MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d8545d6d4f85bbc568dffbdf69f61e4a27a401f27068ecb0850b8f8bed9857bd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: d8545d6d4f85bbc568dffbdf69f61e4a27a401f27068ecb0850b8f8bed9857bd
SHA3-384 hash: 130058004b1d00210c2cd26a2f723bcc22b2e2cacab78cdcbd80d440827b6b5761aa3bd301f30d8864685a7e95728695
SHA1 hash: ff47220b387bdb8f7fb4b34ced6fb040a4a5bc1f
MD5 hash: ed2747ef5abbb31a0d93cfb1abf42a05
humanhash: arizona-hamper-don-beryllium
File name:deploy_softwaretech.sh
Download: download sample
Signature CoinMiner
File size:13'778 bytes
First seen:2026-06-21 18:31:08 UTC
Last seen:2026-06-22 14:41:46 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 192:2875r4D74COKyAVF1mBt6e4egQq1GZ0HRit4Nmn5PH03/BNGBggGQd:T5FT4LyMiXn5PUQ
TLSH T1BC52A772BA65D57638ACC22C998E9110392B3AEB3618346474ED76043FFC32D51F277A
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh

Intelligence


File Origin
# of uploads :
3
# of downloads :
71
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
bash lolbin
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-21T15:40:00Z UTC
Last seen:
2026-06-23T12:59:00Z UTC
Hits:
~100
Status:
terminated
Behavior Graph:
%3 guuid=7317a937-1900-0000-05ef-90372f140000 pid=5167 /usr/bin/sudo guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168 /tmp/sample.bin write-file guuid=7317a937-1900-0000-05ef-90372f140000 pid=5167->guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168 execve guuid=5208ef3a-1900-0000-05ef-903731140000 pid=5169 /usr/bin/mkdir guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=5208ef3a-1900-0000-05ef-903731140000 pid=5169 execve guuid=4600573b-1900-0000-05ef-903732140000 pid=5170 /usr/bin/date guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=4600573b-1900-0000-05ef-903732140000 pid=5170 execve guuid=99d5fd3b-1900-0000-05ef-903733140000 pid=5171 /usr/bin/bash guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=99d5fd3b-1900-0000-05ef-903733140000 pid=5171 clone guuid=b1bf693c-1900-0000-05ef-903735140000 pid=5173 /usr/bin/date guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=b1bf693c-1900-0000-05ef-903735140000 pid=5173 execve guuid=deabc13c-1900-0000-05ef-903736140000 pid=5174 /usr/bin/date guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=deabc13c-1900-0000-05ef-903736140000 pid=5174 execve guuid=940b473d-1900-0000-05ef-903737140000 pid=5175 /usr/bin/date guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=940b473d-1900-0000-05ef-903737140000 pid=5175 execve guuid=7fd49e3d-1900-0000-05ef-903738140000 pid=5176 /usr/bin/date guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=7fd49e3d-1900-0000-05ef-903738140000 pid=5176 execve guuid=09911f3e-1900-0000-05ef-903739140000 pid=5177 /usr/bin/mkdir guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=09911f3e-1900-0000-05ef-903739140000 pid=5177 execve guuid=3459903e-1900-0000-05ef-90373a140000 pid=5178 /usr/bin/date guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=3459903e-1900-0000-05ef-90373a140000 pid=5178 execve guuid=c6dc063f-1900-0000-05ef-90373b140000 pid=5179 /usr/bin/curl net send-data write-file guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=c6dc063f-1900-0000-05ef-90373b140000 pid=5179 execve guuid=ce387cd4-1900-0000-05ef-903743140000 pid=5187 /usr/bin/date guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=ce387cd4-1900-0000-05ef-903743140000 pid=5187 execve guuid=fd371cd5-1900-0000-05ef-903744140000 pid=5188 /usr/bin/curl net send-data write-file guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=fd371cd5-1900-0000-05ef-903744140000 pid=5188 execve guuid=d87e4cd9-1900-0000-05ef-903745140000 pid=5189 /usr/bin/date guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=d87e4cd9-1900-0000-05ef-903745140000 pid=5189 execve guuid=a57865da-1900-0000-05ef-903746140000 pid=5190 /usr/bin/curl net send-data write-file guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=a57865da-1900-0000-05ef-903746140000 pid=5190 execve guuid=369545e0-1900-0000-05ef-903747140000 pid=5191 /usr/bin/chmod guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=369545e0-1900-0000-05ef-903747140000 pid=5191 execve guuid=7b80c0e3-1900-0000-05ef-903748140000 pid=5192 /usr/bin/date guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=7b80c0e3-1900-0000-05ef-903748140000 pid=5192 execve guuid=58b25be4-1900-0000-05ef-903749140000 pid=5193 /usr/bin/date guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=58b25be4-1900-0000-05ef-903749140000 pid=5193 execve guuid=6e1525e5-1900-0000-05ef-90374a140000 pid=5194 /usr/bin/date guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=6e1525e5-1900-0000-05ef-90374a140000 pid=5194 execve guuid=e4fe78e7-1900-0000-05ef-90374b140000 pid=5195 /usr/bin/bash guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=e4fe78e7-1900-0000-05ef-90374b140000 pid=5195 clone guuid=9a3c20e8-1900-0000-05ef-90374c140000 pid=5196 /usr/bin/mkdir guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=9a3c20e8-1900-0000-05ef-90374c140000 pid=5196 execve guuid=9be6cbe8-1900-0000-05ef-90374d140000 pid=5197 /usr/bin/cat write-file guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=9be6cbe8-1900-0000-05ef-90374d140000 pid=5197 execve guuid=063109ea-1900-0000-05ef-90374e140000 pid=5198 /usr/bin/systemctl guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=063109ea-1900-0000-05ef-90374e140000 pid=5198 execve guuid=751432ec-1900-0000-05ef-90374f140000 pid=5199 /usr/bin/systemctl guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=751432ec-1900-0000-05ef-90374f140000 pid=5199 execve guuid=67db5def-1900-0000-05ef-903750140000 pid=5200 /usr/bin/date guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=67db5def-1900-0000-05ef-903750140000 pid=5200 execve guuid=379146f0-1900-0000-05ef-903751140000 pid=5201 /usr/bin/systemctl guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=379146f0-1900-0000-05ef-903751140000 pid=5201 execve guuid=03f67cf3-1900-0000-05ef-903752140000 pid=5202 /usr/bin/date guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=03f67cf3-1900-0000-05ef-903752140000 pid=5202 execve guuid=fc0adff4-1900-0000-05ef-903753140000 pid=5203 /usr/bin/grep guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=fc0adff4-1900-0000-05ef-903753140000 pid=5203 execve guuid=ae44fdf5-1900-0000-05ef-903754140000 pid=5204 /usr/bin/date guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=ae44fdf5-1900-0000-05ef-903754140000 pid=5204 execve guuid=fe19b7f6-1900-0000-05ef-903755140000 pid=5205 /usr/bin/date guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=fe19b7f6-1900-0000-05ef-903755140000 pid=5205 execve guuid=06bc3ef7-1900-0000-05ef-903756140000 pid=5206 /usr/bin/date guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=06bc3ef7-1900-0000-05ef-903756140000 pid=5206 execve guuid=26c9f4f7-1900-0000-05ef-903757140000 pid=5207 /usr/bin/bash write-file zombie guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=26c9f4f7-1900-0000-05ef-903757140000 pid=5207 execve guuid=13bb16f8-1900-0000-05ef-903758140000 pid=5208 /usr/bin/date guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=13bb16f8-1900-0000-05ef-903758140000 pid=5208 execve guuid=e24cc4f8-1900-0000-05ef-90375a140000 pid=5210 /usr/bin/date guuid=b4df9d39-1900-0000-05ef-903730140000 pid=5168->guuid=e24cc4f8-1900-0000-05ef-90375a140000 pid=5210 execve guuid=633e0d3c-1900-0000-05ef-903734140000 pid=5172 /usr/bin/hostname guuid=99d5fd3b-1900-0000-05ef-903733140000 pid=5171->guuid=633e0d3c-1900-0000-05ef-903734140000 pid=5172 execve 0946dce9-18c0-54b2-ac75-804933e3a0d0 64.89.163.22:80 guuid=c6dc063f-1900-0000-05ef-90373b140000 pid=5179->0946dce9-18c0-54b2-ac75-804933e3a0d0 send: 88B guuid=fd371cd5-1900-0000-05ef-903744140000 pid=5188->0946dce9-18c0-54b2-ac75-804933e3a0d0 send: 87B guuid=a57865da-1900-0000-05ef-903746140000 pid=5190->0946dce9-18c0-54b2-ac75-804933e3a0d0 send: 92B guuid=730bb1f8-1900-0000-05ef-903759140000 pid=5209 /usr/bin/bash guuid=26c9f4f7-1900-0000-05ef-903757140000 pid=5207->guuid=730bb1f8-1900-0000-05ef-903759140000 pid=5209 clone guuid=db69c8f9-1900-0000-05ef-90375c140000 pid=5212 /usr/bin/bash guuid=26c9f4f7-1900-0000-05ef-903757140000 pid=5207->guuid=db69c8f9-1900-0000-05ef-90375c140000 pid=5212 clone guuid=fa34cff9-1900-0000-05ef-90375d140000 pid=5213 /usr/bin/grep guuid=26c9f4f7-1900-0000-05ef-903757140000 pid=5207->guuid=fa34cff9-1900-0000-05ef-90375d140000 pid=5213 execve guuid=c27b42fa-1900-0000-05ef-90375e140000 pid=5214 /usr/bin/mkdir guuid=26c9f4f7-1900-0000-05ef-903757140000 pid=5207->guuid=c27b42fa-1900-0000-05ef-90375e140000 pid=5214 execve guuid=a5b274fb-1900-0000-05ef-90375f140000 pid=5215 /usr/bin/date guuid=26c9f4f7-1900-0000-05ef-903757140000 pid=5207->guuid=a5b274fb-1900-0000-05ef-90375f140000 pid=5215 execve guuid=6e09d9fc-1900-0000-05ef-903760140000 pid=5216 /usr/bin/date guuid=26c9f4f7-1900-0000-05ef-903757140000 pid=5207->guuid=6e09d9fc-1900-0000-05ef-903760140000 pid=5216 execve guuid=f297b9fd-1900-0000-05ef-903761140000 pid=5217 /usr/bin/date guuid=26c9f4f7-1900-0000-05ef-903757140000 pid=5207->guuid=f297b9fd-1900-0000-05ef-903761140000 pid=5217 execve guuid=5a2b87fe-1900-0000-05ef-903762140000 pid=5218 /usr/bin/ps guuid=26c9f4f7-1900-0000-05ef-903757140000 pid=5207->guuid=5a2b87fe-1900-0000-05ef-903762140000 pid=5218 execve guuid=4ae191fe-1900-0000-05ef-903763140000 pid=5219 /usr/bin/grep guuid=26c9f4f7-1900-0000-05ef-903757140000 pid=5207->guuid=4ae191fe-1900-0000-05ef-903763140000 pid=5219 execve guuid=18aa3406-1a00-0000-05ef-903764140000 pid=5220 /usr/bin/date guuid=26c9f4f7-1900-0000-05ef-903757140000 pid=5207->guuid=18aa3406-1a00-0000-05ef-903764140000 pid=5220 execve guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221 /root/softwaretechreview/softwaretech mprotect-exec net send-data write-file guuid=26c9f4f7-1900-0000-05ef-903757140000 pid=5207->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221 execve guuid=5930e206-1a00-0000-05ef-903766140000 pid=5222 /usr/bin/date guuid=26c9f4f7-1900-0000-05ef-903757140000 pid=5207->guuid=5930e206-1a00-0000-05ef-903766140000 pid=5222 execve guuid=fdc27407-1a00-0000-05ef-903767140000 pid=5223 /usr/bin/sleep guuid=26c9f4f7-1900-0000-05ef-903757140000 pid=5207->guuid=fdc27407-1a00-0000-05ef-903767140000 pid=5223 execve guuid=fb08c886-1d00-0000-05ef-9037bd140000 pid=5309 /usr/bin/bash guuid=26c9f4f7-1900-0000-05ef-903757140000 pid=5207->guuid=fb08c886-1d00-0000-05ef-9037bd140000 pid=5309 clone guuid=67866887-1d00-0000-05ef-9037bf140000 pid=5311 /usr/bin/bash guuid=26c9f4f7-1900-0000-05ef-903757140000 pid=5207->guuid=67866887-1d00-0000-05ef-9037bf140000 pid=5311 clone guuid=3b597587-1d00-0000-05ef-9037c0140000 pid=5312 /usr/bin/grep guuid=26c9f4f7-1900-0000-05ef-903757140000 pid=5207->guuid=3b597587-1d00-0000-05ef-9037c0140000 pid=5312 execve guuid=4957f787-1d00-0000-05ef-9037c1140000 pid=5313 /usr/bin/sleep guuid=26c9f4f7-1900-0000-05ef-903757140000 pid=5207->guuid=4957f787-1d00-0000-05ef-9037c1140000 pid=5313 execve guuid=7a459a06-2100-0000-05ef-9037c2140000 pid=5314 /usr/bin/bash guuid=26c9f4f7-1900-0000-05ef-903757140000 pid=5207->guuid=7a459a06-2100-0000-05ef-9037c2140000 pid=5314 clone guuid=3fdc4507-2100-0000-05ef-9037c4140000 pid=5316 /usr/bin/bash guuid=26c9f4f7-1900-0000-05ef-903757140000 pid=5207->guuid=3fdc4507-2100-0000-05ef-9037c4140000 pid=5316 clone guuid=dbf95307-2100-0000-05ef-9037c5140000 pid=5317 /usr/bin/grep guuid=26c9f4f7-1900-0000-05ef-903757140000 pid=5207->guuid=dbf95307-2100-0000-05ef-9037c5140000 pid=5317 execve guuid=aee4fb07-2100-0000-05ef-9037c6140000 pid=5318 /usr/bin/sleep guuid=26c9f4f7-1900-0000-05ef-903757140000 pid=5207->guuid=aee4fb07-2100-0000-05ef-9037c6140000 pid=5318 execve guuid=026bb386-2400-0000-05ef-9037c7140000 pid=5319 /usr/bin/bash guuid=26c9f4f7-1900-0000-05ef-903757140000 pid=5207->guuid=026bb386-2400-0000-05ef-9037c7140000 pid=5319 clone guuid=f0e44687-2400-0000-05ef-9037c9140000 pid=5321 /usr/bin/bash guuid=26c9f4f7-1900-0000-05ef-903757140000 pid=5207->guuid=f0e44687-2400-0000-05ef-9037c9140000 pid=5321 clone guuid=68265087-2400-0000-05ef-9037ca140000 pid=5322 /usr/bin/grep guuid=26c9f4f7-1900-0000-05ef-903757140000 pid=5207->guuid=68265087-2400-0000-05ef-9037ca140000 pid=5322 execve guuid=03d6c687-2400-0000-05ef-9037cb140000 pid=5323 /usr/bin/sleep guuid=26c9f4f7-1900-0000-05ef-903757140000 pid=5207->guuid=03d6c687-2400-0000-05ef-9037cb140000 pid=5323 execve guuid=c8e2eaf8-1900-0000-05ef-90375b140000 pid=5211 /usr/bin/cat guuid=730bb1f8-1900-0000-05ef-903759140000 pid=5209->guuid=c8e2eaf8-1900-0000-05ef-90375b140000 pid=5211 execve 8c601206-37b0-591d-baf4-afdc681be666 80.96.113.59:8057 guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->8c601206-37b0-591d-baf4-afdc681be666 send: 467B guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5225 /root/softwaretechreview/softwaretech write-file guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5225 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5226 /root/softwaretechreview/softwaretech write-file guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5226 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5227 /root/softwaretechreview/softwaretech write-file guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5227 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5228 /root/softwaretechreview/softwaretech write-file guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5228 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5229 /root/softwaretechreview/softwaretech write-file guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5229 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5235 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5235 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5236 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5236 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5237 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5237 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5238 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5238 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5239 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5239 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5240 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5240 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5241 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5241 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5242 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5242 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5243 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5243 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5244 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5244 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5245 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5245 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5246 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5246 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5247 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5247 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5248 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5248 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5249 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5249 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5250 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5250 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5251 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5251 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5252 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5252 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5253 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5253 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5254 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5254 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5255 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5255 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5256 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5256 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5257 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5257 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5258 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5258 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5259 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5259 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5260 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5260 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5261 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5261 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5262 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5262 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5263 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5263 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5264 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5264 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5265 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5265 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5266 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5266 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5274 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5274 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5275 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5275 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5276 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5276 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5277 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5277 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5278 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5278 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5279 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5279 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5280 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5280 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5281 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5281 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5282 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5282 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5283 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5283 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5284 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5284 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5285 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5285 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5287 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5287 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5288 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5288 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5289 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5289 clone guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5290 /root/softwaretechreview/softwaretech guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5221->guuid=c3a2c006-1a00-0000-05ef-903765140000 pid=5290 clone guuid=9777e486-1d00-0000-05ef-9037be140000 pid=5310 /usr/bin/cat guuid=fb08c886-1d00-0000-05ef-9037bd140000 pid=5309->guuid=9777e486-1d00-0000-05ef-9037be140000 pid=5310 execve guuid=699bb506-2100-0000-05ef-9037c3140000 pid=5315 /usr/bin/cat guuid=7a459a06-2100-0000-05ef-9037c2140000 pid=5314->guuid=699bb506-2100-0000-05ef-9037c3140000 pid=5315 execve guuid=c56dcd86-2400-0000-05ef-9037c8140000 pid=5320 /usr/bin/cat guuid=026bb386-2400-0000-05ef-9037c7140000 pid=5319->guuid=c56dcd86-2400-0000-05ef-9037c8140000 pid=5320 execve
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-06-14 10:54:41 UTC
File Type:
Text (Shell)
AV detection:
6 of 23 (26.09%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:xmrig antivm defense_evasion discovery execution linux miner persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads CPU attributes
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Enumerates running processes
Reads hardware information
File and Directory Permissions Modification
Executes dropped EXE
Family: xmrig
XMRig Miner payload
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CoinMiner

sh d8545d6d4f85bbc568dffbdf69f61e4a27a401f27068ecb0850b8f8bed9857bd

(this sample)

  
Delivery method
Distributed via web download

Comments