MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ee32c7c0b480bbd90e51f4d44d5e53cea5b149defbcd2aa9e306716d418503d4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 10


Intelligence 10 IOCs YARA 4 File information Comments

SHA256 hash: ee32c7c0b480bbd90e51f4d44d5e53cea5b149defbcd2aa9e306716d418503d4
SHA3-384 hash: b3922ae544859d83b5112b7b049792ad5300e9ffc3b535cfb8db964b72dda610cc43b281378cdbd7f5f276a7df22b307
SHA1 hash: 4ada04c1cef91062e7ef9226b3867ed22fee320a
MD5 hash: 42c8eb25ed22f756b23a87afff41b681
humanhash: mississippi-washington-early-vegan
File name:dropfix
Download: download sample
Signature CoinMiner
File size:1'486'560 bytes
First seen:2025-11-23 21:21:27 UTC
Last seen:2025-11-25 05:18:50 UTC
File type: elf
MIME type:application/x-executable
ssdeep 24576:I12ERqAlDbl0WY6KZ9Hn4kkTU/k9kPbY62cao8gOV15iDfsDlP:I/Fl10l9Hn4kWU/k9k062vXPV156fsDV
TLSH T11F656C5BF2B364FCC19BC030479BD6A3A930742452323E7B65C4DA312E66E245B6DB72
telfhash t13212ddb44afa35f0a6d3d902e363f4b59972196625f835f06656bc84ef81f800c6ec27
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter juroots
Tags:CoinMiner elf

Intelligence


File Origin
# of uploads :
2
# of downloads :
34
Origin country :
IL IL
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Deleting a recently created file
Sends data to a server
Launching a process
Collects information on the CPU
Sets a written file as executable
Changes the time when the file was created, accessed, or modified
Opens a port
Creates or modifies symbolic links
Changes owner for a written file
Receives data from a server
Creating a file
Locks files
Collects information on the network activity
Runs as daemon
DNS request
Connection attempt
Changes access rights for a written file
Gains root access
Creating a process from a recently created file
Creates directories in a temporary directory
Collects information on the RAM
Creates directories
Creating a file in the %temp% directory
Creating a file in the %temp% subdirectories
Substitutes an application name
Loading a system driver
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
gcc miner
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
not packed
Botnet:
unknown
Number of open files:
56
Number of processes launched:
9
Processes remaning?
true
Remote TCP ports scanned:
not identified
Behaviour
Process Renaming
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Verdict:
Malicious
File Type:
elf.64.le
First seen:
2025-11-23T16:42:00Z UTC
Last seen:
2025-11-23T20:36:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan.Linux.Agent.gen
Status:
terminated
Behavior Graph:
%3 guuid=8f6c9688-1900-0000-d1b8-969965140000 pid=5221 /usr/bin/sudo guuid=7b72608a-1900-0000-d1b8-969966140000 pid=5222 /tmp/sample.bin write-file guuid=8f6c9688-1900-0000-d1b8-969965140000 pid=5221->guuid=7b72608a-1900-0000-d1b8-969966140000 pid=5222 execve guuid=2336908a-1900-0000-d1b8-969967140000 pid=5223 /tmp/sample.bin delete-file net send-data write-file zombie guuid=7b72608a-1900-0000-d1b8-969966140000 pid=5222->guuid=2336908a-1900-0000-d1b8-969967140000 pid=5223 clone 89b8c3d5-4efb-5c03-96bf-bbf3983f3298 188.114.96.3:80 guuid=2336908a-1900-0000-d1b8-969967140000 pid=5223->89b8c3d5-4efb-5c03-96bf-bbf3983f3298 send: 47B 816883ca-b21b-552a-98bc-9d857cd28586 188.114.97.3:80 guuid=2336908a-1900-0000-d1b8-969967140000 pid=5223->816883ca-b21b-552a-98bc-9d857cd28586 send: 41B 54d92a3b-1447-55af-b534-047898c60c8d 1.1.1.1:53 guuid=2336908a-1900-0000-d1b8-969967140000 pid=5223->54d92a3b-1447-55af-b534-047898c60c8d send: 61B guuid=a503358c-1900-0000-d1b8-969968140000 pid=5224 /usr/bin/dash guuid=2336908a-1900-0000-d1b8-969967140000 pid=5223->guuid=a503358c-1900-0000-d1b8-969968140000 pid=5224 execve guuid=fe70aee6-1900-0000-d1b8-969970140000 pid=5232 /usr/bin/dash guuid=2336908a-1900-0000-d1b8-969967140000 pid=5223->guuid=fe70aee6-1900-0000-d1b8-969970140000 pid=5232 execve guuid=c7dc090d-1a00-0000-d1b8-969975140000 pid=5237 /usr/bin/dash guuid=2336908a-1900-0000-d1b8-969967140000 pid=5223->guuid=c7dc090d-1a00-0000-d1b8-969975140000 pid=5237 execve guuid=788efb64-1a00-0000-d1b8-969984140000 pid=5252 /usr/bin/dash guuid=2336908a-1900-0000-d1b8-969967140000 pid=5223->guuid=788efb64-1a00-0000-d1b8-969984140000 pid=5252 execve guuid=dca8e269-1a00-0000-d1b8-969987140000 pid=5255 /usr/bin/dash guuid=2336908a-1900-0000-d1b8-969967140000 pid=5223->guuid=dca8e269-1a00-0000-d1b8-969987140000 pid=5255 execve guuid=ad91442b-1b00-0000-d1b8-9699a7140000 pid=5287 /usr/bin/dash guuid=2336908a-1900-0000-d1b8-969967140000 pid=5223->guuid=ad91442b-1b00-0000-d1b8-9699a7140000 pid=5287 execve guuid=46f9412e-1b00-0000-d1b8-9699aa140000 pid=5290 /usr/bin/dash guuid=2336908a-1900-0000-d1b8-969967140000 pid=5223->guuid=46f9412e-1b00-0000-d1b8-9699aa140000 pid=5290 execve guuid=2336908a-1900-0000-d1b8-969967140000 pid=5367 /tmp/sample.bin guuid=2336908a-1900-0000-d1b8-969967140000 pid=5223->guuid=2336908a-1900-0000-d1b8-969967140000 pid=5367 clone guuid=6076c18c-1900-0000-d1b8-969969140000 pid=5225 /usr/sbin/useradd delete-file write-config write-file guuid=a503358c-1900-0000-d1b8-969968140000 pid=5224->guuid=6076c18c-1900-0000-d1b8-969969140000 pid=5225 execve guuid=b51e97e4-1900-0000-d1b8-96996a140000 pid=5226 /usr/sbin/useradd guuid=6076c18c-1900-0000-d1b8-969969140000 pid=5225->guuid=b51e97e4-1900-0000-d1b8-96996a140000 pid=5226 clone guuid=5421d9e4-1900-0000-d1b8-96996b140000 pid=5227 /usr/sbin/useradd guuid=6076c18c-1900-0000-d1b8-969969140000 pid=5225->guuid=5421d9e4-1900-0000-d1b8-96996b140000 pid=5227 clone guuid=f05d13e5-1900-0000-d1b8-96996c140000 pid=5228 /usr/sbin/useradd guuid=6076c18c-1900-0000-d1b8-969969140000 pid=5225->guuid=f05d13e5-1900-0000-d1b8-96996c140000 pid=5228 clone guuid=0d2151e5-1900-0000-d1b8-96996d140000 pid=5229 /usr/sbin/useradd guuid=6076c18c-1900-0000-d1b8-969969140000 pid=5225->guuid=0d2151e5-1900-0000-d1b8-96996d140000 pid=5229 clone guuid=c9b58ce5-1900-0000-d1b8-96996e140000 pid=5230 /usr/sbin/useradd guuid=6076c18c-1900-0000-d1b8-969969140000 pid=5225->guuid=c9b58ce5-1900-0000-d1b8-96996e140000 pid=5230 clone guuid=c8bcc5e5-1900-0000-d1b8-96996f140000 pid=5231 /usr/sbin/useradd guuid=6076c18c-1900-0000-d1b8-969969140000 pid=5225->guuid=c8bcc5e5-1900-0000-d1b8-96996f140000 pid=5231 clone guuid=2c5c56e7-1900-0000-d1b8-969971140000 pid=5233 /usr/bin/dash guuid=fe70aee6-1900-0000-d1b8-969970140000 pid=5232->guuid=2c5c56e7-1900-0000-d1b8-969971140000 pid=5233 clone guuid=8f9c78e7-1900-0000-d1b8-969972140000 pid=5234 /usr/sbin/chpasswd write-config guuid=fe70aee6-1900-0000-d1b8-969970140000 pid=5232->guuid=8f9c78e7-1900-0000-d1b8-969972140000 pid=5234 execve guuid=fff3ac0c-1a00-0000-d1b8-969973140000 pid=5235 /usr/sbin/chpasswd guuid=8f9c78e7-1900-0000-d1b8-969972140000 pid=5234->guuid=fff3ac0c-1a00-0000-d1b8-969973140000 pid=5235 clone guuid=a7a8c80c-1a00-0000-d1b8-969974140000 pid=5236 /usr/sbin/chpasswd guuid=8f9c78e7-1900-0000-d1b8-969972140000 pid=5234->guuid=a7a8c80c-1a00-0000-d1b8-969974140000 pid=5236 clone guuid=2d60450d-1a00-0000-d1b8-969976140000 pid=5238 /usr/sbin/usermod delete-file write-config guuid=c7dc090d-1a00-0000-d1b8-969975140000 pid=5237->guuid=2d60450d-1a00-0000-d1b8-969976140000 pid=5238 execve guuid=0edfc63e-1a00-0000-d1b8-96997e140000 pid=5246 /usr/sbin/usermod guuid=2d60450d-1a00-0000-d1b8-969976140000 pid=5238->guuid=0edfc63e-1a00-0000-d1b8-96997e140000 pid=5246 clone guuid=5d00dd3e-1a00-0000-d1b8-96997f140000 pid=5247 /usr/sbin/usermod guuid=2d60450d-1a00-0000-d1b8-969976140000 pid=5238->guuid=5d00dd3e-1a00-0000-d1b8-96997f140000 pid=5247 clone guuid=c3d8f93e-1a00-0000-d1b8-969980140000 pid=5248 /usr/sbin/usermod guuid=2d60450d-1a00-0000-d1b8-969976140000 pid=5238->guuid=c3d8f93e-1a00-0000-d1b8-969980140000 pid=5248 clone guuid=eeb0153f-1a00-0000-d1b8-969981140000 pid=5249 /usr/sbin/usermod guuid=2d60450d-1a00-0000-d1b8-969976140000 pid=5238->guuid=eeb0153f-1a00-0000-d1b8-969981140000 pid=5249 clone guuid=02e3303f-1a00-0000-d1b8-969982140000 pid=5250 /usr/sbin/usermod guuid=2d60450d-1a00-0000-d1b8-969976140000 pid=5238->guuid=02e3303f-1a00-0000-d1b8-969982140000 pid=5250 clone guuid=5976453f-1a00-0000-d1b8-969983140000 pid=5251 /usr/sbin/usermod guuid=2d60450d-1a00-0000-d1b8-969976140000 pid=5238->guuid=5976453f-1a00-0000-d1b8-969983140000 pid=5251 clone guuid=359f8965-1a00-0000-d1b8-969985140000 pid=5253 /usr/bin/sudo net guuid=788efb64-1a00-0000-d1b8-969984140000 pid=5252->guuid=359f8965-1a00-0000-d1b8-969985140000 pid=5253 execve 0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 10.0.2.15:0 guuid=359f8965-1a00-0000-d1b8-969985140000 pid=5253->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con 558177e1-1f18-5f39-990b-d68b1c194e8a fec0::5054:ff:fe12:3456:0 guuid=359f8965-1a00-0000-d1b8-969985140000 pid=5253->558177e1-1f18-5f39-990b-d68b1c194e8a con cbc59886-1795-52e1-b014-449ae22fd09b fe80::5054:ff:fe12:3456:0 guuid=359f8965-1a00-0000-d1b8-969985140000 pid=5253->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=80710d69-1a00-0000-d1b8-969986140000 pid=5254 /usr/bin/true guuid=359f8965-1a00-0000-d1b8-969985140000 pid=5253->guuid=80710d69-1a00-0000-d1b8-969986140000 pid=5254 execve guuid=a47c3a6a-1a00-0000-d1b8-969988140000 pid=5256 /usr/bin/sudo net zombie guuid=dca8e269-1a00-0000-d1b8-969987140000 pid=5255->guuid=a47c3a6a-1a00-0000-d1b8-969988140000 pid=5256 execve guuid=a47c3a6a-1a00-0000-d1b8-969988140000 pid=5256->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=a47c3a6a-1a00-0000-d1b8-969988140000 pid=5256->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=a47c3a6a-1a00-0000-d1b8-969988140000 pid=5256->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=c673926c-1a00-0000-d1b8-969989140000 pid=5257 /tmp/X11VNC write-file guuid=a47c3a6a-1a00-0000-d1b8-969988140000 pid=5256->guuid=c673926c-1a00-0000-d1b8-969989140000 pid=5257 execve guuid=a289766f-1a00-0000-d1b8-96998a140000 pid=5258 /tmp/X11VNC guuid=c673926c-1a00-0000-d1b8-969989140000 pid=5257->guuid=a289766f-1a00-0000-d1b8-96998a140000 pid=5258 clone guuid=be368d6f-1a00-0000-d1b8-96998b140000 pid=5259 /usr/bin/dash guuid=a289766f-1a00-0000-d1b8-96998a140000 pid=5258->guuid=be368d6f-1a00-0000-d1b8-96998b140000 pid=5259 execve guuid=bb8d0c8f-1a00-0000-d1b8-969991140000 pid=5265 /usr/bin/dash guuid=a289766f-1a00-0000-d1b8-96998a140000 pid=5258->guuid=bb8d0c8f-1a00-0000-d1b8-969991140000 pid=5265 execve guuid=2ca1fe8f-1a00-0000-d1b8-969993140000 pid=5267 /usr/bin/dash guuid=a289766f-1a00-0000-d1b8-96998a140000 pid=5258->guuid=2ca1fe8f-1a00-0000-d1b8-969993140000 pid=5267 execve guuid=8bafab90-1a00-0000-d1b8-969994140000 pid=5268 /usr/bin/dash guuid=a289766f-1a00-0000-d1b8-96998a140000 pid=5258->guuid=8bafab90-1a00-0000-d1b8-969994140000 pid=5268 execve guuid=3fb11a92-1a00-0000-d1b8-969995140000 pid=5269 /usr/bin/dash guuid=a289766f-1a00-0000-d1b8-96998a140000 pid=5258->guuid=3fb11a92-1a00-0000-d1b8-969995140000 pid=5269 execve guuid=98ce9c92-1a00-0000-d1b8-969996140000 pid=5270 /usr/bin/dash guuid=a289766f-1a00-0000-d1b8-96998a140000 pid=5258->guuid=98ce9c92-1a00-0000-d1b8-969996140000 pid=5270 execve guuid=ce3f1193-1a00-0000-d1b8-969997140000 pid=5271 /usr/bin/dash guuid=a289766f-1a00-0000-d1b8-96998a140000 pid=5258->guuid=ce3f1193-1a00-0000-d1b8-969997140000 pid=5271 execve guuid=383c8e93-1a00-0000-d1b8-969998140000 pid=5272 /usr/bin/dash guuid=a289766f-1a00-0000-d1b8-96998a140000 pid=5258->guuid=383c8e93-1a00-0000-d1b8-969998140000 pid=5272 execve guuid=d60f3570-1a00-0000-d1b8-96998c140000 pid=5260 /usr/sbin/xtables-nft-multi guuid=be368d6f-1a00-0000-d1b8-96998b140000 pid=5259->guuid=d60f3570-1a00-0000-d1b8-96998c140000 pid=5260 execve guuid=22e3458f-1a00-0000-d1b8-969992140000 pid=5266 /usr/sbin/xtables-nft-multi guuid=bb8d0c8f-1a00-0000-d1b8-969991140000 pid=5265->guuid=22e3458f-1a00-0000-d1b8-969992140000 pid=5266 execve guuid=c082852b-1b00-0000-d1b8-9699a8140000 pid=5288 /usr/bin/sudo net guuid=ad91442b-1b00-0000-d1b8-9699a7140000 pid=5287->guuid=c082852b-1b00-0000-d1b8-9699a8140000 pid=5288 execve guuid=c082852b-1b00-0000-d1b8-9699a8140000 pid=5288->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=c082852b-1b00-0000-d1b8-9699a8140000 pid=5288->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=c082852b-1b00-0000-d1b8-9699a8140000 pid=5288->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=28f8d72d-1b00-0000-d1b8-9699a9140000 pid=5289 /usr/bin/true guuid=c082852b-1b00-0000-d1b8-9699a8140000 pid=5288->guuid=28f8d72d-1b00-0000-d1b8-9699a9140000 pid=5289 execve guuid=a6a76f2e-1b00-0000-d1b8-9699ab140000 pid=5291 /usr/bin/sudo net zombie guuid=46f9412e-1b00-0000-d1b8-9699aa140000 pid=5290->guuid=a6a76f2e-1b00-0000-d1b8-9699ab140000 pid=5291 execve guuid=a6a76f2e-1b00-0000-d1b8-9699ab140000 pid=5291->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=a6a76f2e-1b00-0000-d1b8-9699ab140000 pid=5291->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=a6a76f2e-1b00-0000-d1b8-9699ab140000 pid=5291->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=1d894430-1b00-0000-d1b8-9699ac140000 pid=5292 /tmp/nwatchdog/d net send-data write-file guuid=a6a76f2e-1b00-0000-d1b8-9699ab140000 pid=5291->guuid=1d894430-1b00-0000-d1b8-9699ac140000 pid=5292 execve ab818c20-8994-51fa-a320-92a8eebfa876 138.201.134.231:80 guuid=1d894430-1b00-0000-d1b8-9699ac140000 pid=5292->ab818c20-8994-51fa-a320-92a8eebfa876 send: 88B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=1d894430-1b00-0000-d1b8-9699ac140000 pid=5292->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 36B guuid=0270e73b-1b00-0000-d1b8-9699af140000 pid=5295 /usr/bin/dash guuid=1d894430-1b00-0000-d1b8-9699ac140000 pid=5292->guuid=0270e73b-1b00-0000-d1b8-9699af140000 pid=5295 execve guuid=24da153c-1b00-0000-d1b8-9699b0140000 pid=5296 /tmp/nwatchdog/NovolineM mprotect-exec write-file guuid=0270e73b-1b00-0000-d1b8-9699af140000 pid=5295->guuid=24da153c-1b00-0000-d1b8-9699b0140000 pid=5296 execve guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313 /tmp/nwatchdog/NovolineM net send-data zombie guuid=24da153c-1b00-0000-d1b8-9699b0140000 pid=5296->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313 clone f7f0ca7d-f2b1-5314-88d5-c257f654234e 88.156.30.96:2137 guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->f7f0ca7d-f2b1-5314-88d5-c257f654234e send: 419B guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5314 /tmp/nwatchdog/NovolineM write-file zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5314 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5315 /tmp/nwatchdog/NovolineM send-data zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5315 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5316 /tmp/nwatchdog/NovolineM guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5316 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5317 /tmp/nwatchdog/NovolineM guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5317 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5318 /tmp/nwatchdog/NovolineM guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5318 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5319 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5319 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5320 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5320 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5321 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5321 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5322 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5322 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5323 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5323 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5324 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5324 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5325 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5325 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5326 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5326 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5327 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5327 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5328 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5328 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5329 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5329 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5330 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5330 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5331 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5331 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5332 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5332 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5333 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5333 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5334 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5334 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5335 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5335 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5336 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5336 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5337 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5337 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5338 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5338 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5339 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5339 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5340 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5340 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5341 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5341 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5342 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5342 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5343 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5343 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5344 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5344 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5345 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5345 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5346 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5346 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5347 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5347 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5348 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5348 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5349 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5349 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5350 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5350 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5351 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5351 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5352 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5352 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5353 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5353 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5354 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5354 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5355 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5355 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5356 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5356 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5357 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5357 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5358 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5358 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5359 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5359 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5360 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5360 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5361 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5361 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5362 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5362 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5363 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5363 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5364 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5364 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5365 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5365 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5366 /tmp/nwatchdog/NovolineM zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5366 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5368 /tmp/nwatchdog/NovolineM net send-data zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5368 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5369 /tmp/nwatchdog/NovolineM net send-data zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5369 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5370 /tmp/nwatchdog/NovolineM net send-data zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5370 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5371 /tmp/nwatchdog/NovolineM net send-data zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5371 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5372 /tmp/nwatchdog/NovolineM net send-data zombie guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5313->guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5372 clone guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5315->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 70B guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5368->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 70B 3e5ff554-cec8-54a0-95c3-03c3ab5bd149 88.156.30.96:20736 guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5368->3e5ff554-cec8-54a0-95c3-03c3ab5bd149 send: 2493B guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5369->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 70B guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5369->3e5ff554-cec8-54a0-95c3-03c3ab5bd149 send: 1216B guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5370->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 70B guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5370->3e5ff554-cec8-54a0-95c3-03c3ab5bd149 send: 1334B guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5371->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 70B guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5371->3e5ff554-cec8-54a0-95c3-03c3ab5bd149 send: 1216B guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5372->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 70B guuid=843d7365-1b00-0000-d1b8-9699c1140000 pid=5372->3e5ff554-cec8-54a0-95c3-03c3ab5bd149 send: 1334B
Threat name:
Linux.PUA.Miner
Status:
Malicious
First seen:
2025-11-23 19:05:24 UTC
File Type:
ELF64 Little (Exe)
AV detection:
12 of 38 (31.58%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
antivm credential_access defense_evasion discovery execution linux persistence privilege_escalation rootkit upx
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Creates .desktop file
Reads CPU attributes
Modifies Bash startup script
UPX packed file
Abuse Elevation Control Mechanism: Sudo and Sudo Caching
Adds a user to the system
Checks hardware identifiers (DMI)
Creates/modifies environment variables
Enumerates running processes
Reads hardware information
Executes dropped EXE
Loads a kernel module
OS Credential Dumping
Modifies password files for system users/ groups
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:F01_s1ckrule
Author:s1ckb017
Rule name:malwareelf55503
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments