🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 deca3cb7361c87f0199a3dc7314e7029cf9965df4cbfb5db52e56709b0504c41. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: deca3cb7361c87f0199a3dc7314e7029cf9965df4cbfb5db52e56709b0504c41
SHA3-384 hash: 6332dd5d2cbdd59e93a8ae2df01db411ba056d0aa64c5a11d794331c5db618afac474594011e406126f342a37b551381
SHA1 hash: 99785ef32c4c9ef9ff91597ca6727c188b83dd09
MD5 hash: 2951d7fe65f0f20c6e22ef04a62f91ff
humanhash: seven-hotel-kilo-don
File name:deca3cb7361c87f0199a3dc7314e7029cf9965df4cbfb5db52e56709b0504c41
Download: download sample
Signature CoinMiner
File size:2'797'568 bytes
First seen:2026-09-09 13:00:16 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 49152:yqCeyU99K8VJRNj6ujE+oGGOlAgmfFbJRDANf9wBL+0s3fXMltEYoTN627WPKZOv:yqbBX3Dw+oWl9m3RMNVwjsPGITN6qWPl
TLSH T19DD533152DD9DB2B6FF0E037A17C7420EDE127BA927E84A0B7D5DA75A0A94F50C2C0B4
Magika gzip
Reporter EnthecSolutions
Tags:CoinMiner enthec gz

Intelligence


File Origin
# of uploads :
1
# of downloads :
24
Origin country :
CA CA
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:deca3cb7361c87f0199a3dc7314e7029cf9965df4cbfb5db52e56709b0504c41~
File size:2'958'141 bytes
SHA256 hash: fb10c6c622310b3af2aba7619a836c249e718a1d00edac6c41b694bc1e0704c8
MD5 hash: e60cfc5ff297d17691b995bd271f99af
MIME type:application/x-tar
Signature CoinMiner
Vendor Threat Intelligence
No detections
Gathering data
Verdict:
inconclusive
YARA:
1 match(es)
Tags:
GZip Archive
Threat name:
Linux.Trojan.Malgent
Status:
Malicious
First seen:
2026-09-09 13:00:38 UTC
File Type:
Binary (Archive)
Extracted files:
20
AV detection:
18 of 36 (50.00%)
Threat level:
  5/5
Result
Malware family:
xmrig_linux
Score:
  10/10
Tags:
family:xmrig_linux antivm defense_evasion discovery linux miner persistence privilege_escalation rootkit upx
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
Reads CPU attributes
Checks hardware identifiers (DMI)
Enumerates running processes
Reads hardware information
Removes the immutable protection flag from a file
Write file to user bin folder
File and Directory Permissions Modification
Executes dropped EXE
Loads a kernel module
XMRig Miner payload
Family: xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments