MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 adaee0af5bc0376c62b7b87408d9e346f2da326d25d474638bbfc4a6b85f3560. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: adaee0af5bc0376c62b7b87408d9e346f2da326d25d474638bbfc4a6b85f3560
SHA3-384 hash: 14809ba5da80a97ebf54d30b25642ebac9903c371633bef0297b9878299def859ed550014903078522f0e7a29c9e2767
SHA1 hash: 5636d84ea69ed5185367a54a5119c7f87a556948
MD5 hash: 5070d90b6316cd9e68ba7c0b092ba661
humanhash: mirror-july-monkey-two
File name:kworkerd-netns
Download: download sample
Signature CoinMiner
File size:138'356 bytes
First seen:2026-06-20 06:01:25 UTC
Last seen:2026-06-21 04:08:28 UTC
File type: elf
MIME type:application/x-sharedlib
ssdeep 3072:sw6eSJYso7HOUQuQsOB2PGfDluMSZ75Ndb3nWKwVb:sk37OUaBjfZuN5f3nKb
TLSH T1DCD312FD0DA36B9AE576003E24BFCE482A11DC07E5A05C03544AEDDAC95D8B1D7832DB
Magika elf
Reporter abuse_ch
Tags:CoinMiner elf UPX
File size (compressed) :138'356 bytes
File size (de-compressed) :349'864 bytes
Format:linux/mips
Unpacked file: 57df2674f16175374bfba7367040ed79889fed9d71b06a96d34181e112f15e22

Intelligence


File Origin
# of uploads :
2
# of downloads :
61
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% directory
Connection attempt
Opens a port
Changes access rights for a written file
Receives data from a server
Changes the time when the file was created, accessed, or modified
DNS request
Runs as daemon
Sets a written file as executable
Deleting a recently created file
Manages services
Collects information on the CPU
Creating a file
Sends data to a server
Launching a process
Creates or modifies files in /cron to set up autorun
Substitutes an application name
Kills critical processes
Deleting of the original file
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
packed upx
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
mips
Packer:
UPX
Botnet:
unknown
Number of open files:
1
Number of processes launched:
1
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
no suspicious findings
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Verdict:
Malicious
File Type:
elf.32.be
First seen:
2026-06-20T03:17:00Z UTC
Last seen:
2026-06-22T00:39:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=7e3baa54-1b00-0000-bbea-ce7e700b0000 pid=2928 /usr/bin/sudo guuid=417eb456-1b00-0000-bbea-ce7e730b0000 pid=2931 /tmp/sample.bin guuid=7e3baa54-1b00-0000-bbea-ce7e700b0000 pid=2928->guuid=417eb456-1b00-0000-bbea-ce7e730b0000 pid=2931 execve
Result
Threat name:
Detection:
malicious
Classification:
troj.spyw.evad.mine
Score:
88 / 100
Signature
Drops invisible ELF files
Executes itself again with its parent PID as an argument (indicative of hampering debugging)
Executes the "crontab" command typically for achieving persistence
Found strings related to Crypto-Mining
Opens /sys/class/net/* files useful for querying network interface information
Performs DNS TXT record lookups
Sample deletes itself
Sample tries to persist itself using cron
Searches for CPU information (likely indicative of DDoS capability)
Writes identical ELF files to multiple locations
Yara detected Xmrig cryptocurrency miner
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1931304 Sample: kworkerd-netns.elf Startdate: 20/06/2026 Architecture: LINUX Score: 88 124 api.robotmarkethub.com 2->124 126 91.239.211.89, 36046, 36048, 36054 HOSTKEY-ASNL Germany 2->126 128 3 other IPs or domains 2->128 130 Yara detected Xmrig cryptocurrency miner 2->130 13 systemd sh 2->13         started        15 kworkerd-netns.elf 2->15         started        18 systemd snapd-env-generator 2->18         started        20 3 other processes 2->20 signatures3 132 Performs DNS TXT record lookups 124->132 process4 signatures5 22 sh sh 13->22         started        24 sh wget 13->24         started        27 sh rm 13->27         started        152 Found strings related to Crypto-Mining 15->152 29 kworkerd-netns.elf 15->29         started        process6 file7 31 sh 22->31         started        33 sh 22->33         started        35 sh 22->35         started        39 23 other processes 22->39 116 /tmp/..redis-sentinel, POSIX 24->116 dropped 37 kworkerd-netns.elf 29->37         started        process8 file9 43 sh .d 31->43         started        45 sh .d 33->45         started        47 sh .d 35->47         started        49 kworkerd-netns.elf sh 37->49         started        51 kworkerd-netns.elf sh 37->51         started        106 /tmp/.d, ELF 39->106 dropped 108 /run/.d, ELF 39->108 dropped 110 /root/.d, ELF 39->110 dropped 112 /dev/shm/.d, ELF 39->112 dropped 134 Writes identical ELF files to multiple locations 39->134 136 Searches for CPU information (likely indicative of DDoS capability) 39->136 138 Drops invisible ELF files 39->138 140 Sample deletes itself 39->140 53 sh awk 39->53         started        55 sh cut 39->55         started        57 sh 39->57         started        59 sh 39->59         started        signatures10 process11 process12 61 .d 43->61         started        63 .d 45->63         started        65 .d 47->65         started        67 sh systemctl 49->67         started        69 sh systemctl 51->69         started        process13 71 .d 61->71         started        75 .d 63->75         started        77 .d 65->77         started        file14 114 /var/spool/cron/crontabs/root, ASCII 71->114 dropped 142 Opens /sys/class/net/* files useful for querying network interface information 71->142 144 Sample deletes itself 71->144 146 Sample tries to persist itself using cron 71->146 79 .d sh 71->79         started        82 .d sh 71->82         started        84 .d sh 75->84         started        86 .d sh 75->86         started        88 .d sh 77->88         started        90 .d sh 77->90         started        signatures15 process16 signatures17 92 sh crontab 79->92         started        96 sh crontab 82->96         started        154 Executes itself again with its parent PID as an argument (indicative of hampering debugging) 84->154 98 sh crontab 84->98         started        100 sh crontab 86->100         started        102 sh crontab 88->102         started        104 sh crontab 90->104         started        process18 file19 118 /var/spool/cron/crontabs/tmp.5zjf2e, ASCII 92->118 dropped 120 /var/spool/cron/crontabs/tmp.uDl2Ze, ASCII 98->120 dropped 148 Sample tries to persist itself using cron 98->148 150 Executes the "crontab" command typically for achieving persistence 98->150 122 /var/spool/cron/crontabs/tmp.G2ZPgN, ASCII 102->122 dropped signatures20
Threat name:
Linux.Trojan.Qwexlafiba
Status:
Malicious
First seen:
2026-06-20 06:03:31 UTC
File Type:
ELF32 Big (SO)
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery execution persistence privilege_escalation upx
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Creates/modifies Cron job
Enumerates active TCP sockets
Enumerates running processes
Modifies systemd
Reads MAC address of network interface
Deletes itself
Modifies Watchdog functionality
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:elf_arm_mips_ko_so

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CoinMiner

elf adaee0af5bc0376c62b7b87408d9e346f2da326d25d474638bbfc4a6b85f3560

(this sample)

  
Delivery method
Distributed via web download

Comments