MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f1253b8e6d33db23fd1d8a07d802d4618b4359005ac616ac5156aacd24b0f604. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: f1253b8e6d33db23fd1d8a07d802d4618b4359005ac616ac5156aacd24b0f604
SHA3-384 hash: 8440ce324f28a6982e511c4b8301394d98848e250be468e048bc46d20f253a41e2a180d595f1a442246116527a24d102
SHA1 hash: 394dbe96d1d4eebc926f63e27329816045b17128
MD5 hash: f56926fa7df4942c949bef48a9ea72ab
humanhash: sink-alanine-quiet-apart
File name:mon.sh
Download: download sample
Signature CoinMiner
File size:3'549 bytes
First seen:2025-06-04 14:56:40 UTC
Last seen:2025-06-05 04:56:28 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 96:l06z0cic27rP7DTAiVjQR75+PmJoMSd6z0cd:l080c9irzDNjQ92mJoMSd80cd
TLSH T1DF71854AFA6486F02C9985A859CBA4863907414B9E040D2DF85EF19D3F8436870FC7FE
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.248.53.119:8000/mon.sh6cdc9ae50dac41db620137c6b9d33be81f0af07828b7f38c630419596f4c27f4 CoinMinerCoinMiner

Intelligence


File Origin
# of uploads :
2
# of downloads :
69
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
fingerprint
Threat name:
Script.Trojan.Heuristic
Status:
Malicious
First seen:
2025-06-04 14:57:29 UTC
File Type:
Text (Shell)
AV detection:
5 of 38 (13.16%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:xmrig antivm defense_evasion discovery execution linux miner persistence privilege_escalation rootkit upx
Behaviour
Enumerates kernel/hardware configuration
Process Discovery
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
Reads CPU attributes
UPX packed file
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Enumerates running processes
Reads hardware information
File and Directory Permissions Modification
Executes dropped EXE
Loads a kernel module
XMRig Miner payload
Xmrig family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments