MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a1a45a93e224d051aeab954568b912dc518d7bb8586dc4714a1d578c9c9bbcb0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: a1a45a93e224d051aeab954568b912dc518d7bb8586dc4714a1d578c9c9bbcb0
SHA3-384 hash: 7eef3059865ae877bf7298b3662d698b1bea4b81cae6d87f67ffc9d6fb95a2b3ad0e9c98743ff73bc0521d16bdb6e5b7
SHA1 hash: 8f37b910d4470dbe3262e257331ddb2ecb0bf34c
MD5 hash: 3132d85ac38b95a03caca8ba728c787b
humanhash: minnesota-skylark-november-may
File name:bolts
Download: download sample
Signature CoinMiner
File size:1'068 bytes
First seen:2025-12-07 15:18:37 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:wdfGyZ1r9yHgnKTpJnHOjWIEQXi/rvsTI0jmXJ:sGc1n4H6EClyXJ
TLSH T1AC1154CBA0A0AC30349C40BCE1465052754A9FB715E54854B80F367E3F54269F13C73B
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
http://185.14.92.152/nuts/lcn/an/aua-wget
http://185.14.92.152/nuts/x0c748b9e8bc6b5b4fe989df67655f3301d28ef81617b9cbe8e0f6a19d4f9b657 Miraimirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
27
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox
Result
Gathering data
Gathering data
Result
Malware family:
Score:
  10/10
Tags:
family:xmrig antivm defense_evasion discovery linux miner
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads CPU attributes
Checks hardware identifiers (DMI)
Enumerates running processes
Reads hardware information
File and Directory Permissions Modification
Executes dropped EXE
XMRig Miner payload
Xmrig family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CoinMiner

sh a1a45a93e224d051aeab954568b912dc518d7bb8586dc4714a1d578c9c9bbcb0

(this sample)

91bc2cc035d6d564b8ec851bae58855e76bd6cf527ea76edb2b6ddfaecc5f6e0

  
Delivery method
Distributed via web download
  
Dropping
MD5 4d689d36d18cd1fb076e010eb4019eb2
  
Dropping
SHA256 91bc2cc035d6d564b8ec851bae58855e76bd6cf527ea76edb2b6ddfaecc5f6e0

Comments