MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e4e170691634d841e8976ae918d2df223feb359db7f4b1c11a6669618bce648d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: e4e170691634d841e8976ae918d2df223feb359db7f4b1c11a6669618bce648d
SHA3-384 hash: 08879c4332a452997551d92c421e18c8e2e0f902ff670da74d4772b03462920a0fe158d9eacab6dcc2142f6e033dd0ae
SHA1 hash: 79e4ff489199690881a5178dcbce65ce0b5a83ec
MD5 hash: 4c7c33f3c94eb1f64d90a549c379e0ce
humanhash: oregon-snake-freddie-table
File name:bolts
Download: download sample
Signature CoinMiner
File size:1'071 bytes
First seen:2025-12-06 06:15:09 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:wdfGyZ1rFy/iKbpJnHOjWIEQXi/rvsTI0jpXnn:sGc1GH6ECltXn
TLSH T1981154CAA061DC70389C40BCE2865051754A9FBB04D58854B80F367E3F54169F53C73B
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
http://193.34.213.150/nuts/lcn/an/aCoinMiner config ua-wget
http://193.34.213.150/nuts/x2530ebc8e77c784ffe628b3588739ff096a2af4437656144983d1ba04b11538f CoinMinerCoinMiner

Intelligence


File Origin
# of uploads :
1
# of downloads :
35
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-06T06:12:00Z UTC
Last seen:
2025-12-06T06:44:00Z UTC
Hits:
~10
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2025-12-06 06:15:24 UTC
File Type:
Text (Shell)
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux upx
Behaviour
Reads runtime system information
Writes file to tmp directory
Reads CPU attributes
UPX packed file
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CoinMiner

sh e4e170691634d841e8976ae918d2df223feb359db7f4b1c11a6669618bce648d

(this sample)

6823fedd07c424cc3e148c967c0ced89693af2456bb21e2ad17a85564326b8b3

  
Delivery method
Distributed via web download
  
Dropping
MD5 58d6587f74fb87f56a4c5482b86bc8e4
  
Dropping
SHA256 6823fedd07c424cc3e148c967c0ced89693af2456bb21e2ad17a85564326b8b3

Comments