MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c11ff09814008a0c73cdcc03ad0805806102f067326bb578f94cf0370acce45a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: c11ff09814008a0c73cdcc03ad0805806102f067326bb578f94cf0370acce45a
SHA3-384 hash: 4b4945db75c7c3772eef41c0a8ad505770c762ca7ff7c04723d8acf112f16b56f799793f33993b2c3c96bdf3b6db862f
SHA1 hash: d0390a9c902a70188a85481fcaecbc9b53290f90
MD5 hash: fdb40926e91b1101f5fcb4ac0613cfd9
humanhash: ceiling-fruit-hydrogen-artist
File name:mon.sh
Download: download sample
Signature CoinMiner
File size:5'055 bytes
First seen:2025-08-02 11:08:21 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:l06z0cic27PP7DTAiVjIAmx793jt0yjtgmu4IL1qFQ2EBQa1d6z0cd:l080c9iPzDNjGd935XvIL1qFhEBr1d8z
TLSH T12CA1944AF690C6B0389DC5A8A99B74863A06028B4E441D1DF86FF488BF5475871F83FF
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.248.53.119:8000/mon.sh1e891ab1521b27923233e694f60fdbf0e1b840e657d8b1ffdefd8b5ef5e38964 CoinMinerCoinMiner
http://ip-api.com/json/n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
29
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
fingerprint
Status:
terminated
Behavior Graph:
%3 guuid=ac6c68a7-1900-0000-8816-cf8e650c0000 pid=3173 /usr/bin/sudo guuid=99f59faa-1900-0000-8816-cf8e660c0000 pid=3174 /tmp/sample.bin guuid=ac6c68a7-1900-0000-8816-cf8e650c0000 pid=3173->guuid=99f59faa-1900-0000-8816-cf8e660c0000 pid=3174 execve guuid=432e9cab-1900-0000-8816-cf8e670c0000 pid=3175 /usr/bin/whoami guuid=99f59faa-1900-0000-8816-cf8e660c0000 pid=3174->guuid=432e9cab-1900-0000-8816-cf8e670c0000 pid=3175 execve guuid=9977a2ac-1900-0000-8816-cf8e680c0000 pid=3176 /usr/bin/whoami guuid=99f59faa-1900-0000-8816-cf8e660c0000 pid=3174->guuid=9977a2ac-1900-0000-8816-cf8e680c0000 pid=3176 execve guuid=1f9410ad-1900-0000-8816-cf8e690c0000 pid=3177 /usr/bin/whoami guuid=99f59faa-1900-0000-8816-cf8e660c0000 pid=3174->guuid=1f9410ad-1900-0000-8816-cf8e690c0000 pid=3177 execve guuid=edf5c9ad-1900-0000-8816-cf8e6b0c0000 pid=3179 /usr/bin/bash guuid=99f59faa-1900-0000-8816-cf8e660c0000 pid=3174->guuid=edf5c9ad-1900-0000-8816-cf8e6b0c0000 pid=3179 clone guuid=22ade1ad-1900-0000-8816-cf8e6c0c0000 pid=3180 /usr/bin/id guuid=99f59faa-1900-0000-8816-cf8e660c0000 pid=3174->guuid=22ade1ad-1900-0000-8816-cf8e6c0c0000 pid=3180 execve guuid=72f0ccae-1900-0000-8816-cf8e6d0c0000 pid=3181 /usr/bin/systemctl guuid=99f59faa-1900-0000-8816-cf8e660c0000 pid=3174->guuid=72f0ccae-1900-0000-8816-cf8e6d0c0000 pid=3181 execve guuid=a105feaf-1900-0000-8816-cf8e710c0000 pid=3185 /usr/bin/bash guuid=99f59faa-1900-0000-8816-cf8e660c0000 pid=3174->guuid=a105feaf-1900-0000-8816-cf8e710c0000 pid=3185 clone guuid=828f02b0-1900-0000-8816-cf8e720c0000 pid=3186 /usr/bin/grep guuid=99f59faa-1900-0000-8816-cf8e660c0000 pid=3174->guuid=828f02b0-1900-0000-8816-cf8e720c0000 pid=3186 execve guuid=134951b0-1900-0000-8816-cf8e740c0000 pid=3188 /usr/bin/bash guuid=99f59faa-1900-0000-8816-cf8e660c0000 pid=3174->guuid=134951b0-1900-0000-8816-cf8e740c0000 pid=3188 clone guuid=fc8d56b0-1900-0000-8816-cf8e750c0000 pid=3189 /usr/bin/bash guuid=99f59faa-1900-0000-8816-cf8e660c0000 pid=3174->guuid=fc8d56b0-1900-0000-8816-cf8e750c0000 pid=3189 clone guuid=e90a7bb0-1900-0000-8816-cf8e770c0000 pid=3191 /usr/bin/ps guuid=99f59faa-1900-0000-8816-cf8e660c0000 pid=3174->guuid=e90a7bb0-1900-0000-8816-cf8e770c0000 pid=3191 execve guuid=20b781b0-1900-0000-8816-cf8e790c0000 pid=3193 /usr/bin/mawk guuid=99f59faa-1900-0000-8816-cf8e660c0000 pid=3174->guuid=20b781b0-1900-0000-8816-cf8e790c0000 pid=3193 execve guuid=dcaa87b0-1900-0000-8816-cf8e7a0c0000 pid=3194 /usr/bin/bash guuid=99f59faa-1900-0000-8816-cf8e660c0000 pid=3174->guuid=dcaa87b0-1900-0000-8816-cf8e7a0c0000 pid=3194 clone guuid=e01dadb3-1900-0000-8816-cf8e7f0c0000 pid=3199 /usr/bin/bash guuid=99f59faa-1900-0000-8816-cf8e660c0000 pid=3174->guuid=e01dadb3-1900-0000-8816-cf8e7f0c0000 pid=3199 clone guuid=5c724eb6-1900-0000-8816-cf8e8a0c0000 pid=3210 /usr/bin/bash guuid=99f59faa-1900-0000-8816-cf8e660c0000 pid=3174->guuid=5c724eb6-1900-0000-8816-cf8e8a0c0000 pid=3210 clone guuid=b6a4c1b6-1900-0000-8816-cf8e8d0c0000 pid=3213 /usr/bin/curl net send-data guuid=99f59faa-1900-0000-8816-cf8e660c0000 pid=3174->guuid=b6a4c1b6-1900-0000-8816-cf8e8d0c0000 pid=3213 execve guuid=89b6c8b6-1900-0000-8816-cf8e8e0c0000 pid=3214 /usr/bin/grep guuid=99f59faa-1900-0000-8816-cf8e660c0000 pid=3174->guuid=89b6c8b6-1900-0000-8816-cf8e8e0c0000 pid=3214 execve guuid=5b2469c8-1900-0000-8816-cf8ea10c0000 pid=3233 /usr/bin/wget net send-data write-file guuid=99f59faa-1900-0000-8816-cf8e660c0000 pid=3174->guuid=5b2469c8-1900-0000-8816-cf8ea10c0000 pid=3233 execve guuid=395585d8-1900-0000-8816-cf8ead0c0000 pid=3245 /usr/bin/chmod guuid=99f59faa-1900-0000-8816-cf8e660c0000 pid=3174->guuid=395585d8-1900-0000-8816-cf8ead0c0000 pid=3245 execve guuid=55efffd8-1900-0000-8816-cf8eaf0c0000 pid=3247 /home/sandbox/run.sh guuid=99f59faa-1900-0000-8816-cf8e660c0000 pid=3174->guuid=55efffd8-1900-0000-8816-cf8eaf0c0000 pid=3247 execve guuid=b9f1ed6a-1b00-0000-8816-cf8e2d100000 pid=4141 /usr/bin/rm delete-file guuid=99f59faa-1900-0000-8816-cf8e660c0000 pid=3174->guuid=b9f1ed6a-1b00-0000-8816-cf8e2d100000 pid=4141 execve guuid=20745c6b-1b00-0000-8816-cf8e2e100000 pid=4142 /usr/bin/whoami guuid=99f59faa-1900-0000-8816-cf8e660c0000 pid=3174->guuid=20745c6b-1b00-0000-8816-cf8e2e100000 pid=4142 execve guuid=d6b7026c-1b00-0000-8816-cf8e33100000 pid=4147 /usr/bin/whoami guuid=99f59faa-1900-0000-8816-cf8e660c0000 pid=3174->guuid=d6b7026c-1b00-0000-8816-cf8e33100000 pid=4147 execve guuid=f6e27e6c-1b00-0000-8816-cf8e35100000 pid=4149 /usr/bin/whoami guuid=99f59faa-1900-0000-8816-cf8e660c0000 pid=3174->guuid=f6e27e6c-1b00-0000-8816-cf8e35100000 pid=4149 execve guuid=6f845bb0-1900-0000-8816-cf8e760c0000 pid=3190 /usr/bin/bash guuid=134951b0-1900-0000-8816-cf8e740c0000 pid=3188->guuid=6f845bb0-1900-0000-8816-cf8e760c0000 pid=3190 clone guuid=fd50bfb3-1900-0000-8816-cf8e800c0000 pid=3200 /usr/bin/pgrep guuid=e01dadb3-1900-0000-8816-cf8e7f0c0000 pid=3199->guuid=fd50bfb3-1900-0000-8816-cf8e800c0000 pid=3200 execve guuid=57d2c6b3-1900-0000-8816-cf8e810c0000 pid=3201 /usr/bin/bash guuid=e01dadb3-1900-0000-8816-cf8e7f0c0000 pid=3199->guuid=57d2c6b3-1900-0000-8816-cf8e810c0000 pid=3201 clone guuid=084e5db6-1900-0000-8816-cf8e8b0c0000 pid=3211 /usr/bin/grep guuid=5c724eb6-1900-0000-8816-cf8e8a0c0000 pid=3210->guuid=084e5db6-1900-0000-8816-cf8e8b0c0000 pid=3211 execve b60edd83-de97-543e-8c12-c815cb088ff2 ip-api.com:80 guuid=b6a4c1b6-1900-0000-8816-cf8e8d0c0000 pid=3213->b60edd83-de97-543e-8c12-c815cb088ff2 send: 79B guuid=b6a4c1b6-1900-0000-8816-cf8e8d0c0000 pid=3222 /usr/bin/curl dns net send-data guuid=b6a4c1b6-1900-0000-8816-cf8e8d0c0000 pid=3213->guuid=b6a4c1b6-1900-0000-8816-cf8e8d0c0000 pid=3222 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=b6a4c1b6-1900-0000-8816-cf8e8d0c0000 pid=3222->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 28B 2f67bf0f-8453-5800-9e7b-37101ce5849f 162.248.53.119:8000 guuid=5b2469c8-1900-0000-8816-cf8ea10c0000 pid=3233->2f67bf0f-8453-5800-9e7b-37101ce5849f send: 140B guuid=b5a994d9-1900-0000-8816-cf8eb10c0000 pid=3249 /usr/bin/systemctl guuid=55efffd8-1900-0000-8816-cf8eaf0c0000 pid=3247->guuid=b5a994d9-1900-0000-8816-cf8eb10c0000 pid=3249 execve guuid=c29818dc-1900-0000-8816-cf8eb40c0000 pid=3252 /usr/bin/bash guuid=55efffd8-1900-0000-8816-cf8eaf0c0000 pid=3247->guuid=c29818dc-1900-0000-8816-cf8eb40c0000 pid=3252 clone guuid=cd09aee3-1900-0000-8816-cf8ebc0c0000 pid=3260 /usr/bin/bash guuid=55efffd8-1900-0000-8816-cf8eaf0c0000 pid=3247->guuid=cd09aee3-1900-0000-8816-cf8ebc0c0000 pid=3260 clone guuid=00df32e5-1900-0000-8816-cf8ec10c0000 pid=3265 /usr/bin/id guuid=55efffd8-1900-0000-8816-cf8eaf0c0000 pid=3247->guuid=00df32e5-1900-0000-8816-cf8ec10c0000 pid=3265 execve guuid=ce3998e5-1900-0000-8816-cf8ec20c0000 pid=3266 /usr/bin/mkdir guuid=55efffd8-1900-0000-8816-cf8eaf0c0000 pid=3247->guuid=ce3998e5-1900-0000-8816-cf8ec20c0000 pid=3266 execve guuid=1da41be6-1900-0000-8816-cf8ec50c0000 pid=3269 /usr/bin/wget dns net send-data write-file guuid=55efffd8-1900-0000-8816-cf8eaf0c0000 pid=3247->guuid=1da41be6-1900-0000-8816-cf8ec50c0000 pid=3269 execve guuid=af7e5f19-1a00-0000-8816-cf8e1f0d0000 pid=3359 /usr/bin/tar write-file guuid=55efffd8-1900-0000-8816-cf8eaf0c0000 pid=3247->guuid=af7e5f19-1a00-0000-8816-cf8e1f0d0000 pid=3359 execve guuid=8d6df42f-1a00-0000-8816-cf8e520d0000 pid=3410 /usr/bin/mv guuid=55efffd8-1900-0000-8816-cf8eaf0c0000 pid=3247->guuid=8d6df42f-1a00-0000-8816-cf8e520d0000 pid=3410 execve guuid=70536730-1a00-0000-8816-cf8e540d0000 pid=3412 /usr/bin/rm guuid=55efffd8-1900-0000-8816-cf8eaf0c0000 pid=3247->guuid=70536730-1a00-0000-8816-cf8e540d0000 pid=3412 execve guuid=b96dbc30-1a00-0000-8816-cf8e570d0000 pid=3415 /usr/bin/chmod guuid=55efffd8-1900-0000-8816-cf8eaf0c0000 pid=3247->guuid=b96dbc30-1a00-0000-8816-cf8e570d0000 pid=3415 execve guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417 /usr/lib/dev/systemdev/systemd-mont mprotect-exec net send-data guuid=55efffd8-1900-0000-8816-cf8eaf0c0000 pid=3247->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417 execve guuid=d2375031-1a00-0000-8816-cf8e5b0d0000 pid=3419 /usr/bin/sleep guuid=55efffd8-1900-0000-8816-cf8eaf0c0000 pid=3247->guuid=d2375031-1a00-0000-8816-cf8e5b0d0000 pid=3419 execve guuid=0bb72150-1a00-0000-8816-cf8ecb0d0000 pid=3531 /usr/bin/ps guuid=55efffd8-1900-0000-8816-cf8eaf0c0000 pid=3247->guuid=0bb72150-1a00-0000-8816-cf8ecb0d0000 pid=3531 execve guuid=9a572c57-1a00-0000-8816-cf8ee30d0000 pid=3555 /usr/bin/sleep guuid=55efffd8-1900-0000-8816-cf8eaf0c0000 pid=3247->guuid=9a572c57-1a00-0000-8816-cf8ee30d0000 pid=3555 execve guuid=2474b763-1b00-0000-8816-cf8e13100000 pid=4115 /usr/bin/ps guuid=55efffd8-1900-0000-8816-cf8eaf0c0000 pid=3247->guuid=2474b763-1b00-0000-8816-cf8e13100000 pid=4115 execve guuid=229aff69-1b00-0000-8816-cf8e2b100000 pid=4139 /usr/bin/rm guuid=55efffd8-1900-0000-8816-cf8eaf0c0000 pid=3247->guuid=229aff69-1b00-0000-8816-cf8e2b100000 pid=4139 execve guuid=94476c6a-1b00-0000-8816-cf8e2c100000 pid=4140 /usr/bin/rm guuid=55efffd8-1900-0000-8816-cf8eaf0c0000 pid=3247->guuid=94476c6a-1b00-0000-8816-cf8e2c100000 pid=4140 execve guuid=06c529dc-1900-0000-8816-cf8eb50c0000 pid=3253 /usr/bin/wget dns net send-data guuid=c29818dc-1900-0000-8816-cf8eb40c0000 pid=3252->guuid=06c529dc-1900-0000-8816-cf8eb50c0000 pid=3253 execve guuid=06c529dc-1900-0000-8816-cf8eb50c0000 pid=3253->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B 0690ccd5-4816-5f11-94dc-7c585f38cdea ipv4.icanhazip.com:0 guuid=06c529dc-1900-0000-8816-cf8eb50c0000 pid=3253->0690ccd5-4816-5f11-94dc-7c585f38cdea con d0ecfe49-aa79-583f-85c6-85ac97075256 ipv4.icanhazip.com:80 guuid=06c529dc-1900-0000-8816-cf8eb50c0000 pid=3253->d0ecfe49-aa79-583f-85c6-85ac97075256 send: 133B guuid=2b42cce3-1900-0000-8816-cf8ebd0c0000 pid=3261 /usr/bin/bash guuid=cd09aee3-1900-0000-8816-cf8ebc0c0000 pid=3260->guuid=2b42cce3-1900-0000-8816-cf8ebd0c0000 pid=3261 clone guuid=b987dce3-1900-0000-8816-cf8ebe0c0000 pid=3262 /usr/bin/sed guuid=cd09aee3-1900-0000-8816-cf8ebc0c0000 pid=3260->guuid=b987dce3-1900-0000-8816-cf8ebe0c0000 pid=3262 execve guuid=a483ece3-1900-0000-8816-cf8ebf0c0000 pid=3263 /usr/bin/cut guuid=cd09aee3-1900-0000-8816-cf8ebc0c0000 pid=3260->guuid=a483ece3-1900-0000-8816-cf8ebf0c0000 pid=3263 execve guuid=1da41be6-1900-0000-8816-cf8ec50c0000 pid=3269->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 164B 75aab096-419b-50ef-be46-7d76b6a90e4c github.com:443 guuid=1da41be6-1900-0000-8816-cf8ec50c0000 pid=3269->75aab096-419b-50ef-be46-7d76b6a90e4c send: 802B f8c5e44f-328d-5324-8bbd-da50752b9120 release-assets.githubusercontent.com:0 guuid=1da41be6-1900-0000-8816-cf8ec50c0000 pid=3269->f8c5e44f-328d-5324-8bbd-da50752b9120 con f0eebea5-e97d-507c-a771-59cac353877c release-assets.githubusercontent.com:443 guuid=1da41be6-1900-0000-8816-cf8ec50c0000 pid=3269->f0eebea5-e97d-507c-a771-59cac353877c send: 1660B guuid=0c5fdb19-1a00-0000-8816-cf8e200d0000 pid=3360 /usr/bin/gzip guuid=af7e5f19-1a00-0000-8816-cf8e1f0d0000 pid=3359->guuid=0c5fdb19-1a00-0000-8816-cf8e200d0000 pid=3360 execve 27958174-7cd5-58aa-a656-dcfbbd6ab520 51.178.73.238:9118 guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->27958174-7cd5-58aa-a656-dcfbbd6ab520 send: 561B guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3428 /usr/lib/dev/systemdev/systemd-mont write-file zombie guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3428 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3429 /usr/lib/dev/systemdev/systemd-mont send-data guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3429 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3430 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3430 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3431 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3431 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3432 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3432 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3446 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3446 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3447 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3447 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3448 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3448 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3449 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3449 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3468 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3468 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3469 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3469 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3470 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3470 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3471 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3471 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3490 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3490 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3491 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3491 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3492 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3492 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3493 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3493 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3513 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3513 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3514 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3514 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3515 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3515 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3516 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3516 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3537 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3537 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3538 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3538 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3539 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3539 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3540 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3540 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3556 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3556 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3557 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3557 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3558 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3558 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3559 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3559 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3564 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3564 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3565 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3565 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3566 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3566 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3567 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3567 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3578 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3578 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3579 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3579 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3580 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3580 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3581 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3581 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3596 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3596 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3597 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3597 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3598 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3598 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3599 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3599 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3609 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3609 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3610 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3610 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3611 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3611 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3612 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3612 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3630 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3630 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3631 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3631 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3632 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3632 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3633 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3633 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3652 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3652 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3653 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3653 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3654 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3654 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3655 /usr/lib/dev/systemdev/systemd-mont guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3417->guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3655 clone guuid=c8983d31-1a00-0000-8816-cf8e590d0000 pid=3429->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 80B
Verdict:
Malicious
Threat:
HEUR:Trojan-Downloader.Shell.Agent
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2025-08-02 11:09:22 UTC
File Type:
Text (Shell)
AV detection:
5 of 38 (13.16%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
antivm discovery execution linux persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Checks CPU configuration
Reads CPU attributes
Creates/modifies Cron job
Enumerates running processes
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments