usr/bin/whoami guuid=ec890837-1a00-0000-12ab-3fb4020c0000 pid=3074->guuid=593e4e12-1c00-0000-12ab-3fb4a60f0000 pid=4006 execve guuid=287cde3d-1a00-0000-12ab-3fb41a0c0000 pid=3098 /usr/bin/bash guuid=e9dbd13d-1a00-0000-12ab-3fb4170c0000 pid=3095->guuid=287cde3d-1a00-0000-12ab-3fb41a0c0000 pid=3098 clone guuid=8c8bd743-1a00-0000-12ab-3fb42b0c0000 pid=3115 /usr/bin/pgrep guuid=6519c943-1a00-0000-12ab-3fb42a0c0000 pid=3114->guuid=8c8bd743-1a00-0000-12ab-3fb42b0c0000 pid=3115 execve guuid=c2a9e443-1a00-0000-12ab-3fb42c0c0000 pid=3116 /usr/bin/bash guuid=6519c943-1a00-0000-12ab-3fb42a0c0000 pid=3114->guuid=c2a9e443-1a00-0000-12ab-3fb42c0c0000 pid=3116 clone b60edd83-de97-543e-8c12-c815cb088ff2 ip-api.com:80 guuid=c6e52847-1a00-0000-12ab-3fb4350c0000 pid=3125->b60edd83-de97-543e-8c12-c815cb088ff2 send: 79B guuid=c6e52847-1a00-0000-12ab-3fb4350c0000 pid=3135 /usr/bin/curl dns net send-data guuid=c6e52847-1a00-0000-12ab-3fb4350c0000 pid=3125->guuid=c6e52847-1a00-0000-12ab-3fb4350c0000 pid=3135 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=c6e52847-1a00-0000-12ab-3fb4350c0000 pid=3135->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 28B 2f67bf0f-8453-5800-9e7b-37101ce5849f 162.248.53.119:8000 guuid=ff9b2f57-1a00-0000-12ab-3fb4600c0000 pid=3168->2f67bf0f-8453-5800-9e7b-37101ce5849f send: 140B guuid=8affe868-1a00-0000-12ab-3fb47d0c0000 pid=3197 /usr/bin/systemctl guuid=5ca73068-1a00-0000-12ab-3fb47c0c0000 pid=3196->guuid=8affe868-1a00-0000-12ab-3fb47d0c0000 pid=3197 execve guuid=f7a3d96a-1a00-0000-12ab-3fb47e0c0000 pid=3198 /usr/bin/bash guuid=5ca73068-1a00-0000-12ab-3fb47c0c0000 pid=3196->guuid=f7a3d96a-1a00-0000-12ab-3fb47e0c0000 pid=3198 clone guuid=6ef70073-1a00-0000-12ab-3fb4800c0000 pid=3200 /usr/bin/bash guuid=5ca73068-1a00-0000-12ab-3fb47c0c0000 pid=3196->guuid=6ef70073-1a00-0000-12ab-3fb4800c0000 pid=3200 clone guuid=b0ad5b74-1a00-0000-12ab-3fb4840c0000 pid=3204 /usr/bin/id guuid=5ca73068-1a00-0000-12ab-3fb47c0c0000 pid=3196->guuid=b0ad5b74-1a00-0000-12ab-3fb4840c0000 pid=3204 execve guuid=3934bb74-1a00-0000-12ab-3fb4850c0000 pid=3205 /usr/bin/mkdir guuid=5ca73068-1a00-0000-12ab-3fb47c0c0000 pid=3196->guuid=3934bb74-1a00-0000-12ab-3fb4850c0000 pid=3205 execve guuid=3ff33675-1a00-0000-12ab-3fb4860c0000 pid=3206 /usr/bin/wget dns net send-data write-file guuid=5ca73068-1a00-0000-12ab-3fb47c0c0000 pid=3196->guuid=3ff33675-1a00-0000-12ab-3fb4860c0000 pid=3206 execve guuid=f68d50c2-1a00-0000-12ab-3fb4e00c0000 pid=3296 /usr/bin/tar write-file guuid=5ca73068-1a00-0000-12ab-3fb47c0c0000 pid=3196->guuid=f68d50c2-1a00-0000-12ab-3fb4e00c0000 pid=3296 execve guuid=6b8795d3-1a00-0000-12ab-3fb4040d0000 pid=3332 /usr/bin/mv guuid=5ca73068-1a00-0000-12ab-3fb47c0c0000 pid=3196->guuid=6b8795d3-1a00-0000-12ab-3fb4040d0000 pid=3332 execve guuid=bc1546d4-1a00-0000-12ab-3fb4050d0000 pid=3333 /usr/bin/rm guuid=5ca73068-1a00-0000-12ab-3fb47c0c0000 pid=3196->guuid=bc1546d4-1a00-0000-12ab-3fb4050d0000 pid=3333 execve guuid=8084d1d4-1a00-0000-12ab-3fb4070d0000 pid=3335 /usr/bin/chmod guuid=5ca73068-1a00-0000-12ab-3fb47c0c0000 pid=3196->guuid=8084d1d4-1a00-0000-12ab-3fb4070d0000 pid=3335 execve guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336 /usr/lib/dev/systemdev/systemd-mont mprotect-exec net send-data guuid=5ca73068-1a00-0000-12ab-3fb47c0c0000 pid=3196->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336 execve guuid=3b0cafd5-1a00-0000-12ab-3fb4090d0000 pid=3337 /usr/bin/sleep guuid=5ca73068-1a00-0000-12ab-3fb47c0c0000 pid=3196->guuid=3b0cafd5-1a00-0000-12ab-3fb4090d0000 pid=3337 execve guuid=29122ff4-1a00-0000-12ab-3fb4530d0000 pid=3411 /usr/bin/ps guuid=5ca73068-1a00-0000-12ab-3fb47c0c0000 pid=3196->guuid=29122ff4-1a00-0000-12ab-3fb4530d0000 pid=3411 execve guuid=8db4d4fc-1a00-0000-12ab-3fb46d0d0000 pid=3437 /usr/bin/sleep guuid=5ca73068-1a00-0000-12ab-3fb47c0c0000 pid=3196->guuid=8db4d4fc-1a00-0000-12ab-3fb46d0d0000 pid=3437 execve guuid=d5d16f09-1c00-0000-12ab-3fb4850f0000 pid=3973 /usr/bin/ps guuid=5ca73068-1a00-0000-12ab-3fb47c0c0000 pid=3196->guuid=d5d16f09-1c00-0000-12ab-3fb4850f0000 pid=3973 execve guuid=ecc23610-1c00-0000-12ab-3fb49d0f0000 pid=3997 /usr/bin/rm guuid=5ca73068-1a00-0000-12ab-3fb47c0c0000 pid=3196->guuid=ecc23610-1c00-0000-12ab-3fb49d0f0000 pid=3997 execve guuid=75e49810-1c00-0000-12ab-3fb49f0f0000 pid=3999 /usr/bin/rm guuid=5ca73068-1a00-0000-12ab-3fb47c0c0000 pid=3196->guuid=75e49810-1c00-0000-12ab-3fb49f0f0000 pid=3999 execve guuid=423cf16a-1a00-0000-12ab-3fb47f0c0000 pid=3199 /usr/bin/wget dns net send-data guuid=f7a3d96a-1a00-0000-12ab-3fb47e0c0000 pid=3198->guuid=423cf16a-1a00-0000-12ab-3fb47f0c0000 pid=3199 execve guuid=423cf16a-1a00-0000-12ab-3fb47f0c0000 pid=3199->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B 0690ccd5-4816-5f11-94dc-7c585f38cdea ipv4.icanhazip.com:0 guuid=423cf16a-1a00-0000-12ab-3fb47f0c0000 pid=3199->0690ccd5-4816-5f11-94dc-7c585f38cdea con d0ecfe49-aa79-583f-85c6-85ac97075256 ipv4.icanhazip.com:80 guuid=423cf16a-1a00-0000-12ab-3fb47f0c0000 pid=3199->d0ecfe49-aa79-583f-85c6-85ac97075256 send: 133B guuid=16d63e73-1a00-0000-12ab-3fb4810c0000 pid=3201 /usr/bin/bash guuid=6ef70073-1a00-0000-12ab-3fb4800c0000 pid=3200->guuid=16d63e73-1a00-0000-12ab-3fb4810c0000 pid=3201 clone guuid=04646b73-1a00-0000-12ab-3fb4820c0000 pid=3202 /usr/bin/sed guuid=6ef70073-1a00-0000-12ab-3fb4800c0000 pid=3200->guuid=04646b73-1a00-0000-12ab-3fb4820c0000 pid=3202 execve guuid=7e118573-1a00-0000-12ab-3fb4830c0000 pid=3203 /usr/bin/cut guuid=6ef70073-1a00-0000-12ab-3fb4800c0000 pid=3200->guuid=7e118573-1a00-0000-12ab-3fb4830c0000 pid=3203 execve guuid=3ff33675-1a00-0000-12ab-3fb4860c0000 pid=3206->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 150B 75aab096-419b-50ef-be46-7d76b6a90e4c github.com:443 guuid=3ff33675-1a00-0000-12ab-3fb4860c0000 pid=3206->75aab096-419b-50ef-be46-7d76b6a90e4c send: 802B a13b061a-f048-5755-ac95-a8265477be45 objects.githubusercontent.com:0 guuid=3ff33675-1a00-0000-12ab-3fb4860c0000 pid=3206->a13b061a-f048-5755-ac95-a8265477be45 con 06a44d09-e679-52bb-9c81-7632368ac4a3 objects.githubusercontent.com:443 guuid=3ff33675-1a00-0000-12ab-3fb4860c0000 pid=3206->06a44d09-e679-52bb-9c81-7632368ac4a3 send: 1242B guuid=fa8ce8c2-1a00-0000-12ab-3fb4e30c0000 pid=3299 /usr/bin/gzip guuid=f68d50c2-1a00-0000-12ab-3fb4e00c0000 pid=3296->guuid=fa8ce8c2-1a00-0000-12ab-3fb4e30c0000 pid=3299 execve 27958174-7cd5-58aa-a656-dcfbbd6ab520 51.178.73.238:9118 guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->27958174-7cd5-58aa-a656-dcfbbd6ab520 send: 561B guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3348 /usr/lib/dev/systemdev/systemd-mont write-file zombie guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3348 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3350 /usr/lib/dev/systemdev/systemd-mont send-data guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3350 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3351 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3351 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3352 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3352 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3353 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3353 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3367 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3367 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3368 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3368 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3370 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3370 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3371 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3371 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3372 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3372 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3373 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3373 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3374 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3374 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3375 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3375 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3377 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3377 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3378 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3378 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3379 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3379 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3380 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3380 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3397 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3397 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3398 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3398 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3400 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3400 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3401 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3401 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3419 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3419 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3420 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3420 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3421 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3421 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3422 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3422 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3432 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3432 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3433 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3433 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3434 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3434 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3435 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3435 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3457 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3457 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3458 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3458 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3459 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3459 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3460 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3460 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3478 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3478 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3479 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3479 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3480 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3480 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3481 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3481 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3495 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3495 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3496 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3496 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3497 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3497 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3498 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3498 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3523 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3523 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3524 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3524 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3525 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3525 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3526 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3526 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3545 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3545 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3546 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3546 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3547 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3547 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3548 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3548 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3566 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3566 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3567 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3567 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3568 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3568 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3569 /usr/lib/dev/systemdev/systemd-mont guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3336->guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3569 clone guuid=3e5989d5-1a00-0000-12ab-3fb4080d0000 pid=3350->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 80B
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2025-07-11 11:57:25 UTC
File Type:
Text (Shell)
AV detection:
4 of 38 (10.53%)
Threat level:
  5/5
Result
Malware family:
xmrig_linux
Score:
  10/10
Tags:
family:xmrig family:xmrig_linux antivm defense_evasion discovery execution linux miner persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads CPU attributes
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Enumerates running processes
Looks up external IP address via web service
Reads hardware information
File and Directory Permissions Modification
Executes dropped EXE
XMRig Miner payload
Xmrig family
Xmrig_linux family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments