MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ad57a41f8719b0784771ba4adbda4f02e300ee01902de794dddfc91d470591d3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: ad57a41f8719b0784771ba4adbda4f02e300ee01902de794dddfc91d470591d3
SHA3-384 hash: 1c7024ab6b98254104a38133a9961874a2c65c546a2c182290fc250e138a13df363e3ad1817e65575c489e50303ca44f
SHA1 hash: 0283a9f4368d4c3b5c1c1866c7472f9c87f4f879
MD5 hash: f132c410d85fed6214533ecceb9a3095
humanhash: blossom-mike-seven-summer
File name:mon.sh
Download: download sample
Signature CoinMiner
File size:5'234 bytes
First seen:2025-08-07 11:42:11 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:l06z0cic27PP7DTAiVjIAmx793jt0yjtgmu4IL1qFQ2ZV7Raa3d6z0cd:l080c9iPzDNjGd935XvIL1qFhH7Rx3dS
TLSH T159B1954AF690C6B03C9D81A8A99B74863A06428B4E451D1DF86FF098BF5475871F83FF
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.248.53.119:8000/mon.sh1e891ab1521b27923233e694f60fdbf0e1b840e657d8b1ffdefd8b5ef5e38964 CoinMinerCoinMiner
http://ip-api.com/json/n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
39
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=9586f415-1700-0000-3a9d-3399640e0000 pid=3684 /usr/bin/sudo guuid=3b546118-1700-0000-3a9d-33996e0e0000 pid=3694 /tmp/sample.bin guuid=9586f415-1700-0000-3a9d-3399640e0000 pid=3684->guuid=3b546118-1700-0000-3a9d-33996e0e0000 pid=3694 execve guuid=8b69cf18-1700-0000-3a9d-3399720e0000 pid=3698 /usr/bin/whoami guuid=3b546118-1700-0000-3a9d-33996e0e0000 pid=3694->guuid=8b69cf18-1700-0000-3a9d-3399720e0000 pid=3698 execve guuid=78699e19-1700-0000-3a9d-3399760e0000 pid=3702 /usr/bin/whoami guuid=3b546118-1700-0000-3a9d-33996e0e0000 pid=3694->guuid=78699e19-1700-0000-3a9d-3399760e0000 pid=3702 execve guuid=e64e481a-1700-0000-3a9d-33997a0e0000 pid=3706 /usr/bin/whoami guuid=3b546118-1700-0000-3a9d-33996e0e0000 pid=3694->guuid=e64e481a-1700-0000-3a9d-33997a0e0000 pid=3706 execve guuid=e857221b-1700-0000-3a9d-33997b0e0000 pid=3707 /usr/bin/bash guuid=3b546118-1700-0000-3a9d-33996e0e0000 pid=3694->guuid=e857221b-1700-0000-3a9d-33997b0e0000 pid=3707 clone guuid=f370531b-1700-0000-3a9d-33997d0e0000 pid=3709 /usr/bin/id guuid=3b546118-1700-0000-3a9d-33996e0e0000 pid=3694->guuid=f370531b-1700-0000-3a9d-33997d0e0000 pid=3709 execve guuid=3bfc3d1c-1700-0000-3a9d-3399820e0000 pid=3714 /usr/bin/systemctl guuid=3b546118-1700-0000-3a9d-33996e0e0000 pid=3694->guuid=3bfc3d1c-1700-0000-3a9d-3399820e0000 pid=3714 execve guuid=e1f0cd1d-1700-0000-3a9d-3399860e0000 pid=3718 /usr/bin/bash guuid=3b546118-1700-0000-3a9d-33996e0e0000 pid=3694->guuid=e1f0cd1d-1700-0000-3a9d-3399860e0000 pid=3718 clone guuid=6d20d51d-1700-0000-3a9d-3399870e0000 pid=3719 /usr/bin/grep guuid=3b546118-1700-0000-3a9d-33996e0e0000 pid=3694->guuid=6d20d51d-1700-0000-3a9d-3399870e0000 pid=3719 execve guuid=c62c4e1e-1700-0000-3a9d-33998a0e0000 pid=3722 /usr/bin/bash guuid=3b546118-1700-0000-3a9d-33996e0e0000 pid=3694->guuid=c62c4e1e-1700-0000-3a9d-33998a0e0000 pid=3722 clone guuid=ec26551e-1700-0000-3a9d-33998b0e0000 pid=3723 /usr/bin/bash guuid=3b546118-1700-0000-3a9d-33996e0e0000 pid=3694->guuid=ec26551e-1700-0000-3a9d-33998b0e0000 pid=3723 clone guuid=f85c9e1e-1700-0000-3a9d-3399900e0000 pid=3728 /usr/bin/ps guuid=3b546118-1700-0000-3a9d-33996e0e0000 pid=3694->guuid=f85c9e1e-1700-0000-3a9d-3399900e0000 pid=3728 execve guuid=3093a51e-1700-0000-3a9d-3399910e0000 pid=3729 /usr/bin/mawk guuid=3b546118-1700-0000-3a9d-33996e0e0000 pid=3694->guuid=3093a51e-1700-0000-3a9d-3399910e0000 pid=3729 execve guuid=3b78ad1e-1700-0000-3a9d-3399920e0000 pid=3730 /usr/bin/bash guuid=3b546118-1700-0000-3a9d-33996e0e0000 pid=3694->guuid=3b78ad1e-1700-0000-3a9d-3399920e0000 pid=3730 clone guuid=cfd45621-1700-0000-3a9d-33999e0e0000 pid=3742 /usr/bin/bash guuid=3b546118-1700-0000-3a9d-33996e0e0000 pid=3694->guuid=cfd45621-1700-0000-3a9d-33999e0e0000 pid=3742 clone guuid=4be16925-1700-0000-3a9d-3399b00e0000 pid=3760 /usr/bin/bash guuid=3b546118-1700-0000-3a9d-33996e0e0000 pid=3694->guuid=4be16925-1700-0000-3a9d-3399b00e0000 pid=3760 clone guuid=8280fc25-1700-0000-3a9d-3399b30e0000 pid=3763 /usr/bin/curl net send-data guuid=3b546118-1700-0000-3a9d-33996e0e0000 pid=3694->guuid=8280fc25-1700-0000-3a9d-3399b30e0000 pid=3763 execve guuid=b2440426-1700-0000-3a9d-3399b40e0000 pid=3764 /usr/bin/grep guuid=3b546118-1700-0000-3a9d-33996e0e0000 pid=3694->guuid=b2440426-1700-0000-3a9d-3399b40e0000 pid=3764 execve guuid=eab3d735-1700-0000-3a9d-3399fb0e0000 pid=3835 /usr/bin/wget net send-data write-file guuid=3b546118-1700-0000-3a9d-33996e0e0000 pid=3694->guuid=eab3d735-1700-0000-3a9d-3399fb0e0000 pid=3835 execve guuid=1ab8a24a-1700-0000-3a9d-3399260f0000 pid=3878 /usr/bin/chmod guuid=3b546118-1700-0000-3a9d-33996e0e0000 pid=3694->guuid=1ab8a24a-1700-0000-3a9d-3399260f0000 pid=3878 execve guuid=c48b124b-1700-0000-3a9d-3399280f0000 pid=3880 /home/sandbox/run.sh guuid=3b546118-1700-0000-3a9d-33996e0e0000 pid=3694->guuid=c48b124b-1700-0000-3a9d-3399280f0000 pid=3880 execve guuid=eb334dc8-1800-0000-3a9d-3399f2130000 pid=5106 /usr/bin/rm delete-file guuid=3b546118-1700-0000-3a9d-33996e0e0000 pid=3694->guuid=eb334dc8-1800-0000-3a9d-3399f2130000 pid=5106 execve guuid=6c36b8c8-1800-0000-3a9d-3399f5130000 pid=5109 /usr/bin/whoami guuid=3b546118-1700-0000-3a9d-33996e0e0000 pid=3694->guuid=6c36b8c8-1800-0000-3a9d-3399f5130000 pid=5109 execve guuid=371034c9-1800-0000-3a9d-3399f7130000 pid=5111 /usr/bin/whoami guuid=3b546118-1700-0000-3a9d-33996e0e0000 pid=3694->guuid=371034c9-1800-0000-3a9d-3399f7130000 pid=5111 execve guuid=78f794c9-1800-0000-3a9d-3399fa130000 pid=5114 /usr/bin/whoami guuid=3b546118-1700-0000-3a9d-33996e0e0000 pid=3694->guuid=78f794c9-1800-0000-3a9d-3399fa130000 pid=5114 execve guuid=2ed0771e-1700-0000-3a9d-33998c0e0000 pid=3724 /usr/bin/bash guuid=c62c4e1e-1700-0000-3a9d-33998a0e0000 pid=3722->guuid=2ed0771e-1700-0000-3a9d-33998c0e0000 pid=3724 clone guuid=73556a21-1700-0000-3a9d-33999f0e0000 pid=3743 /usr/bin/pgrep guuid=cfd45621-1700-0000-3a9d-33999e0e0000 pid=3742->guuid=73556a21-1700-0000-3a9d-33999f0e0000 pid=3743 execve guuid=54fb7021-1700-0000-3a9d-3399a00e0000 pid=3744 /usr/bin/bash guuid=cfd45621-1700-0000-3a9d-33999e0e0000 pid=3742->guuid=54fb7021-1700-0000-3a9d-3399a00e0000 pid=3744 clone guuid=c97b8525-1700-0000-3a9d-3399b10e0000 pid=3761 /usr/bin/grep guuid=4be16925-1700-0000-3a9d-3399b00e0000 pid=3760->guuid=c97b8525-1700-0000-3a9d-3399b10e0000 pid=3761 execve b60edd83-de97-543e-8c12-c815cb088ff2 ip-api.com:80 guuid=8280fc25-1700-0000-3a9d-3399b30e0000 pid=3763->b60edd83-de97-543e-8c12-c815cb088ff2 send: 79B guuid=8280fc25-1700-0000-3a9d-3399b30e0000 pid=3775 /usr/bin/curl dns net send-data guuid=8280fc25-1700-0000-3a9d-3399b30e0000 pid=3763->guuid=8280fc25-1700-0000-3a9d-3399b30e0000 pid=3775 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=8280fc25-1700-0000-3a9d-3399b30e0000 pid=3775->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 28B 2f67bf0f-8453-5800-9e7b-37101ce5849f 162.248.53.119:8000 guuid=eab3d735-1700-0000-3a9d-3399fb0e0000 pid=3835->2f67bf0f-8453-5800-9e7b-37101ce5849f send: 140B guuid=db4ea54b-1700-0000-3a9d-33992b0f0000 pid=3883 /usr/bin/systemctl guuid=c48b124b-1700-0000-3a9d-3399280f0000 pid=3880->guuid=db4ea54b-1700-0000-3a9d-33992b0f0000 pid=3883 execve guuid=2586054e-1700-0000-3a9d-33993b0f0000 pid=3899 /usr/bin/bash guuid=c48b124b-1700-0000-3a9d-3399280f0000 pid=3880->guuid=2586054e-1700-0000-3a9d-33993b0f0000 pid=3899 clone guuid=2696f053-1700-0000-3a9d-3399510f0000 pid=3921 /usr/bin/bash guuid=c48b124b-1700-0000-3a9d-3399280f0000 pid=3880->guuid=2696f053-1700-0000-3a9d-3399510f0000 pid=3921 clone guuid=3f5f8754-1700-0000-3a9d-3399570f0000 pid=3927 /usr/bin/id guuid=c48b124b-1700-0000-3a9d-3399280f0000 pid=3880->guuid=3f5f8754-1700-0000-3a9d-3399570f0000 pid=3927 execve guuid=ec7ff654-1700-0000-3a9d-3399590f0000 pid=3929 /usr/bin/mkdir guuid=c48b124b-1700-0000-3a9d-3399280f0000 pid=3880->guuid=ec7ff654-1700-0000-3a9d-3399590f0000 pid=3929 execve guuid=61106155-1700-0000-3a9d-33995c0f0000 pid=3932 /usr/bin/wget dns net send-data write-file guuid=c48b124b-1700-0000-3a9d-3399280f0000 pid=3880->guuid=61106155-1700-0000-3a9d-33995c0f0000 pid=3932 execve guuid=1aa7df7c-1700-0000-3a9d-3399e10f0000 pid=4065 /usr/bin/tar write-file guuid=c48b124b-1700-0000-3a9d-3399280f0000 pid=3880->guuid=1aa7df7c-1700-0000-3a9d-3399e10f0000 pid=4065 execve guuid=822b5a8c-1700-0000-3a9d-33991d100000 pid=4125 /usr/bin/mv guuid=c48b124b-1700-0000-3a9d-3399280f0000 pid=3880->guuid=822b5a8c-1700-0000-3a9d-33991d100000 pid=4125 execve guuid=549ab98c-1700-0000-3a9d-33991e100000 pid=4126 /usr/bin/rm guuid=c48b124b-1700-0000-3a9d-3399280f0000 pid=3880->guuid=549ab98c-1700-0000-3a9d-33991e100000 pid=4126 execve guuid=dc310a8d-1700-0000-3a9d-33991f100000 pid=4127 /usr/bin/chmod guuid=c48b124b-1700-0000-3a9d-3399280f0000 pid=3880->guuid=dc310a8d-1700-0000-3a9d-33991f100000 pid=4127 execve guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131 /usr/lib/dev/systemdev/systemd-mont mprotect-exec net send-data guuid=c48b124b-1700-0000-3a9d-3399280f0000 pid=3880->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131 execve guuid=25de6d8d-1700-0000-3a9d-339924100000 pid=4132 /usr/bin/sleep guuid=c48b124b-1700-0000-3a9d-3399280f0000 pid=3880->guuid=25de6d8d-1700-0000-3a9d-339924100000 pid=4132 execve guuid=82f2d2ab-1700-0000-3a9d-33999b100000 pid=4251 /usr/bin/ps guuid=c48b124b-1700-0000-3a9d-3399280f0000 pid=3880->guuid=82f2d2ab-1700-0000-3a9d-33999b100000 pid=4251 execve guuid=43f141b4-1700-0000-3a9d-3399c5100000 pid=4293 /usr/bin/sleep guuid=c48b124b-1700-0000-3a9d-3399280f0000 pid=3880->guuid=43f141b4-1700-0000-3a9d-3399c5100000 pid=4293 execve guuid=5b6abcc0-1800-0000-3a9d-3399dd130000 pid=5085 /usr/bin/ps guuid=c48b124b-1700-0000-3a9d-3399280f0000 pid=3880->guuid=5b6abcc0-1800-0000-3a9d-3399dd130000 pid=5085 execve guuid=364afdc6-1800-0000-3a9d-3399ee130000 pid=5102 /usr/bin/rm guuid=c48b124b-1700-0000-3a9d-3399280f0000 pid=3880->guuid=364afdc6-1800-0000-3a9d-3399ee130000 pid=5102 execve guuid=a3bfdfc7-1800-0000-3a9d-3399f1130000 pid=5105 /usr/bin/rm guuid=c48b124b-1700-0000-3a9d-3399280f0000 pid=3880->guuid=a3bfdfc7-1800-0000-3a9d-3399f1130000 pid=5105 execve guuid=6416194e-1700-0000-3a9d-33993c0f0000 pid=3900 /usr/bin/wget dns net send-data guuid=2586054e-1700-0000-3a9d-33993b0f0000 pid=3899->guuid=6416194e-1700-0000-3a9d-33993c0f0000 pid=3900 execve guuid=6416194e-1700-0000-3a9d-33993c0f0000 pid=3900->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B 0690ccd5-4816-5f11-94dc-7c585f38cdea ipv4.icanhazip.com:0 guuid=6416194e-1700-0000-3a9d-33993c0f0000 pid=3900->0690ccd5-4816-5f11-94dc-7c585f38cdea con d0ecfe49-aa79-583f-85c6-85ac97075256 ipv4.icanhazip.com:80 guuid=6416194e-1700-0000-3a9d-33993c0f0000 pid=3900->d0ecfe49-aa79-583f-85c6-85ac97075256 send: 133B guuid=6aa4fe53-1700-0000-3a9d-3399520f0000 pid=3922 /usr/bin/bash guuid=2696f053-1700-0000-3a9d-3399510f0000 pid=3921->guuid=6aa4fe53-1700-0000-3a9d-3399520f0000 pid=3922 clone guuid=3bee0654-1700-0000-3a9d-3399530f0000 pid=3923 /usr/bin/sed guuid=2696f053-1700-0000-3a9d-3399510f0000 pid=3921->guuid=3bee0654-1700-0000-3a9d-3399530f0000 pid=3923 execve guuid=41e00c54-1700-0000-3a9d-3399540f0000 pid=3924 /usr/bin/cut guuid=2696f053-1700-0000-3a9d-3399510f0000 pid=3921->guuid=41e00c54-1700-0000-3a9d-3399540f0000 pid=3924 execve guuid=61106155-1700-0000-3a9d-33995c0f0000 pid=3932->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 164B 75aab096-419b-50ef-be46-7d76b6a90e4c github.com:443 guuid=61106155-1700-0000-3a9d-33995c0f0000 pid=3932->75aab096-419b-50ef-be46-7d76b6a90e4c send: 802B f8c5e44f-328d-5324-8bbd-da50752b9120 release-assets.githubusercontent.com:0 guuid=61106155-1700-0000-3a9d-33995c0f0000 pid=3932->f8c5e44f-328d-5324-8bbd-da50752b9120 con f0eebea5-e97d-507c-a771-59cac353877c release-assets.githubusercontent.com:443 guuid=61106155-1700-0000-3a9d-33995c0f0000 pid=3932->f0eebea5-e97d-507c-a771-59cac353877c send: 1660B guuid=5558317d-1700-0000-3a9d-3399e30f0000 pid=4067 /usr/bin/gzip guuid=1aa7df7c-1700-0000-3a9d-3399e10f0000 pid=4065->guuid=5558317d-1700-0000-3a9d-3399e30f0000 pid=4067 execve 27958174-7cd5-58aa-a656-dcfbbd6ab520 51.178.73.238:9118 guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->27958174-7cd5-58aa-a656-dcfbbd6ab520 send: 561B guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4144 /usr/lib/dev/systemdev/systemd-mont write-file zombie guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4144 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4145 /usr/lib/dev/systemdev/systemd-mont send-data guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4145 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4146 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4146 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4147 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4147 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4148 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4148 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4172 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4172 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4173 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4173 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4175 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4175 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4176 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4176 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4196 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4196 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4197 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4197 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4198 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4198 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4199 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4199 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4209 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4209 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4210 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4210 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4211 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4211 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4212 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4212 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4230 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4230 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4231 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4231 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4232 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4232 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4233 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4233 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4258 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4258 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4259 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4259 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4260 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4260 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4262 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4262 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4284 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4284 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4285 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4285 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4286 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4286 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4287 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4287 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4326 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4326 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4327 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4327 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4329 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4329 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4331 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4331 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4356 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4356 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4357 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4357 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4358 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4358 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4359 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4359 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4386 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4386 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4387 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4387 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4388 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4388 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4389 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4389 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4412 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4412 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4413 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4413 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4414 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4414 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4416 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4416 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4442 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4442 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4443 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4443 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4445 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4445 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4446 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4446 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4469 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4469 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4470 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4470 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4471 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4471 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4472 /usr/lib/dev/systemdev/systemd-mont guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4131->guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4472 clone guuid=cc42548d-1700-0000-3a9d-339923100000 pid=4145->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 80B
Verdict:
Malicious
Threat:
HEUR:Trojan-Downloader.Shell.Agent
Threat name:
Script.Trojan.Heuristic
Status:
Malicious
First seen:
2025-08-07 11:42:42 UTC
File Type:
Text (Shell)
AV detection:
7 of 23 (30.43%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
antivm discovery execution linux persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Checks CPU configuration
Reads CPU attributes
Creates/modifies Cron job
Enumerates running processes
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Distributed via web download

Comments