🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 88ef20d6ef76a46c70a2a29f41a91cdb95408902ff4ca778ff248ec78ff122df. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 88ef20d6ef76a46c70a2a29f41a91cdb95408902ff4ca778ff248ec78ff122df
SHA3-384 hash: 0dda8bf9cf5f7e4c0402121217c1bf362dc5489d57b132031b322c607cae3b610bed02e731667c44afa211c06e9f5a1a
SHA1 hash: fcd06f69e557e8859e9216cad4b8f0c3e01ba29b
MD5 hash: 0d123b27b962cb9559c97ebab9e9658a
humanhash: saturn-saturn-delta-bakerloo
File name:check1.sh
Download: download sample
Signature CoinMiner
File size:986 bytes
First seen:2026-10-02 23:48:00 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:VUeYj+H1JAEDMK9CFdYhEnHQBYw9I5dApMApARiJ83AnQZaZl1cSRs/:VUeYj+H1JjDMK9CnYhEYSeMeuiJ8wOjJ
TLSH T17F1192815626AC762CDC811D72E6945E5042022F065F3F9CB8DEA8B70F5C540F0A0BB4
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139.211/check1.sh88ef20d6ef76a46c70a2a29f41a91cdb95408902ff4ca778ff248ec78ff122df CoinMinercensys CoinMiner sh ua-wget
http://176.65.139.211/Error84n/an/acensys elf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
bash lolbin
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-10-02T21:20:00Z UTC
Last seen:
2026-10-03T18:58:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=c59f7caa-1900-0000-217f-d941350d0000 pid=3381 /usr/bin/sudo guuid=a619e8ae-1900-0000-217f-d9413b0d0000 pid=3387 /tmp/sample.bin guuid=c59f7caa-1900-0000-217f-d941350d0000 pid=3381->guuid=a619e8ae-1900-0000-217f-d9413b0d0000 pid=3387 execve guuid=efea88af-1900-0000-217f-d9413c0d0000 pid=3388 /usr/bin/bash guuid=a619e8ae-1900-0000-217f-d9413b0d0000 pid=3387->guuid=efea88af-1900-0000-217f-d9413c0d0000 pid=3388 clone guuid=11be8faf-1900-0000-217f-d9413e0d0000 pid=3390 /usr/bin/grep guuid=a619e8ae-1900-0000-217f-d9413b0d0000 pid=3387->guuid=11be8faf-1900-0000-217f-d9413e0d0000 pid=3390 execve guuid=4f5602b0-1900-0000-217f-d941400d0000 pid=3392 /usr/bin/bash guuid=a619e8ae-1900-0000-217f-d9413b0d0000 pid=3387->guuid=4f5602b0-1900-0000-217f-d941400d0000 pid=3392 clone guuid=d4ec06b0-1900-0000-217f-d941410d0000 pid=3393 /usr/bin/bash guuid=a619e8ae-1900-0000-217f-d9413b0d0000 pid=3387->guuid=d4ec06b0-1900-0000-217f-d941410d0000 pid=3393 clone guuid=a95f6db0-1900-0000-217f-d941430d0000 pid=3395 /usr/bin/pgrep guuid=a619e8ae-1900-0000-217f-d9413b0d0000 pid=3387->guuid=a95f6db0-1900-0000-217f-d941430d0000 pid=3395 execve guuid=4aff10b8-1900-0000-217f-d941490d0000 pid=3401 /usr/bin/rm delete-file guuid=a619e8ae-1900-0000-217f-d9413b0d0000 pid=3387->guuid=4aff10b8-1900-0000-217f-d941490d0000 pid=3401 execve guuid=97c14fc1-1900-0000-217f-d9415e0d0000 pid=3422 /usr/bin/sleep guuid=a619e8ae-1900-0000-217f-d9413b0d0000 pid=3387->guuid=97c14fc1-1900-0000-217f-d9415e0d0000 pid=3422 execve guuid=33c4f1eb-1a00-0000-217f-d941890f0000 pid=3977 /usr/bin/curl net send-data write-file guuid=a619e8ae-1900-0000-217f-d9413b0d0000 pid=3387->guuid=33c4f1eb-1a00-0000-217f-d941890f0000 pid=3977 execve guuid=acf081ff-1a00-0000-217f-d9418a0f0000 pid=3978 /usr/bin/wget net send-data write-file guuid=a619e8ae-1900-0000-217f-d9413b0d0000 pid=3387->guuid=acf081ff-1a00-0000-217f-d9418a0f0000 pid=3978 execve guuid=a92eac2d-1b00-0000-217f-d9419b0f0000 pid=3995 /usr/bin/sleep guuid=a619e8ae-1900-0000-217f-d9413b0d0000 pid=3387->guuid=a92eac2d-1b00-0000-217f-d9419b0f0000 pid=3995 execve guuid=f15c781c-1c00-0000-217f-d9419c0f0000 pid=3996 /usr/bin/chmod guuid=a619e8ae-1900-0000-217f-d9413b0d0000 pid=3387->guuid=f15c781c-1c00-0000-217f-d9419c0f0000 pid=3996 execve guuid=2ebbe51c-1c00-0000-217f-d9419d0f0000 pid=3997 /usr/bin/bash guuid=a619e8ae-1900-0000-217f-d9413b0d0000 pid=3387->guuid=2ebbe51c-1c00-0000-217f-d9419d0f0000 pid=3997 clone guuid=3101fa1c-1c00-0000-217f-d9419f0f0000 pid=3999 /usr/bin/rm guuid=a619e8ae-1900-0000-217f-d9413b0d0000 pid=3387->guuid=3101fa1c-1c00-0000-217f-d9419f0f0000 pid=3999 execve guuid=885a3d1d-1c00-0000-217f-d941a00f0000 pid=4000 /usr/bin/sleep guuid=a619e8ae-1900-0000-217f-d9413b0d0000 pid=3387->guuid=885a3d1d-1c00-0000-217f-d941a00f0000 pid=4000 execve guuid=0cd49347-1d00-0000-217f-d941a10f0000 pid=4001 /usr/bin/rm guuid=a619e8ae-1900-0000-217f-d9413b0d0000 pid=3387->guuid=0cd49347-1d00-0000-217f-d941a10f0000 pid=4001 execve guuid=5ccbde47-1d00-0000-217f-d941a20f0000 pid=4002 /usr/bin/rm delete-file guuid=a619e8ae-1900-0000-217f-d9413b0d0000 pid=3387->guuid=5ccbde47-1d00-0000-217f-d941a20f0000 pid=4002 execve guuid=97553048-1d00-0000-217f-d941a30f0000 pid=4003 /usr/bin/rm delete-file guuid=a619e8ae-1900-0000-217f-d9413b0d0000 pid=3387->guuid=97553048-1d00-0000-217f-d941a30f0000 pid=4003 execve guuid=849b7948-1d00-0000-217f-d941a40f0000 pid=4004 /usr/bin/rm delete-file guuid=a619e8ae-1900-0000-217f-d9413b0d0000 pid=3387->guuid=849b7948-1d00-0000-217f-d941a40f0000 pid=4004 execve guuid=de3bc648-1d00-0000-217f-d941a50f0000 pid=4005 /usr/bin/rm delete-file guuid=a619e8ae-1900-0000-217f-d9413b0d0000 pid=3387->guuid=de3bc648-1d00-0000-217f-d941a50f0000 pid=4005 execve guuid=b32d1949-1d00-0000-217f-d941a60f0000 pid=4006 /usr/bin/rm guuid=a619e8ae-1900-0000-217f-d9413b0d0000 pid=3387->guuid=b32d1949-1d00-0000-217f-d941a60f0000 pid=4006 execve guuid=067e6149-1d00-0000-217f-d941a70f0000 pid=4007 /usr/bin/clear guuid=a619e8ae-1900-0000-217f-d9413b0d0000 pid=3387->guuid=067e6149-1d00-0000-217f-d941a70f0000 pid=4007 execve guuid=0b921fb0-1900-0000-217f-d941420d0000 pid=3394 /usr/bin/bash guuid=4f5602b0-1900-0000-217f-d941400d0000 pid=3392->guuid=0b921fb0-1900-0000-217f-d941420d0000 pid=3394 clone 0eae001c-4ad4-599c-ab6a-77d3fac12203 176.65.139.211:80 guuid=33c4f1eb-1a00-0000-217f-d941890f0000 pid=3977->0eae001c-4ad4-599c-ab6a-77d3fac12203 send: 85B guuid=acf081ff-1a00-0000-217f-d9418a0f0000 pid=3978->0eae001c-4ad4-599c-ab6a-77d3fac12203 send: 136B
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-10-02 23:48:13 UTC
File Type:
Text (Shell)
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:xmrig antivm defense_evasion discovery execution linux miner persistence privilege_escalation
Behaviour
Reads runtime system information
Checks CPU configuration
Reads CPU attributes
Creates/modifies Cron job
Deletes log files
Enumerates running processes
File and Directory Permissions Modification
Indicator Removal: Clear Command History
Executes dropped EXE
Family: xmrig
XMRig Miner payload
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:LIN_Sample_Unique_586960df
Author:Marjoriefort
Description:Specimen unique (soumission Bazaar) - strings distinctifs propres au sample
Reference:586960df8bf559ffbba600f11917a99baed4a875cb7faa5eabc060bcde67277b.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CoinMiner

sh 88ef20d6ef76a46c70a2a29f41a91cdb95408902ff4ca778ff248ec78ff122df

(this sample)

  
Delivery method
Distributed via web download

Comments