🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e0f6f3de0f1122c31b2e443bb6e855ffeda844dec04d4dcfc6aa9922b74a185d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: e0f6f3de0f1122c31b2e443bb6e855ffeda844dec04d4dcfc6aa9922b74a185d
SHA3-384 hash: ea8f47c3777c9395ea3fec4beab064beb9345717bc718a9c276db7a4bb675f59cf5c33a315fe4c5c5a641f536039555e
SHA1 hash: 868a22403e9ed8f2c3f6762430dc92b428626b2f
MD5 hash: 3eba976641c350af144f4d2420b80fdd
humanhash: shade-sad-spaghetti-kansas
File name:kinst7.sh
Download: download sample
Signature CoinMiner
File size:2'132 bytes
First seen:2026-10-01 17:20:55 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:iUxJYwTcmKJdnE4FTTbPdItnKmhix9YMQ:iZwTh6dEeTTmhbMQ
TLSH T17D411FB5EC385AF273EE543CED6992962B930EB742B63C00714B1D19275D63E6138AA0
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter boredchilada2
Tags:CoinMiner docker sh XMRIG
URLMalware sample (SHA256 hash)SignatureTags
http://154.201.66.125:8899/sysmon.gzn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
CA CA
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-10-01T15:50:00Z UTC
Last seen:
2026-10-01T16:06:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=f369d3f3-1a00-0000-184e-2255db080000 pid=2267 /usr/bin/sudo guuid=98af1cf7-1a00-0000-184e-2255e3080000 pid=2275 /tmp/sample.bin guuid=f369d3f3-1a00-0000-184e-2255db080000 pid=2267->guuid=98af1cf7-1a00-0000-184e-2255e3080000 pid=2275 execve guuid=109390f7-1a00-0000-184e-2255e5080000 pid=2277 /usr/bin/mkdir guuid=98af1cf7-1a00-0000-184e-2255e3080000 pid=2275->guuid=109390f7-1a00-0000-184e-2255e5080000 pid=2277 execve guuid=9c8050f8-1a00-0000-184e-2255e7080000 pid=2279 /usr/bin/dash guuid=98af1cf7-1a00-0000-184e-2255e3080000 pid=2275->guuid=9c8050f8-1a00-0000-184e-2255e7080000 pid=2279 clone guuid=f62d26f9-1a00-0000-184e-2255ec080000 pid=2284 /usr/bin/cat write-file guuid=98af1cf7-1a00-0000-184e-2255e3080000 pid=2275->guuid=f62d26f9-1a00-0000-184e-2255ec080000 pid=2284 execve guuid=b8627bf9-1a00-0000-184e-2255ee080000 pid=2286 /usr/bin/chmod guuid=98af1cf7-1a00-0000-184e-2255e3080000 pid=2275->guuid=b8627bf9-1a00-0000-184e-2255ee080000 pid=2286 execve guuid=4d3bcaf9-1a00-0000-184e-2255f0080000 pid=2288 /usr/bin/cat write-file guuid=98af1cf7-1a00-0000-184e-2255e3080000 pid=2275->guuid=4d3bcaf9-1a00-0000-184e-2255f0080000 pid=2288 execve guuid=e19849fa-1a00-0000-184e-2255f1080000 pid=2289 /usr/bin/chmod guuid=98af1cf7-1a00-0000-184e-2255e3080000 pid=2275->guuid=e19849fa-1a00-0000-184e-2255f1080000 pid=2289 execve guuid=1995d3fa-1a00-0000-184e-2255f2080000 pid=2290 /usr/bin/pgrep guuid=98af1cf7-1a00-0000-184e-2255e3080000 pid=2275->guuid=1995d3fa-1a00-0000-184e-2255f2080000 pid=2290 execve guuid=5b3f2e02-1b00-0000-184e-2255f4080000 pid=2292 /usr/bin/pgrep guuid=98af1cf7-1a00-0000-184e-2255e3080000 pid=2275->guuid=5b3f2e02-1b00-0000-184e-2255f4080000 pid=2292 execve guuid=41e6e707-1b00-0000-184e-2255fe080000 pid=2302 /usr/bin/pgrep guuid=98af1cf7-1a00-0000-184e-2255e3080000 pid=2275->guuid=41e6e707-1b00-0000-184e-2255fe080000 pid=2302 execve guuid=a7ac310d-1b00-0000-184e-225506090000 pid=2310 /usr/bin/dash guuid=98af1cf7-1a00-0000-184e-2255e3080000 pid=2275->guuid=a7ac310d-1b00-0000-184e-225506090000 pid=2310 clone guuid=4b39420d-1b00-0000-184e-225508090000 pid=2312 /usr/bin/sleep guuid=98af1cf7-1a00-0000-184e-2255e3080000 pid=2275->guuid=4b39420d-1b00-0000-184e-225508090000 pid=2312 execve guuid=f249a185-1b00-0000-184e-2255cb090000 pid=2507 /usr/bin/pgrep guuid=98af1cf7-1a00-0000-184e-2255e3080000 pid=2275->guuid=f249a185-1b00-0000-184e-2255cb090000 pid=2507 execve guuid=2cb1aa85-1b00-0000-184e-2255cc090000 pid=2508 /usr/bin/head guuid=98af1cf7-1a00-0000-184e-2255e3080000 pid=2275->guuid=2cb1aa85-1b00-0000-184e-2255cc090000 pid=2508 execve guuid=538b5af8-1a00-0000-184e-2255e8080000 pid=2280 /usr/bin/hostname guuid=9c8050f8-1a00-0000-184e-2255e7080000 pid=2279->guuid=538b5af8-1a00-0000-184e-2255e8080000 pid=2280 execve guuid=664e64f8-1a00-0000-184e-2255e9080000 pid=2281 /usr/bin/tr guuid=9c8050f8-1a00-0000-184e-2255e7080000 pid=2279->guuid=664e64f8-1a00-0000-184e-2255e9080000 pid=2281 execve guuid=5f516bf8-1a00-0000-184e-2255ea080000 pid=2282 /usr/bin/head guuid=9c8050f8-1a00-0000-184e-2255e7080000 pid=2279->guuid=5f516bf8-1a00-0000-184e-2255ea080000 pid=2282 execve guuid=438c370d-1b00-0000-184e-225507090000 pid=2311 /usr/bin/dash zombie guuid=a7ac310d-1b00-0000-184e-225506090000 pid=2310->guuid=438c370d-1b00-0000-184e-225507090000 pid=2311 execve guuid=c7dcde0e-1b00-0000-184e-22550c090000 pid=2316 /usr/bin/curl net send-data guuid=438c370d-1b00-0000-184e-225507090000 pid=2311->guuid=c7dcde0e-1b00-0000-184e-22550c090000 pid=2316 execve c838a6cd-0f3d-5cc4-8392-af52ca523f66 154.201.66.125:8899 guuid=c7dcde0e-1b00-0000-184e-22550c090000 pid=2316->c838a6cd-0f3d-5cc4-8392-af52ca523f66 send: 92B
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2026-09-28 02:51:57 UTC
File Type:
Text (Shell)
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
antivm discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
Reads CPU attributes
Enumerates running processes
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MULTI_Sample_CoinMiner_1ad8694c_Extrait
Author:Marjoriefort
Description:Detects CoinMiner (inconnu, etat extrait)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments