MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dc0a766ad6dfb84cedd35a182d7b19b5579a21c386e76c79b16a7f56e13e625a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: dc0a766ad6dfb84cedd35a182d7b19b5579a21c386e76c79b16a7f56e13e625a
SHA3-384 hash: 9e51cb44ed3f3aa1dd11283e2fd14095e3d3faf3acd735402be401f98a6a24cfac6c9d206042bf5565f8ff0456650504
SHA1 hash: b6018b27b0838239c7b7c266442e8edde714f2f2
MD5 hash: 7687eb7d39b11d3e1f38b2f485153706
humanhash: earth-massachusetts-hawaii-beryllium
File name:all.sh
Download: download sample
Signature CoinMiner
File size:607 bytes
First seen:2025-12-21 12:32:51 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:1XJeGDW/WLCLQorgvML7HXLWxuUgWZFFWoC0E2/QEX:dJ5QWLCdaMrLIuUTF00Gk
TLSH T1AAF07DCA8831DF349C45903F611B8C95E4DAA72E8F4EA5444F59EA30FD1888E6BC7124
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
37
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
evasive
Verdict:
Adware
File Type:
unix shell
First seen:
2025-12-21T09:49:00Z UTC
Last seen:
2025-12-21T10:45:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=28608715-1700-0000-3aaa-3eac090e0000 pid=3593 /usr/bin/sudo guuid=0d49c117-1700-0000-3aaa-3eac0d0e0000 pid=3597 /tmp/sample.bin write-file guuid=28608715-1700-0000-3aaa-3eac090e0000 pid=3593->guuid=0d49c117-1700-0000-3aaa-3eac0d0e0000 pid=3597 execve guuid=05332a18-1700-0000-3aaa-3eac0f0e0000 pid=3599 /usr/bin/nproc guuid=0d49c117-1700-0000-3aaa-3eac0d0e0000 pid=3597->guuid=05332a18-1700-0000-3aaa-3eac0f0e0000 pid=3599 execve guuid=ed91ad18-1700-0000-3aaa-3eac110e0000 pid=3601 /usr/sbin/sysctl write-file guuid=0d49c117-1700-0000-3aaa-3eac0d0e0000 pid=3597->guuid=ed91ad18-1700-0000-3aaa-3eac110e0000 pid=3601 execve guuid=3d24b027-1700-0000-3aaa-3eac370e0000 pid=3639 /usr/bin/ps guuid=0d49c117-1700-0000-3aaa-3eac0d0e0000 pid=3597->guuid=3d24b027-1700-0000-3aaa-3eac370e0000 pid=3639 execve guuid=7053b727-1700-0000-3aaa-3eac380e0000 pid=3640 /usr/bin/grep guuid=0d49c117-1700-0000-3aaa-3eac0d0e0000 pid=3597->guuid=7053b727-1700-0000-3aaa-3eac380e0000 pid=3640 execve guuid=f99abe27-1700-0000-3aaa-3eac390e0000 pid=3641 /usr/bin/grep guuid=0d49c117-1700-0000-3aaa-3eac0d0e0000 pid=3597->guuid=f99abe27-1700-0000-3aaa-3eac390e0000 pid=3641 execve guuid=9e65c527-1700-0000-3aaa-3eac3a0e0000 pid=3642 /usr/bin/mawk guuid=0d49c117-1700-0000-3aaa-3eac0d0e0000 pid=3597->guuid=9e65c527-1700-0000-3aaa-3eac3a0e0000 pid=3642 execve guuid=8090ca27-1700-0000-3aaa-3eac3b0e0000 pid=3643 /usr/bin/xargs guuid=0d49c117-1700-0000-3aaa-3eac0d0e0000 pid=3597->guuid=8090ca27-1700-0000-3aaa-3eac3b0e0000 pid=3643 execve guuid=8c507f2a-1700-0000-3aaa-3eac480e0000 pid=3656 /usr/bin/bash guuid=0d49c117-1700-0000-3aaa-3eac0d0e0000 pid=3597->guuid=8c507f2a-1700-0000-3aaa-3eac480e0000 pid=3656 clone guuid=53a2742b-1700-0000-3aaa-3eac510e0000 pid=3665 /usr/bin/chmod guuid=0d49c117-1700-0000-3aaa-3eac0d0e0000 pid=3597->guuid=53a2742b-1700-0000-3aaa-3eac510e0000 pid=3665 execve guuid=ffe3ba2b-1700-0000-3aaa-3eac530e0000 pid=3667 /usr/bin/bash guuid=0d49c117-1700-0000-3aaa-3eac0d0e0000 pid=3597->guuid=ffe3ba2b-1700-0000-3aaa-3eac530e0000 pid=3667 clone guuid=af34df2b-1700-0000-3aaa-3eac550e0000 pid=3669 /usr/bin/rm delete-file guuid=0d49c117-1700-0000-3aaa-3eac0d0e0000 pid=3597->guuid=af34df2b-1700-0000-3aaa-3eac550e0000 pid=3669 execve guuid=ad6b2d2c-1700-0000-3aaa-3eac570e0000 pid=3671 /usr/bin/mkdir guuid=0d49c117-1700-0000-3aaa-3eac0d0e0000 pid=3597->guuid=ad6b2d2c-1700-0000-3aaa-3eac570e0000 pid=3671 execve guuid=e3f8852c-1700-0000-3aaa-3eac590e0000 pid=3673 /usr/bin/bash guuid=0d49c117-1700-0000-3aaa-3eac0d0e0000 pid=3597->guuid=e3f8852c-1700-0000-3aaa-3eac590e0000 pid=3673 clone guuid=af148d2c-1700-0000-3aaa-3eac5a0e0000 pid=3674 /usr/bin/tar write-file guuid=0d49c117-1700-0000-3aaa-3eac0d0e0000 pid=3597->guuid=af148d2c-1700-0000-3aaa-3eac5a0e0000 pid=3674 execve guuid=4b217858-1700-0000-3aaa-3eac080f0000 pid=3848 /usr/bin/bash guuid=0d49c117-1700-0000-3aaa-3eac0d0e0000 pid=3597->guuid=4b217858-1700-0000-3aaa-3eac080f0000 pid=3848 clone guuid=0a2dfe29-1700-0000-3aaa-3eac440e0000 pid=3652 /usr/bin/kill guuid=8090ca27-1700-0000-3aaa-3eac3b0e0000 pid=3643->guuid=0a2dfe29-1700-0000-3aaa-3eac440e0000 pid=3652 execve guuid=bc09892a-1700-0000-3aaa-3eac490e0000 pid=3657 /usr/bin/grep guuid=8c507f2a-1700-0000-3aaa-3eac480e0000 pid=3656->guuid=bc09892a-1700-0000-3aaa-3eac490e0000 pid=3657 execve guuid=7d58912a-1700-0000-3aaa-3eac4a0e0000 pid=3658 /usr/bin/cut guuid=8c507f2a-1700-0000-3aaa-3eac480e0000 pid=3656->guuid=7d58912a-1700-0000-3aaa-3eac4a0e0000 pid=3658 execve guuid=191d952a-1700-0000-3aaa-3eac4b0e0000 pid=3659 /usr/bin/id guuid=bc09892a-1700-0000-3aaa-3eac490e0000 pid=3657->guuid=191d952a-1700-0000-3aaa-3eac4b0e0000 pid=3659 execve guuid=256c9a2c-1700-0000-3aaa-3eac5b0e0000 pid=3675 /usr/bin/wget net send-data guuid=e3f8852c-1700-0000-3aaa-3eac590e0000 pid=3673->guuid=256c9a2c-1700-0000-3aaa-3eac5b0e0000 pid=3675 execve guuid=72e5e22c-1700-0000-3aaa-3eac5c0e0000 pid=3676 /usr/bin/tar guuid=af148d2c-1700-0000-3aaa-3eac5a0e0000 pid=3674->guuid=72e5e22c-1700-0000-3aaa-3eac5c0e0000 pid=3676 clone 4cbb7cc2-1ba6-59d8-9b21-9f87dab192fe 23.132.164.155:80 guuid=256c9a2c-1700-0000-3aaa-3eac5b0e0000 pid=3675->4cbb7cc2-1ba6-59d8-9b21-9f87dab192fe send: 140B guuid=ab46eb2c-1700-0000-3aaa-3eac5d0e0000 pid=3677 /usr/bin/gzip guuid=72e5e22c-1700-0000-3aaa-3eac5c0e0000 pid=3676->guuid=ab46eb2c-1700-0000-3aaa-3eac5d0e0000 pid=3677 execve guuid=35059458-1700-0000-3aaa-3eac0a0f0000 pid=3850 /root/.../.x/a write-file zombie guuid=4b217858-1700-0000-3aaa-3eac080f0000 pid=3848->guuid=35059458-1700-0000-3aaa-3eac0a0f0000 pid=3850 execve guuid=26652759-1700-0000-3aaa-3eac0e0f0000 pid=3854 /usr/bin/cat guuid=35059458-1700-0000-3aaa-3eac0a0f0000 pid=3850->guuid=26652759-1700-0000-3aaa-3eac0e0f0000 pid=3854 execve guuid=6d286e59-1700-0000-3aaa-3eac0f0f0000 pid=3855 /usr/bin/dash guuid=35059458-1700-0000-3aaa-3eac0a0f0000 pid=3850->guuid=6d286e59-1700-0000-3aaa-3eac0f0f0000 pid=3855 clone guuid=c26a7359-1700-0000-3aaa-3eac100f0000 pid=3856 /usr/bin/grep guuid=35059458-1700-0000-3aaa-3eac0a0f0000 pid=3850->guuid=c26a7359-1700-0000-3aaa-3eac100f0000 pid=3856 execve guuid=8772be59-1700-0000-3aaa-3eac140f0000 pid=3860 /usr/bin/chmod guuid=35059458-1700-0000-3aaa-3eac0a0f0000 pid=3850->guuid=8772be59-1700-0000-3aaa-3eac140f0000 pid=3860 execve guuid=635af659-1700-0000-3aaa-3eac180f0000 pid=3864 /root/.../.x/run write-file zombie guuid=35059458-1700-0000-3aaa-3eac0a0f0000 pid=3850->guuid=635af659-1700-0000-3aaa-3eac180f0000 pid=3864 execve guuid=523f435a-1700-0000-3aaa-3eac190f0000 pid=3865 /usr/bin/nproc guuid=635af659-1700-0000-3aaa-3eac180f0000 pid=3864->guuid=523f435a-1700-0000-3aaa-3eac190f0000 pid=3865 execve guuid=a683845a-1700-0000-3aaa-3eac1b0f0000 pid=3867 /usr/bin/uname guuid=635af659-1700-0000-3aaa-3eac180f0000 pid=3864->guuid=a683845a-1700-0000-3aaa-3eac1b0f0000 pid=3867 execve guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869 /root/.../.x/stak/ld-linux-x86-64.so.2 mprotect-exec net send-data zombie guuid=635af659-1700-0000-3aaa-3eac180f0000 pid=3864->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869 execve 0316afb9-0e3b-5e17-862c-d63b852ace8b 204.93.253.180:80 guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->0316afb9-0e3b-5e17-862c-d63b852ace8b send: 451B guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3890 /root/.../.x/stak/ld-linux-x86-64.so.2 write-file zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3890 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3891 /root/.../.x/stak/ld-linux-x86-64.so.2 guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3891 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3892 /root/.../.x/stak/ld-linux-x86-64.so.2 guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3892 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3893 /root/.../.x/stak/ld-linux-x86-64.so.2 guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3893 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3894 /root/.../.x/stak/ld-linux-x86-64.so.2 guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3894 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3907 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3907 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3909 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3909 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3911 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3911 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3912 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3912 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3933 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3933 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3934 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3934 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3935 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3935 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3936 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3936 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3956 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3956 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3957 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3957 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3958 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3958 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3959 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3959 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3988 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3988 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3989 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3989 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3990 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3990 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3991 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3991 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4011 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4011 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4012 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4012 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4013 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4013 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4014 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4014 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4037 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4037 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4038 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4038 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4039 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4039 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4040 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4040 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4074 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4074 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4075 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4075 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4076 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4076 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4077 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4077 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4106 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4106 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4107 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4107 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4108 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4108 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4109 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4109 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4125 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4125 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4126 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4126 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4127 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4127 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4128 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4128 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4152 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4152 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4153 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4153 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4154 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4154 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4155 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4155 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4181 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4181 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4182 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4182 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4183 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4183 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4184 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4184 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4218 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4218 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4219 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4219 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4220 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4220 clone guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4221 /root/.../.x/stak/ld-linux-x86-64.so.2 zombie guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=3869->guuid=a913c45a-1700-0000-3aaa-3eac1d0f0000 pid=4221 clone
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2025-12-21 12:24:10 UTC
File Type:
Text (Shell)
AV detection:
3 of 24 (12.50%)
Threat level:
  5/5
Result
Malware family:
xmrig_linux
Score:
  10/10
Tags:
family:xmrig family:xmrig_linux antivm defense_evasion discovery execution linux miner persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Checks CPU configuration
Reads CPU attributes
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Enumerates running processes
Reads hardware information
File and Directory Permissions Modification
Executes dropped EXE
XMRig Miner payload
Xmrig family
Xmrig_linux family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Linux_Malware_Indicators_Aug20_1
Author:Florian Roth (Nextron Systems)
Description:Detects indicators often found in linux malware samples. Note: This detection is based on common characteristics typically associated with the mentioned threats, must be considered a clue and does not conclusively prove maliciousness.
Reference:Internal Research
Rule name:SUSP_LNX_Linux_Malware_Indicators_Aug20_1_RID3621
Author:Florian Roth
Description:Detects indicators often found in linux malware samples
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CoinMiner

sh dc0a766ad6dfb84cedd35a182d7b19b5579a21c386e76c79b16a7f56e13e625a

(this sample)

  
Delivery method
Distributed via web download

Comments