MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 da026a5eeff1dec78606051a1710afae91b24093a3efdbf7e10db6dd600921cd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: da026a5eeff1dec78606051a1710afae91b24093a3efdbf7e10db6dd600921cd
SHA3-384 hash: f8cd3f90b52aab7ce517d38d0aeb25d2cfdab284237cfc43f4ed315491ed4c5ab330bf2032bc5fe33992bae259360347
SHA1 hash: 11656cc4418fb777518d3e871d82a7a17ecb2561
MD5 hash: 69e7f5fb38f80bb28fa92940a5049acf
humanhash: venus-network-mockingbird-alanine
File name:d.sh
Download: download sample
Signature CoinMiner
File size:1'163 bytes
First seen:2025-11-05 14:50:20 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:g2oLDC+cl0kr7za/55AXMVUQutWMGbWkAuOhdXzsgiO96Milf4J37g:ghNll/zAXMyQutpG9AuOhdXQgB96MiqW
TLSH T10B21F38B2071D2722B0E8438079FF046A907504384080A41FACE7B057F79F6AB67779B
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter juroots
Tags:CoinMiner sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
43
Origin country :
CH CH
Vendor Threat Intelligence
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=dbdfdaac-1800-0000-2f1a-7b184b0a0000 pid=2635 /usr/bin/sudo guuid=f2e581ae-1800-0000-2f1a-7b18510a0000 pid=2641 /tmp/sample.bin guuid=dbdfdaac-1800-0000-2f1a-7b184b0a0000 pid=2635->guuid=f2e581ae-1800-0000-2f1a-7b18510a0000 pid=2641 execve guuid=8c54dcae-1800-0000-2f1a-7b18530a0000 pid=2643 /usr/bin/uname guuid=f2e581ae-1800-0000-2f1a-7b18510a0000 pid=2641->guuid=8c54dcae-1800-0000-2f1a-7b18530a0000 pid=2643 execve guuid=36fe24af-1800-0000-2f1a-7b18550a0000 pid=2645 /usr/bin/rm guuid=f2e581ae-1800-0000-2f1a-7b18510a0000 pid=2641->guuid=36fe24af-1800-0000-2f1a-7b18550a0000 pid=2645 execve guuid=bec472af-1800-0000-2f1a-7b18560a0000 pid=2646 /usr/bin/wget net send-data write-file guuid=f2e581ae-1800-0000-2f1a-7b18510a0000 pid=2641->guuid=bec472af-1800-0000-2f1a-7b18560a0000 pid=2646 execve guuid=22df46f6-1800-0000-2f1a-7b18ea0a0000 pid=2794 /usr/bin/chmod guuid=f2e581ae-1800-0000-2f1a-7b18510a0000 pid=2641->guuid=22df46f6-1800-0000-2f1a-7b18ea0a0000 pid=2794 execve guuid=099cacf6-1800-0000-2f1a-7b18eb0a0000 pid=2795 /tmp/mddos net write-file guuid=f2e581ae-1800-0000-2f1a-7b18510a0000 pid=2641->guuid=099cacf6-1800-0000-2f1a-7b18eb0a0000 pid=2795 execve a80c69d1-8dd9-551e-a9f1-850c1b9ddbac 154.12.95.211:80 guuid=bec472af-1800-0000-2f1a-7b18560a0000 pid=2646->a80c69d1-8dd9-551e-a9f1-850c1b9ddbac send: 145B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=099cacf6-1800-0000-2f1a-7b18eb0a0000 pid=2795->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=70effcf6-1800-0000-2f1a-7b18ec0a0000 pid=2796 /tmp/mddos guuid=099cacf6-1800-0000-2f1a-7b18eb0a0000 pid=2795->guuid=70effcf6-1800-0000-2f1a-7b18ec0a0000 pid=2796 clone guuid=5c4602f7-1800-0000-2f1a-7b18ee0a0000 pid=2798 /tmp/mddos net net-scan send-data zombie guuid=099cacf6-1800-0000-2f1a-7b18eb0a0000 pid=2795->guuid=5c4602f7-1800-0000-2f1a-7b18ee0a0000 pid=2798 clone guuid=80c707f7-1800-0000-2f1a-7b18ef0a0000 pid=2799 /tmp/mddos delete-file dns net send-data write-file zombie guuid=099cacf6-1800-0000-2f1a-7b18eb0a0000 pid=2795->guuid=80c707f7-1800-0000-2f1a-7b18ef0a0000 pid=2799 clone guuid=5c4602f7-1800-0000-2f1a-7b18ee0a0000 pid=2798->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5c4602f7-1800-0000-2f1a-7b18ee0a0000 pid=2798|send-data send-data to 4097 IP addresses review logs to see them all guuid=5c4602f7-1800-0000-2f1a-7b18ee0a0000 pid=2798->guuid=5c4602f7-1800-0000-2f1a-7b18ee0a0000 pid=2798|send-data send guuid=7d0cd834-1900-0000-2f1a-7b18710b0000 pid=2929 /tmp/mddos dns net send-data guuid=5c4602f7-1800-0000-2f1a-7b18ee0a0000 pid=2798->guuid=7d0cd834-1900-0000-2f1a-7b18710b0000 pid=2929 clone guuid=f6ef2ecd-1900-0000-2f1a-7b18760c0000 pid=3190 /tmp/mddos dns net send-data guuid=5c4602f7-1800-0000-2f1a-7b18ee0a0000 pid=2798->guuid=f6ef2ecd-1900-0000-2f1a-7b18760c0000 pid=3190 clone guuid=d5126bd7-1900-0000-2f1a-7b18770c0000 pid=3191 /tmp/mddos dns net send-data guuid=5c4602f7-1800-0000-2f1a-7b18ee0a0000 pid=2798->guuid=d5126bd7-1900-0000-2f1a-7b18770c0000 pid=3191 clone guuid=67598312-1b00-0000-2f1a-7b18f80e0000 pid=3832 /tmp/mddos dns net send-data guuid=5c4602f7-1800-0000-2f1a-7b18ee0a0000 pid=2798->guuid=67598312-1b00-0000-2f1a-7b18f80e0000 pid=3832 clone guuid=08c5164f-1b00-0000-2f1a-7b18c40f0000 pid=4036 /tmp/mddos dns net send-data guuid=5c4602f7-1800-0000-2f1a-7b18ee0a0000 pid=2798->guuid=08c5164f-1b00-0000-2f1a-7b18c40f0000 pid=4036 clone guuid=80c707f7-1800-0000-2f1a-7b18ef0a0000 pid=2799->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 40B 4040aa01-6b40-5823-8497-31365418729f www.baojunwakuang.asia:60195 guuid=80c707f7-1800-0000-2f1a-7b18ef0a0000 pid=2799->4040aa01-6b40-5823-8497-31365418729f send: 74B guuid=b2e85c0b-1900-0000-2f1a-7b18160b0000 pid=2838 /usr/bin/dash guuid=80c707f7-1800-0000-2f1a-7b18ef0a0000 pid=2799->guuid=b2e85c0b-1900-0000-2f1a-7b18160b0000 pid=2838 execve guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=3019 /tmp/.dbus-daemon mprotect-exec write-file guuid=80c707f7-1800-0000-2f1a-7b18ef0a0000 pid=2799->guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=3019 execve guuid=80c707f7-1800-0000-2f1a-7b18ef0a0000 pid=3507 /tmp/mddos zombie guuid=80c707f7-1800-0000-2f1a-7b18ef0a0000 pid=2799->guuid=80c707f7-1800-0000-2f1a-7b18ef0a0000 pid=3507 clone guuid=80c707f7-1800-0000-2f1a-7b18ef0a0000 pid=3508 /tmp/mddos guuid=80c707f7-1800-0000-2f1a-7b18ef0a0000 pid=2799->guuid=80c707f7-1800-0000-2f1a-7b18ef0a0000 pid=3508 clone guuid=fc27e40b-1900-0000-2f1a-7b18180b0000 pid=2840 /usr/bin/wget net send-data write-file guuid=b2e85c0b-1900-0000-2f1a-7b18160b0000 pid=2838->guuid=fc27e40b-1900-0000-2f1a-7b18180b0000 pid=2840 execve f5b1d3ba-183d-5692-94d6-585cd31b4a96 www.baojunwakuang.asia:80 guuid=fc27e40b-1900-0000-2f1a-7b18180b0000 pid=2840->f5b1d3ba-183d-5692-94d6-585cd31b4a96 send: 145B guuid=7d0cd834-1900-0000-2f1a-7b18710b0000 pid=2929->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 40B 54bbe27e-32aa-5142-803d-6e30290a2480 www.baojunwakuang.asia:59736 guuid=7d0cd834-1900-0000-2f1a-7b18710b0000 pid=2929->54bbe27e-32aa-5142-803d-6e30290a2480 send: 7B guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=3080 /tmp/.dbus-daemon guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=3019->guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=3080 clone guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=3081 /tmp/.dbus-daemon write-file guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=3019->guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=3081 clone guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=4185 /tmp/.dbus-daemon guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=3019->guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=4185 clone guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5245 /tmp/.dbus-daemon guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=3019->guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5245 clone guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5246 /tmp/.dbus-daemon write-file guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=3019->guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5246 clone guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5247 /tmp/.dbus-daemon write-file guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=3019->guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5247 clone guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5248 /tmp/.dbus-daemon write-file guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=3019->guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5248 clone guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5288 /tmp/.dbus-daemon guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=3019->guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5288 clone guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5289 /tmp/.dbus-daemon guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=3019->guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5289 clone guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5290 /tmp/.dbus-daemon guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=3019->guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5290 clone guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5291 /tmp/.dbus-daemon guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=3019->guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5291 clone guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5292 /tmp/.dbus-daemon guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=3019->guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5292 clone guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5293 /tmp/.dbus-daemon guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=3019->guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5293 clone guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5294 /tmp/.dbus-daemon guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=3019->guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5294 clone guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5295 /tmp/.dbus-daemon guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=3019->guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5295 clone guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5298 /tmp/.dbus-daemon guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=3019->guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5298 clone guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5299 /tmp/.dbus-daemon guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=3019->guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5299 clone guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5300 /tmp/.dbus-daemon guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=3019->guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5300 clone guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5301 /tmp/.dbus-daemon guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=3019->guuid=35e85b6c-1900-0000-2f1a-7b18cb0b0000 pid=5301 clone guuid=f6ef2ecd-1900-0000-2f1a-7b18760c0000 pid=3190->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 40B guuid=f6ef2ecd-1900-0000-2f1a-7b18760c0000 pid=3190->54bbe27e-32aa-5142-803d-6e30290a2480 send: 7B guuid=d5126bd7-1900-0000-2f1a-7b18770c0000 pid=3191->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 40B guuid=d5126bd7-1900-0000-2f1a-7b18770c0000 pid=3191->54bbe27e-32aa-5142-803d-6e30290a2480 send: 7B guuid=67598312-1b00-0000-2f1a-7b18f80e0000 pid=3832->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 80B guuid=67598312-1b00-0000-2f1a-7b18f80e0000 pid=3832->54bbe27e-32aa-5142-803d-6e30290a2480 send: 7B guuid=08c5164f-1b00-0000-2f1a-7b18c40f0000 pid=4036->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 80B guuid=08c5164f-1b00-0000-2f1a-7b18c40f0000 pid=4036->54bbe27e-32aa-5142-803d-6e30290a2480 send: 7B
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2025-11-05 14:53:36 UTC
File Type:
Text (Shell)
AV detection:
4 of 23 (17.39%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:xmrig antivm credential_access defense_evasion discovery linux miner
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads CPU attributes
Reads process memory
Checks hardware identifiers (DMI)
Reads MAC address of network interface
Reads hardware information
File and Directory Permissions Modification
Executes dropped EXE
Contacts a large (23207) amount of remote hosts
Creates a large amount of network flows
XMRig Miner payload
Xmrig family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments