MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ce078e93c7b103796d9b9bd506670c794d02863365241e744d3419924e5e0160. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 5


Intelligence 5 IOCs YARA 2 File information Comments

SHA256 hash: ce078e93c7b103796d9b9bd506670c794d02863365241e744d3419924e5e0160
SHA3-384 hash: 57ccea3b791cb32fb8c5bb487c4586b5a19e7dfa8b6d22461ad79efc1ededded172da8513398c6866c14bd61f4d3ef0b
SHA1 hash: a155566331308a8cab77e1a8f4af150f74d121f4
MD5 hash: b668d70afcd2f3eb2f8dc777bf7eb720
humanhash: table-paris-speaker-march
File name:run.sh
Download: download sample
Signature CoinMiner
File size:6'595 bytes
First seen:2025-07-31 09:27:36 UTC
Last seen:2025-08-01 08:00:21 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 192:2I8481zDN1eEXOKD5grqa1ayH+4MeYvNZlu:ovnS9j9cu
TLSH T1BED19401FBC0A6F4659C855C044A1D40694B51177E082C18FCEDB5AAFF28B6C62FDBF6
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.248.53.119:8000/mon.sh1e891ab1521b27923233e694f60fdbf0e1b840e657d8b1ffdefd8b5ef5e38964 CoinMinerCoinMiner
http://162.248.53.119:8000/yes.tar.gzn/an/aopendir
https://github.com/Hansen333/Hansen33-s-DERO-Miner/releases/download/Version-0.6/hansen33s-dero-miner-linux-amd64.tar.gzn/an/an/a

Intelligence


File Origin
# of uploads :
3
# of downloads :
34
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=6342b540-1900-0000-e32a-e010d30f0000 pid=4051 /usr/bin/sudo guuid=9e5f5342-1900-0000-e32a-e010da0f0000 pid=4058 /tmp/sample.bin guuid=6342b540-1900-0000-e32a-e010d30f0000 pid=4051->guuid=9e5f5342-1900-0000-e32a-e010da0f0000 pid=4058 execve guuid=b41efe42-1900-0000-e32a-e010dd0f0000 pid=4061 /usr/bin/systemctl guuid=9e5f5342-1900-0000-e32a-e010da0f0000 pid=4058->guuid=b41efe42-1900-0000-e32a-e010dd0f0000 pid=4061 execve guuid=732b6d45-1900-0000-e32a-e010e70f0000 pid=4071 /usr/bin/bash guuid=9e5f5342-1900-0000-e32a-e010da0f0000 pid=4058->guuid=732b6d45-1900-0000-e32a-e010e70f0000 pid=4071 clone guuid=9d6bf04d-1900-0000-e32a-e01006100000 pid=4102 /usr/bin/bash guuid=9e5f5342-1900-0000-e32a-e010da0f0000 pid=4058->guuid=9d6bf04d-1900-0000-e32a-e01006100000 pid=4102 clone guuid=4ebb934e-1900-0000-e32a-e0100c100000 pid=4108 /usr/bin/id guuid=9e5f5342-1900-0000-e32a-e010da0f0000 pid=4058->guuid=4ebb934e-1900-0000-e32a-e0100c100000 pid=4108 execve guuid=cb794c4f-1900-0000-e32a-e0100f100000 pid=4111 /usr/bin/mkdir guuid=9e5f5342-1900-0000-e32a-e010da0f0000 pid=4058->guuid=cb794c4f-1900-0000-e32a-e0100f100000 pid=4111 execve guuid=f4b40950-1900-0000-e32a-e01013100000 pid=4115 /usr/bin/wget dns net send-data write-file guuid=9e5f5342-1900-0000-e32a-e010da0f0000 pid=4058->guuid=f4b40950-1900-0000-e32a-e01013100000 pid=4115 execve guuid=2af54872-1900-0000-e32a-e01078100000 pid=4216 /usr/bin/tar write-file guuid=9e5f5342-1900-0000-e32a-e010da0f0000 pid=4058->guuid=2af54872-1900-0000-e32a-e01078100000 pid=4216 execve guuid=86737e76-1900-0000-e32a-e0108f100000 pid=4239 /usr/bin/mv guuid=9e5f5342-1900-0000-e32a-e010da0f0000 pid=4058->guuid=86737e76-1900-0000-e32a-e0108f100000 pid=4239 execve guuid=49fbd276-1900-0000-e32a-e01093100000 pid=4243 /usr/bin/rm guuid=9e5f5342-1900-0000-e32a-e010da0f0000 pid=4058->guuid=49fbd276-1900-0000-e32a-e01093100000 pid=4243 execve guuid=af931177-1900-0000-e32a-e01097100000 pid=4247 /usr/bin/chmod guuid=9e5f5342-1900-0000-e32a-e010da0f0000 pid=4058->guuid=af931177-1900-0000-e32a-e01097100000 pid=4247 execve guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4249 /usr/lib/dev/systemdev/systemd-mont dns mprotect-exec send-data zombie guuid=9e5f5342-1900-0000-e32a-e010da0f0000 pid=4058->guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4249 execve guuid=ef1c6377-1900-0000-e32a-e0109a100000 pid=4250 /usr/bin/sleep guuid=9e5f5342-1900-0000-e32a-e010da0f0000 pid=4058->guuid=ef1c6377-1900-0000-e32a-e0109a100000 pid=4250 execve guuid=769fc595-1900-0000-e32a-e01010110000 pid=4368 /usr/bin/ps guuid=9e5f5342-1900-0000-e32a-e010da0f0000 pid=4058->guuid=769fc595-1900-0000-e32a-e01010110000 pid=4368 execve guuid=5931319d-1900-0000-e32a-e01029110000 pid=4393 /usr/bin/sleep guuid=9e5f5342-1900-0000-e32a-e010da0f0000 pid=4058->guuid=5931319d-1900-0000-e32a-e01029110000 pid=4393 execve guuid=5ae2cca9-1a00-0000-e32a-e010c2130000 pid=5058 /usr/bin/ps guuid=9e5f5342-1900-0000-e32a-e010da0f0000 pid=4058->guuid=5ae2cca9-1a00-0000-e32a-e010c2130000 pid=5058 execve guuid=a7adf4b3-1a00-0000-e32a-e010d8130000 pid=5080 /usr/bin/rm guuid=9e5f5342-1900-0000-e32a-e010da0f0000 pid=4058->guuid=a7adf4b3-1a00-0000-e32a-e010d8130000 pid=5080 execve guuid=bf9b5eb4-1a00-0000-e32a-e010d9130000 pid=5081 /usr/bin/rm guuid=9e5f5342-1900-0000-e32a-e010da0f0000 pid=4058->guuid=bf9b5eb4-1a00-0000-e32a-e010d9130000 pid=5081 execve guuid=41e07b45-1900-0000-e32a-e010e90f0000 pid=4073 /usr/bin/wget dns net send-data guuid=732b6d45-1900-0000-e32a-e010e70f0000 pid=4071->guuid=41e07b45-1900-0000-e32a-e010e90f0000 pid=4073 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=41e07b45-1900-0000-e32a-e010e90f0000 pid=4073->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B 0690ccd5-4816-5f11-94dc-7c585f38cdea ipv4.icanhazip.com:0 guuid=41e07b45-1900-0000-e32a-e010e90f0000 pid=4073->0690ccd5-4816-5f11-94dc-7c585f38cdea con d0ecfe49-aa79-583f-85c6-85ac97075256 ipv4.icanhazip.com:80 guuid=41e07b45-1900-0000-e32a-e010e90f0000 pid=4073->d0ecfe49-aa79-583f-85c6-85ac97075256 send: 133B guuid=9826fb4d-1900-0000-e32a-e01007100000 pid=4103 /usr/bin/bash guuid=9d6bf04d-1900-0000-e32a-e01006100000 pid=4102->guuid=9826fb4d-1900-0000-e32a-e01007100000 pid=4103 clone guuid=504f054e-1900-0000-e32a-e01008100000 pid=4104 /usr/bin/sed guuid=9d6bf04d-1900-0000-e32a-e01006100000 pid=4102->guuid=504f054e-1900-0000-e32a-e01008100000 pid=4104 execve guuid=a920174e-1900-0000-e32a-e01009100000 pid=4105 /usr/bin/cut guuid=9d6bf04d-1900-0000-e32a-e01006100000 pid=4102->guuid=a920174e-1900-0000-e32a-e01009100000 pid=4105 execve guuid=f4b40950-1900-0000-e32a-e01013100000 pid=4115->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 164B 75aab096-419b-50ef-be46-7d76b6a90e4c github.com:443 guuid=f4b40950-1900-0000-e32a-e01013100000 pid=4115->75aab096-419b-50ef-be46-7d76b6a90e4c send: 829B f8c5e44f-328d-5324-8bbd-da50752b9120 release-assets.githubusercontent.com:0 guuid=f4b40950-1900-0000-e32a-e01013100000 pid=4115->f8c5e44f-328d-5324-8bbd-da50752b9120 con f0eebea5-e97d-507c-a771-59cac353877c release-assets.githubusercontent.com:443 guuid=f4b40950-1900-0000-e32a-e01013100000 pid=4115->f0eebea5-e97d-507c-a771-59cac353877c send: 1667B guuid=85909d72-1900-0000-e32a-e0107b100000 pid=4219 /usr/bin/gzip guuid=2af54872-1900-0000-e32a-e01078100000 pid=4216->guuid=85909d72-1900-0000-e32a-e0107b100000 pid=4219 execve 527b9e10-ad3e-592b-bdb8-5b9ba29350f7 dero-node-ch4k1pu.mysrv.cloud:443 guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4249->527b9e10-ad3e-592b-bdb8-5b9ba29350f7 send: 279B c493a42f-c32a-53cc-b7d2-5f4949c52772 dero-node-ch4k1pu.mysrv.cloud:10300 guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4249->c493a42f-c32a-53cc-b7d2-5f4949c52772 send: 359B ba76c5c9-61c3-5246-80ac-65f61cd35a66 dero.rabidmining.com:10100 guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4249->ba76c5c9-61c3-5246-80ac-65f61cd35a66 send: 584B 8c74ad8d-fdb0-558a-91aa-3c70123c9668 127.0.0.1:58214 guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4249->8c74ad8d-fdb0-558a-91aa-3c70123c9668 send: 9513B ce4ef018-ef48-5d18-b2c2-ddf892934a6f 127.0.0.1:58220 guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4249->ce4ef018-ef48-5d18-b2c2-ddf892934a6f send: 9513B guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4329 /usr/lib/dev/systemdev/systemd-mont zombie guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4249->guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4329 clone guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4330 /usr/lib/dev/systemdev/systemd-mont guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4249->guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4330 clone guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4331 /usr/lib/dev/systemdev/systemd-mont net send-data zombie guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4249->guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4331 clone guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4333 /usr/lib/dev/systemdev/systemd-mont dns net send-data zombie guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4249->guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4333 clone guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4334 /usr/lib/dev/systemdev/systemd-mont guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4249->guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4334 clone guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4335 /usr/lib/dev/systemdev/systemd-mont guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4249->guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4335 clone guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4556 /usr/lib/dev/systemdev/systemd-mont guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4249->guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4556 clone guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4704 /usr/lib/dev/systemdev/systemd-mont net send-data zombie guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4249->guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4704 clone guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4754 /usr/lib/dev/systemdev/systemd-mont dns net send-data zombie guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4249->guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4754 clone guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5016 /usr/lib/dev/systemdev/systemd-mont mprotect-exec net guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4330->guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5016 execve guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4331->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 45B a7eef23b-3bd8-5389-bd5c-62af93207a18 127.0.0.1:9 guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4331->a7eef23b-3bd8-5389-bd5c-62af93207a18 con a7584e78-d7f5-5f4f-a42d-f2588183f47a ::1:9 guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4331->a7584e78-d7f5-5f4f-a42d-f2588183f47a con guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4333->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 45B guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4333->527b9e10-ad3e-592b-bdb8-5b9ba29350f7 send: 88B guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4333->c493a42f-c32a-53cc-b7d2-5f4949c52772 con guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4333->ba76c5c9-61c3-5246-80ac-65f61cd35a66 send: 661B guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4333->8c74ad8d-fdb0-558a-91aa-3c70123c9668 send: 3697B guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4333->ce4ef018-ef48-5d18-b2c2-ddf892934a6f send: 3697B guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5142 /usr/lib/dev/systemdev/systemd-mont mprotect-exec net guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4556->guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5142 execve guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4704->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 128B guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4704->527b9e10-ad3e-592b-bdb8-5b9ba29350f7 send: 279B guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4754->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 38B guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4754->527b9e10-ad3e-592b-bdb8-5b9ba29350f7 send: 88B guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4754->c493a42f-c32a-53cc-b7d2-5f4949c52772 send: 279B guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4754->ba76c5c9-61c3-5246-80ac-65f61cd35a66 send: 156B guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4754->8c74ad8d-fdb0-558a-91aa-3c70123c9668 send: 15479B guuid=5e6b5577-1900-0000-e32a-e01099100000 pid=4754->ce4ef018-ef48-5d18-b2c2-ddf892934a6f send: 15479B f729ef60-53f8-59ec-91e2-a2ae6cbd2b4b 127.0.0.1:18081 guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5016->f729ef60-53f8-59ec-91e2-a2ae6cbd2b4b con guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5096 /usr/lib/dev/systemdev/systemd-mont guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5016->guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5096 clone guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5097 /usr/lib/dev/systemdev/systemd-mont send-data guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5016->guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5097 clone guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5098 /usr/lib/dev/systemdev/systemd-mont net send-data guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5016->guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5098 clone guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5099 /usr/lib/dev/systemdev/systemd-mont send-data guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5016->guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5099 clone guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5100 /usr/lib/dev/systemdev/systemd-mont send-data guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5016->guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5100 clone guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5101 /usr/lib/dev/systemdev/systemd-mont guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5016->guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5101 clone guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5203 /usr/lib/dev/systemdev/systemd-mont guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5016->guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5203 clone guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5271 /usr/lib/dev/systemdev/systemd-mont send-data guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5016->guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5271 clone guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5097->f729ef60-53f8-59ec-91e2-a2ae6cbd2b4b send: 1083B guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5098->a7eef23b-3bd8-5389-bd5c-62af93207a18 con guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5098->a7584e78-d7f5-5f4f-a42d-f2588183f47a con guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5098->f729ef60-53f8-59ec-91e2-a2ae6cbd2b4b send: 372B guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5099->f729ef60-53f8-59ec-91e2-a2ae6cbd2b4b send: 114B guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5100->f729ef60-53f8-59ec-91e2-a2ae6cbd2b4b send: 200B guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5142->f729ef60-53f8-59ec-91e2-a2ae6cbd2b4b con guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5209 /usr/lib/dev/systemdev/systemd-mont guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5142->guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5209 clone guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5210 /usr/lib/dev/systemdev/systemd-mont send-data guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5142->guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5210 clone guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5212 /usr/lib/dev/systemdev/systemd-mont net guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5142->guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5212 clone guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5214 /usr/lib/dev/systemdev/systemd-mont send-data guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5142->guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5214 clone guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5215 /usr/lib/dev/systemdev/systemd-mont guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5142->guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5215 clone guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5246 /usr/lib/dev/systemdev/systemd-mont send-data guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5142->guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5246 clone guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5258 /usr/lib/dev/systemdev/systemd-mont send-data guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5142->guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5258 clone guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5259 /usr/lib/dev/systemdev/systemd-mont guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5142->guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5259 clone guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5272 /usr/lib/dev/systemdev/systemd-mont send-data guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5142->guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5272 clone guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5210->f729ef60-53f8-59ec-91e2-a2ae6cbd2b4b send: 114B guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5212->a7eef23b-3bd8-5389-bd5c-62af93207a18 con guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5212->a7584e78-d7f5-5f4f-a42d-f2588183f47a con guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5214->f729ef60-53f8-59ec-91e2-a2ae6cbd2b4b send: 1342B guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5246->f729ef60-53f8-59ec-91e2-a2ae6cbd2b4b send: 271B guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5258->f729ef60-53f8-59ec-91e2-a2ae6cbd2b4b send: 568B guuid=6641fd90-1a00-0000-e32a-e01098130000 pid=5271->f729ef60-53f8-59ec-91e2-a2ae6cbd2b4b send: 884B guuid=e730f9ca-1a00-0000-e32a-e01016140000 pid=5272->f729ef60-53f8-59ec-91e2-a2ae6cbd2b4b send: 309B
Threat name:
Script.Trojan.Heuristic
Status:
Malicious
First seen:
2025-07-31 10:34:43 UTC
File Type:
Text (Shell)
AV detection:
5 of 38 (13.16%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:xmrig antivm defense_evasion discovery linux miner upx
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
Reads CPU attributes
UPX packed file
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
XMRig Miner payload
Xmrig family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_SH_CryptoMiner_Indicators_Dec20_1
Author:Florian Roth (Nextron Systems)
Description:Detects helper script used in a crypto miner campaign
Reference:https://www.intezer.com/blog/research/new-golang-worm-drops-xmrig-miner-on-servers/
Rule name:SUSP_LNX_SH_CryptoMiner_Indicators_Dec20_1_RID364E
Author:Florian Roth
Description:Detects helper script used in a crypto miner campaign
Reference:https://www.intezer.com/blog/research/new-golang-worm-drops-xmrig-miner-on-servers/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Distributed via web download

Comments