MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ae1dc80d8a8a509c500bb117ac850d9410208f078d219d283880e0cce17f38fa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: ae1dc80d8a8a509c500bb117ac850d9410208f078d219d283880e0cce17f38fa
SHA3-384 hash: 89f47dd6633540419ca8335b3bb41ae62e0be8c6b58a6d94152f7611ae7157843989e1163a0bb887ce336d1792f05fe8
SHA1 hash: 3fae4077e4abc87244606cf66281b062e3c313c3
MD5 hash: 875869c7629ebc9ae8fe80caa793836c
humanhash: robert-fourteen-october-six
File name:ae1dc80d8a8a509c500bb117ac850d9410208f078d219d283880e0cce17f38fa
Download: download sample
Signature CoinMiner
File size:3'166'208 bytes
First seen:2026-07-31 11:00:19 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 98304:yqbBX3Dw+oWl9m3RMNVwjsPGITN6qWPKYeHy+jNvr:yY5Dw+oSmmTwjsPN5MPFeHy+RD
TLSH T1F6E533512E9A872B2AF0E037F25CB470DDE22BF5D63E85A0B7C5ED61A4994F50D2C078
Magika gzip
Reporter EnthecSolutions
Tags:CoinMiner enthec gz

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
CA CA
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:ae1dc80d8a8a509c500bb117ac850d9410208f078d219d283880e0cce17f38fa~
File size:3'331'562 bytes
SHA256 hash: 117e24246f04d89621c91e17f66604589a63bba1537c3aa102594853a4cf4f88
MD5 hash: 89c38272ab17f729282763465078f639
MIME type:application/x-tar
Signature CoinMiner
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
gz
First seen:
2026-07-31T09:09:00Z UTC
Last seen:
2026-07-31T13:05:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
1 match(es)
Tags:
GZip Archive
Threat name:
Linux.Dropper.ShellAgent
Status:
Malicious
First seen:
2026-07-31 11:13:35 UTC
AV detection:
18 of 38 (47.37%)
Threat level:
  3/5
Result
Malware family:
xmrig_linux
Score:
  10/10
Tags:
family:xmrig_linux antivm defense_evasion discovery linux miner persistence privilege_escalation rootkit upx
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
Reads CPU attributes
Checks hardware identifiers (DMI)
Enumerates running processes
Reads hardware information
Removes the immutable protection flag from a file
Write file to user bin folder
File and Directory Permissions Modification
Executes dropped EXE
Loads a kernel module
XMRig Miner payload
Family: xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments