MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9935f0b2d2eb492252ef523222201b2cb3ad5dd7a73c34d1d952909f7da66d46. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 9935f0b2d2eb492252ef523222201b2cb3ad5dd7a73c34d1d952909f7da66d46
SHA3-384 hash: ff8c9ddf2dea40e93d14144729e943a0bd15b37d72d177c010e3cee77da8712f7555676db98cdf88413ae193163ecc01
SHA1 hash: 185d32cef77324ccdf4d41e765ef0d159b8f7e9b
MD5 hash: f5cba15a697198f6bd7071742e898103
humanhash: romeo-uranus-vegan-lactose
File name:sh
Download: download sample
Signature CoinMiner
File size:2'279 bytes
First seen:2025-07-14 23:20:10 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vkwvpihneZZn1oBlyeLnltonmzEvJGU6ljiPq2MTCki:vkwYheZZK6eD2mzIj6K
TLSH T1774146BAB4628E3033ACC5F875856548A34786AF492B5EB4F083B83C37BC35470B47A5
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
http://66.63.187.193/n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
35
Origin country :
DE DE
Vendor Threat Intelligence
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2025-07-14 23:20:30 UTC
File Type:
Text (Shell)
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:xmrig antivm defense_evasion discovery linux miner persistence privilege_escalation upx
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads CPU attributes
UPX packed file
Reads AppArmor ptrace settings
Attempts to change immutable files
Checks hardware identifiers (DMI)
Enumerates running processes
Modifies systemd
Reads hardware information
Reads network interface configuration
File and Directory Permissions Modification
Creates Raw socket
Executes dropped EXE
Flushes firewall rules
Unexpected DNS network traffic destination
Contacts a large (1740591) amount of remote hosts
Creates a large amount of network flows
XMRig Miner payload
Xmrig family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CoinMiner

sh 9935f0b2d2eb492252ef523222201b2cb3ad5dd7a73c34d1d952909f7da66d46

(this sample)

  
Delivery method
Distributed via web download

Comments