MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9bbb4b428b34a0ce31da7183bf4a20f48a5a5639d4acf7afb7bd1d0a4205e098. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 11


Intelligence 11 IOCs YARA 16 File information Comments

SHA256 hash: 9bbb4b428b34a0ce31da7183bf4a20f48a5a5639d4acf7afb7bd1d0a4205e098
SHA3-384 hash: d92333a7ebe090fa342bd127c4ae5b31219f4061b2f853d0070d3e6cdf6b0931e0603aedb6c550703461ca9d88b38acb
SHA1 hash: 91dc840927011260b243ad7619bf63d65293ac21
MD5 hash: ed234e65a87f7ecd03727981c841bbfa
humanhash: wisconsin-east-november-carpet
File name:63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e
Download: download sample
Signature CoinMiner
File size:5'195'856 bytes
First seen:2026-07-22 23:31:48 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 98304:+jbh6zwjVQMJwkLH3M9YmbOB/KvDVaNOKbKz3naV8qOH+8gLJ:+jGw1yY4OBQ33ae2V
TLSH T1E2366D4BF1A324FCC19BC434875B99A2B935786901247DBB66C4EE302E33F605B59F62
telfhash t1f6723ff062e434e1a096c95aebb6f4b0d53718bb07d5b6b18437bc63cf64f480d6a812
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:CoinMiner elf upx-dec


Avatar
abuse_ch
UPX decompressed file, sourced from SHA256 63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e
File size (compressed) :1'986'520 bytes
File size (de-compressed) :5'195'856 bytes
Format:linux/amd64
Packed file: 63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e

Intelligence


File Origin
# of uploads :
1
# of downloads :
99
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file
Sends data to a server
Receives data from a server
Changes access rights for a written file
Runs as daemon
Changes the time when the file was created, accessed, or modified
Kills processes
Locks files
Collects information on the CPU
Launching a process
Collects information on the RAM
Connection attempt
Substitutes an application name
Creates or modifies files in /cron to set up autorun
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
true
Architecture:
x86
Packer:
not packed
Botnet:
unknown
Number of open files:
67
Number of processes launched:
1
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
Anti-VM
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Verdict:
Malicious
File Type:
elf.64.le
First seen:
2026-07-22T21:08:00Z UTC
Last seen:
2026-07-23T00:42:00Z UTC
Hits:
~1000
Status:
terminated
Behavior Graph:
%3 guuid=285fb207-1c00-0000-39f9-566750070000 pid=1872 /usr/bin/sudo guuid=93fc9b0a-1c00-0000-39f9-566757070000 pid=1879 /tmp/sample.bin mprotect-exec guuid=285fb207-1c00-0000-39f9-566750070000 pid=1872->guuid=93fc9b0a-1c00-0000-39f9-566757070000 pid=1879 execve guuid=1c8acb0c-1c00-0000-39f9-56675c070000 pid=1884 /tmp/sample.bin net zombie guuid=93fc9b0a-1c00-0000-39f9-566757070000 pid=1879->guuid=1c8acb0c-1c00-0000-39f9-56675c070000 pid=1884 clone 5ae18a07-f053-5a60-99ed-4d9d3e20c696 1.1.1.1:853 guuid=1c8acb0c-1c00-0000-39f9-56675c070000 pid=1884->5ae18a07-f053-5a60-99ed-4d9d3e20c696 con 5f6004ab-135d-5863-8d6f-a6f76ba0720b 45.148.10.68:21370 guuid=1c8acb0c-1c00-0000-39f9-56675c070000 pid=1884->5f6004ab-135d-5863-8d6f-a6f76ba0720b con 5493bef4-721b-597b-a55d-af49e1a84f0e 45.148.10.113:21370 guuid=1c8acb0c-1c00-0000-39f9-56675c070000 pid=1884->5493bef4-721b-597b-a55d-af49e1a84f0e con caec5668-d34a-5eb7-86d9-4f5a59806182 45.148.10.144:21370 guuid=1c8acb0c-1c00-0000-39f9-56675c070000 pid=1884->caec5668-d34a-5eb7-86d9-4f5a59806182 con 14ac75f0-edad-5de2-b6fb-37afde7f0bf7 45.148.10.208:21370 guuid=1c8acb0c-1c00-0000-39f9-56675c070000 pid=1884->14ac75f0-edad-5de2-b6fb-37afde7f0bf7 con guuid=7f88ca0e-1c00-0000-39f9-566761070000 pid=1889 /usr/bin/dash guuid=1c8acb0c-1c00-0000-39f9-56675c070000 pid=1884->guuid=7f88ca0e-1c00-0000-39f9-566761070000 pid=1889 execve guuid=4cc9200f-1c00-0000-39f9-566765070000 pid=1893 /tmp/sample.bin guuid=1c8acb0c-1c00-0000-39f9-56675c070000 pid=1884->guuid=4cc9200f-1c00-0000-39f9-566765070000 pid=1893 clone guuid=6a0e4e0f-1c00-0000-39f9-566767070000 pid=1895 /usr/bin/dash guuid=1c8acb0c-1c00-0000-39f9-56675c070000 pid=1884->guuid=6a0e4e0f-1c00-0000-39f9-566767070000 pid=1895 execve guuid=1c8acb0c-1c00-0000-39f9-56675c070000 pid=1932 /tmp/sample.bin bpf-socket-filter net net-scan send-data write-config zombie guuid=1c8acb0c-1c00-0000-39f9-56675c070000 pid=1884->guuid=1c8acb0c-1c00-0000-39f9-56675c070000 pid=1932 clone guuid=1c8acb0c-1c00-0000-39f9-56675c070000 pid=1968 /tmp/sample.bin guuid=1c8acb0c-1c00-0000-39f9-56675c070000 pid=1884->guuid=1c8acb0c-1c00-0000-39f9-56675c070000 pid=1968 clone guuid=e4b1fa0e-1c00-0000-39f9-566762070000 pid=1890 /usr/bin/dash guuid=7f88ca0e-1c00-0000-39f9-566761070000 pid=1889->guuid=e4b1fa0e-1c00-0000-39f9-566762070000 pid=1890 clone guuid=5977000f-1c00-0000-39f9-566763070000 pid=1891 /usr/bin/dash guuid=7f88ca0e-1c00-0000-39f9-566761070000 pid=1889->guuid=5977000f-1c00-0000-39f9-566763070000 pid=1891 clone guuid=90c6270f-1c00-0000-39f9-566766070000 pid=1894 /tmp/sample.bin zombie guuid=4cc9200f-1c00-0000-39f9-566765070000 pid=1893->guuid=90c6270f-1c00-0000-39f9-566766070000 pid=1894 clone guuid=e9587f0f-1c00-0000-39f9-566769070000 pid=1897 /usr/sbin/xtables-nft-multi guuid=6a0e4e0f-1c00-0000-39f9-566767070000 pid=1895->guuid=e9587f0f-1c00-0000-39f9-566769070000 pid=1897 execve guuid=5361a01c-1c00-0000-39f9-56677c070000 pid=1916 /usr/sbin/xtables-nft-multi guuid=6a0e4e0f-1c00-0000-39f9-566767070000 pid=1895->guuid=5361a01c-1c00-0000-39f9-56677c070000 pid=1916 execve guuid=1c8acb0c-1c00-0000-39f9-56675c070000 pid=1932|network network activity to 2048 IP addresses review logs to see them all guuid=1c8acb0c-1c00-0000-39f9-56675c070000 pid=1932->guuid=1c8acb0c-1c00-0000-39f9-56675c070000 pid=1932|network network guuid=f834b63f-1c00-0000-39f9-5667a7070000 pid=1959 /usr/bin/dash guuid=1c8acb0c-1c00-0000-39f9-56675c070000 pid=1932->guuid=f834b63f-1c00-0000-39f9-5667a7070000 pid=1959 execve guuid=89de6540-1c00-0000-39f9-5667a9070000 pid=1961 /usr/sbin/xtables-nft-multi guuid=f834b63f-1c00-0000-39f9-5667a7070000 pid=1959->guuid=89de6540-1c00-0000-39f9-5667a9070000 pid=1961 execve guuid=2c302041-1c00-0000-39f9-5667ab070000 pid=1963 /usr/sbin/xtables-nft-multi guuid=f834b63f-1c00-0000-39f9-5667a7070000 pid=1959->guuid=2c302041-1c00-0000-39f9-5667ab070000 pid=1963 execve guuid=461a8841-1c00-0000-39f9-5667ac070000 pid=1964 /usr/sbin/xtables-nft-multi guuid=f834b63f-1c00-0000-39f9-5667a7070000 pid=1959->guuid=461a8841-1c00-0000-39f9-5667ac070000 pid=1964 execve guuid=6d80e841-1c00-0000-39f9-5667ad070000 pid=1965 /usr/sbin/xtables-nft-multi guuid=f834b63f-1c00-0000-39f9-5667a7070000 pid=1959->guuid=6d80e841-1c00-0000-39f9-5667ad070000 pid=1965 execve
Gathering data
Result
Threat name:
Detection:
malicious
Classification:
troj.spyw.mine
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Connects to many ports of the same IP (likely port scanning)
Executes the "crontab" command typically for achieving persistence
Executes the "iptables" command to insert, remove and/or manipulate rules
Found strings related to Crypto-Mining
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Opens /sys/class/net/* files useful for querying network interface information
Sample tries to persist itself using cron
Tries to load the MSR kernel module used for reading/writing to CPUs model specific register
Yara detected Xmrig cryptocurrency miner
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1946843 Sample: 63be5f38b520b3143732962a5f8... Startdate: 23/07/2026 Architecture: LINUX Score: 100 102 FoundByClothing.com 2->102 104 216.2.120.75 XO-AS15-VerizonBusinessUS United States 2->104 106 99 other IPs or domains 2->106 108 Malicious sample detected (through community Yara rule) 2->108 110 Antivirus / Scanner detection for submitted sample 2->110 112 Multi AV Scanner detection for submitted file 2->112 114 2 other signatures 2->114 15 63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e.elf 2->15         started        18 dash rm 2->18         started        20 dash rm 2->20         started        signatures3 process4 signatures5 138 Found strings related to Crypto-Mining 15->138 22 63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e.elf 15->22         started        process6 signatures7 136 Opens /sys/class/net/* files useful for querying network interface information 22->136 25 63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e.elf 22->25         started        27 63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e.elf sh 22->27         started        29 63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e.elf sh 22->29         started        31 2 other processes 22->31 process8 process9 33 63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e.elf 63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e.elf 25->33         started        35 sh crontab 27->35         started        39 sh crontab 27->39         started        41 sh 27->41         started        43 sh iptables 29->43         started        45 sh iptables 29->45         started        49 2 other processes 29->49 47 sh iptables 31->47         started        51 2 other processes 31->51 file10 53 63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e.elf 33->53         started        100 /var/spool/cron/crontabs/tmp.gdnoRd, ASCII 35->100 dropped 124 Sample tries to persist itself using cron 35->124 126 Executes the "crontab" command typically for achieving persistence 35->126 128 Executes the "iptables" command to insert, remove and/or manipulate rules 47->128 130 Tries to load the MSR kernel module used for reading/writing to CPUs model specific register 51->130 signatures11 process12 signatures13 134 Opens /sys/class/net/* files useful for querying network interface information 53->134 56 63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e.elf 53->56         started        58 63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e.elf sh 53->58         started        60 63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e.elf sh 53->60         started        62 2 other processes 53->62 process14 process15 64 63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e.elf 63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e.elf 56->64         started        66 sh crontab 58->66         started        70 sh crontab 58->70         started        72 sh 58->72         started        74 sh iptables 60->74         started        76 sh iptables 60->76         started        80 2 other processes 60->80 78 sh iptables 62->78         started        82 2 other processes 62->82 file16 84 63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e.elf 64->84         started        98 /var/spool/cron/crontabs/tmp.7mKpAz, ASCII 66->98 dropped 116 Sample tries to persist itself using cron 66->116 118 Executes the "crontab" command typically for achieving persistence 66->118 120 Executes the "iptables" command to insert, remove and/or manipulate rules 78->120 122 Tries to load the MSR kernel module used for reading/writing to CPUs model specific register 82->122 signatures17 process18 signatures19 132 Opens /sys/class/net/* files useful for querying network interface information 84->132 87 63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e.elf sh 84->87         started        89 63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e.elf sh 84->89         started        91 63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e.elf sh 84->91         started        93 2 other processes 84->93 process20 process21 95 sh crontab 87->95         started        signatures22 140 Executes the "crontab" command typically for achieving persistence 95->140
Threat name:
Linux.Coinminer.XMRig
Status:
Malicious
First seen:
2026-07-22 23:35:54 UTC
File Type:
ELF64 Little (Exe)
AV detection:
12 of 24 (50.00%)
Threat level:
  4/5
Result
Malware family:
Score:
  10/10
Tags:
family:xmrig antivm defense_evasion discovery execution linux miner persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Changes its process name
Checks CPU configuration
Reads CPU attributes
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Enumerates running processes
Reads hardware information
Reads network interface configuration
Creates Raw socket
Flushes firewall rules
Contacts a large (292285) amount of remote hosts
Creates a large amount of network flows
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:enterpriseunix2
Author:Tim Brown @timb_machine
Description:Enterprise UNIX
Rule name:Linux_Trojan_Pornoasset_927f314f
Author:Elastic Security
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:miner_lin_xmrig_strings
Author:Sekoia.io
Description:Detects XMRig ELF
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
Rule name:upxHook
Author:@r3dbU7z
Description:Detect artifacts from 'upxHook' - modification of UPX packer
Reference:https://bazaar.abuse.ch/sample/6352be8aa5d8063673aa428c3807228c40505004320232a23d99ebd9ef48478a/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CoinMiner

elf 9bbb4b428b34a0ce31da7183bf4a20f48a5a5639d4acf7afb7bd1d0a4205e098

(this sample)

  
Delivery method
Distributed via web download

Comments