MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f11371b1a4e88d9324df22bd463921a1d72b7f6dbb3937a4aa20f87fede2bd11. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: f11371b1a4e88d9324df22bd463921a1d72b7f6dbb3937a4aa20f87fede2bd11
SHA3-384 hash: d05b96b3ecf3040103ab3161d3955b572458d6f89479e79f9b20a6414e5b871c4a5adfeaef816fcdf2d4c0d9fbc6b279
SHA1 hash: 9dce3e984f7ddad12d04430f1ec0dcf2ebdf7647
MD5 hash: 760c9e2edbd32d62106eead624e6f147
humanhash: kentucky-nine-zulu-pennsylvania
File name:bolts
Download: download sample
Signature CoinMiner
File size:1'974 bytes
First seen:2026-01-23 07:03:55 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:o9qMkpnIDd3Eo+h/s54NvIaNHnJl9vYp1MSQ7BVKfw0c22DND7DYcHMjStLqJi5m:o9qMyIB3ETK8VE9cBCcRHGi5m
TLSH T12941DEED64D279E87855E99CB663C21815C4F68808E7178C784C6D36F355408F7267FC
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
http://87.121.84.24/nuts/poopn/an/aCoinMiner elf geofenced ua-wget USA x86

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox coinminer
Result
Gathering data
Result
Malware family:
Score:
  10/10
Tags:
family:xmrig antivm defense_evasion discovery linux miner upx
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to shm directory
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads CPU attributes
UPX packed file
Checks hardware identifiers (DMI)
Enumerates running processes
Reads hardware information
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Unexpected DNS network traffic destination
XMRig Miner payload
Xmrig family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CoinMiner

sh f11371b1a4e88d9324df22bd463921a1d72b7f6dbb3937a4aa20f87fede2bd11

(this sample)

  
Delivery method
Distributed via web download

Comments