MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fae8540f4551d934f1576def2e9ca6f0317a8113654d4c15c0ebf877e8d6c956. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: fae8540f4551d934f1576def2e9ca6f0317a8113654d4c15c0ebf877e8d6c956
SHA3-384 hash: c1f852a18b13791e458fe78c8316bc5accd36586f68dce0fb35c094f6fa90270e57ae7c6049e38be986ff3fee76372a1
SHA1 hash: 264474ce11e458863e2cf6f12116d96d09feb2aa
MD5 hash: fad7698681942d4a00ad19b12fce353a
humanhash: pizza-saturn-oscar-angel
File name:mon.sh
Download: download sample
Signature CoinMiner
File size:4'623 bytes
First seen:2025-07-14 18:19:36 UTC
Last seen:2025-07-15 16:16:58 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 96:l06z0cic27pCP7DTAiVjDAmx793jt0yjtgmu4IL1Sd6z0cd:l080c9ipCzDNjdd935XvIL1Sd80cd
TLSH T19C91724AF690C6B0389DC5A8A99B64863907428B5E050D1DF82EF49CBF5439C70F87EF
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.248.53.119:8000/mon.sh1e891ab1521b27923233e694f60fdbf0e1b840e657d8b1ffdefd8b5ef5e38964 CoinMinerCoinMiner
http://ip-api.com/json/n/an/an/a

Intelligence


File Origin
# of uploads :
3
# of downloads :
30
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
fingerprint
Status:
terminated
Behavior Graph:
%3 guuid=0ce3026e-1a00-0000-c731-cd30220c0000 pid=3106 /usr/bin/sudo guuid=547b8070-1a00-0000-c731-cd30270c0000 pid=3111 /tmp/sample.bin guuid=0ce3026e-1a00-0000-c731-cd30220c0000 pid=3106->guuid=547b8070-1a00-0000-c731-cd30270c0000 pid=3111 execve guuid=b7326871-1a00-0000-c731-cd30290c0000 pid=3113 /usr/bin/whoami guuid=547b8070-1a00-0000-c731-cd30270c0000 pid=3111->guuid=b7326871-1a00-0000-c731-cd30290c0000 pid=3113 execve guuid=df0af571-1a00-0000-c731-cd302a0c0000 pid=3114 /usr/bin/whoami guuid=547b8070-1a00-0000-c731-cd30270c0000 pid=3111->guuid=df0af571-1a00-0000-c731-cd302a0c0000 pid=3114 execve guuid=5f744172-1a00-0000-c731-cd302c0c0000 pid=3116 /usr/bin/whoami guuid=547b8070-1a00-0000-c731-cd30270c0000 pid=3111->guuid=5f744172-1a00-0000-c731-cd302c0c0000 pid=3116 execve guuid=bffeb872-1a00-0000-c731-cd302f0c0000 pid=3119 /usr/bin/bash guuid=547b8070-1a00-0000-c731-cd30270c0000 pid=3111->guuid=bffeb872-1a00-0000-c731-cd302f0c0000 pid=3119 clone guuid=930fce72-1a00-0000-c731-cd30300c0000 pid=3120 /usr/bin/id guuid=547b8070-1a00-0000-c731-cd30270c0000 pid=3111->guuid=930fce72-1a00-0000-c731-cd30300c0000 pid=3120 execve guuid=8ee1c973-1a00-0000-c731-cd30330c0000 pid=3123 /usr/bin/systemctl guuid=547b8070-1a00-0000-c731-cd30270c0000 pid=3111->guuid=8ee1c973-1a00-0000-c731-cd30330c0000 pid=3123 execve guuid=93b6ce76-1a00-0000-c731-cd303d0c0000 pid=3133 /usr/bin/bash guuid=547b8070-1a00-0000-c731-cd30270c0000 pid=3111->guuid=93b6ce76-1a00-0000-c731-cd303d0c0000 pid=3133 clone guuid=3498d576-1a00-0000-c731-cd303e0c0000 pid=3134 /usr/bin/grep guuid=547b8070-1a00-0000-c731-cd30270c0000 pid=3111->guuid=3498d576-1a00-0000-c731-cd303e0c0000 pid=3134 execve guuid=72d63577-1a00-0000-c731-cd303f0c0000 pid=3135 /usr/bin/bash guuid=547b8070-1a00-0000-c731-cd30270c0000 pid=3111->guuid=72d63577-1a00-0000-c731-cd303f0c0000 pid=3135 clone guuid=992b4077-1a00-0000-c731-cd30400c0000 pid=3136 /usr/bin/bash guuid=547b8070-1a00-0000-c731-cd30270c0000 pid=3111->guuid=992b4077-1a00-0000-c731-cd30400c0000 pid=3136 clone guuid=623d7477-1a00-0000-c731-cd30430c0000 pid=3139 /usr/bin/ps guuid=547b8070-1a00-0000-c731-cd30270c0000 pid=3111->guuid=623d7477-1a00-0000-c731-cd30430c0000 pid=3139 execve guuid=25f47b77-1a00-0000-c731-cd30440c0000 pid=3140 /usr/bin/mawk guuid=547b8070-1a00-0000-c731-cd30270c0000 pid=3111->guuid=25f47b77-1a00-0000-c731-cd30440c0000 pid=3140 execve guuid=a11e8177-1a00-0000-c731-cd30450c0000 pid=3141 /usr/bin/bash guuid=547b8070-1a00-0000-c731-cd30270c0000 pid=3111->guuid=a11e8177-1a00-0000-c731-cd30450c0000 pid=3141 clone guuid=680ca27d-1a00-0000-c731-cd30550c0000 pid=3157 /usr/bin/bash guuid=547b8070-1a00-0000-c731-cd30270c0000 pid=3111->guuid=680ca27d-1a00-0000-c731-cd30550c0000 pid=3157 clone guuid=5606ec81-1a00-0000-c731-cd30610c0000 pid=3169 /usr/bin/curl net send-data guuid=547b8070-1a00-0000-c731-cd30270c0000 pid=3111->guuid=5606ec81-1a00-0000-c731-cd30610c0000 pid=3169 execve guuid=63132282-1a00-0000-c731-cd30620c0000 pid=3170 /usr/bin/grep guuid=547b8070-1a00-0000-c731-cd30270c0000 pid=3111->guuid=63132282-1a00-0000-c731-cd30620c0000 pid=3170 execve guuid=c1db7496-1a00-0000-c731-cd30820c0000 pid=3202 /usr/bin/wget net send-data write-file guuid=547b8070-1a00-0000-c731-cd30270c0000 pid=3111->guuid=c1db7496-1a00-0000-c731-cd30820c0000 pid=3202 execve guuid=32d372a6-1a00-0000-c731-cd30840c0000 pid=3204 /usr/bin/chmod guuid=547b8070-1a00-0000-c731-cd30270c0000 pid=3111->guuid=32d372a6-1a00-0000-c731-cd30840c0000 pid=3204 execve guuid=8052d8a6-1a00-0000-c731-cd30850c0000 pid=3205 /home/sandbox/run.sh guuid=547b8070-1a00-0000-c731-cd30270c0000 pid=3111->guuid=8052d8a6-1a00-0000-c731-cd30850c0000 pid=3205 execve guuid=860c0746-1c00-0000-c731-cd305b0f0000 pid=3931 /usr/bin/rm delete-file guuid=547b8070-1a00-0000-c731-cd30270c0000 pid=3111->guuid=860c0746-1c00-0000-c731-cd305b0f0000 pid=3931 execve guuid=3bb95e46-1c00-0000-c731-cd305e0f0000 pid=3934 /usr/bin/whoami guuid=547b8070-1a00-0000-c731-cd30270c0000 pid=3111->guuid=3bb95e46-1c00-0000-c731-cd305e0f0000 pid=3934 execve guuid=9effbf46-1c00-0000-c731-cd30620f0000 pid=3938 /usr/bin/whoami guuid=547b8070-1a00-0000-c731-cd30270c0000 pid=3111->guuid=9effbf46-1c00-0000-c731-cd30620f0000 pid=3938 execve guuid=c62e2147-1c00-0000-c731-cd30640f0000 pid=3940 /usr/bin/whoami guuid=547b8070-1a00-0000-c731-cd30270c0000 pid=3111->guuid=c62e2147-1c00-0000-c731-cd30640f0000 pid=3940 execve guuid=b7864c77-1a00-0000-c731-cd30420c0000 pid=3138 /usr/bin/bash guuid=72d63577-1a00-0000-c731-cd303f0c0000 pid=3135->guuid=b7864c77-1a00-0000-c731-cd30420c0000 pid=3138 clone guuid=a814ae7d-1a00-0000-c731-cd30570c0000 pid=3159 /usr/bin/pgrep guuid=680ca27d-1a00-0000-c731-cd30550c0000 pid=3157->guuid=a814ae7d-1a00-0000-c731-cd30570c0000 pid=3159 execve guuid=c5adb47d-1a00-0000-c731-cd30580c0000 pid=3160 /usr/bin/bash guuid=680ca27d-1a00-0000-c731-cd30550c0000 pid=3157->guuid=c5adb47d-1a00-0000-c731-cd30580c0000 pid=3160 clone b60edd83-de97-543e-8c12-c815cb088ff2 ip-api.com:80 guuid=5606ec81-1a00-0000-c731-cd30610c0000 pid=3169->b60edd83-de97-543e-8c12-c815cb088ff2 send: 79B guuid=5606ec81-1a00-0000-c731-cd30610c0000 pid=3178 /usr/bin/curl dns net send-data guuid=5606ec81-1a00-0000-c731-cd30610c0000 pid=3169->guuid=5606ec81-1a00-0000-c731-cd30610c0000 pid=3178 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=5606ec81-1a00-0000-c731-cd30610c0000 pid=3178->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 28B 2f67bf0f-8453-5800-9e7b-37101ce5849f 162.248.53.119:8000 guuid=c1db7496-1a00-0000-c731-cd30820c0000 pid=3202->2f67bf0f-8453-5800-9e7b-37101ce5849f send: 140B guuid=ada93ea7-1a00-0000-c731-cd30860c0000 pid=3206 /usr/bin/systemctl guuid=8052d8a6-1a00-0000-c731-cd30850c0000 pid=3205->guuid=ada93ea7-1a00-0000-c731-cd30860c0000 pid=3206 execve guuid=5c8713a9-1a00-0000-c731-cd308b0c0000 pid=3211 /usr/bin/bash guuid=8052d8a6-1a00-0000-c731-cd30850c0000 pid=3205->guuid=5c8713a9-1a00-0000-c731-cd308b0c0000 pid=3211 clone guuid=fd88f5ae-1a00-0000-c731-cd30960c0000 pid=3222 /usr/bin/bash guuid=8052d8a6-1a00-0000-c731-cd30850c0000 pid=3205->guuid=fd88f5ae-1a00-0000-c731-cd30960c0000 pid=3222 clone guuid=baea8faf-1a00-0000-c731-cd309c0c0000 pid=3228 /usr/bin/id guuid=8052d8a6-1a00-0000-c731-cd30850c0000 pid=3205->guuid=baea8faf-1a00-0000-c731-cd309c0c0000 pid=3228 execve guuid=2ed4f0af-1a00-0000-c731-cd309d0c0000 pid=3229 /usr/bin/mkdir guuid=8052d8a6-1a00-0000-c731-cd30850c0000 pid=3205->guuid=2ed4f0af-1a00-0000-c731-cd309d0c0000 pid=3229 execve guuid=fae96cb0-1a00-0000-c731-cd309f0c0000 pid=3231 /usr/bin/wget dns net send-data write-file guuid=8052d8a6-1a00-0000-c731-cd30850c0000 pid=3205->guuid=fae96cb0-1a00-0000-c731-cd309f0c0000 pid=3231 execve guuid=df9b4ef6-1a00-0000-c731-cd30e90c0000 pid=3305 /usr/bin/tar write-file guuid=8052d8a6-1a00-0000-c731-cd30850c0000 pid=3205->guuid=df9b4ef6-1a00-0000-c731-cd30e90c0000 pid=3305 execve guuid=f00f7c09-1b00-0000-c731-cd30110d0000 pid=3345 /usr/bin/mv guuid=8052d8a6-1a00-0000-c731-cd30850c0000 pid=3205->guuid=f00f7c09-1b00-0000-c731-cd30110d0000 pid=3345 execve guuid=ab51db09-1b00-0000-c731-cd30130d0000 pid=3347 /usr/bin/rm guuid=8052d8a6-1a00-0000-c731-cd30850c0000 pid=3205->guuid=ab51db09-1b00-0000-c731-cd30130d0000 pid=3347 execve guuid=16e2190a-1b00-0000-c731-cd30150d0000 pid=3349 /usr/bin/chmod guuid=8052d8a6-1a00-0000-c731-cd30850c0000 pid=3205->guuid=16e2190a-1b00-0000-c731-cd30150d0000 pid=3349 execve guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351 /usr/lib/dev/systemdev/systemd-mont mprotect-exec net send-data guuid=8052d8a6-1a00-0000-c731-cd30850c0000 pid=3205->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351 execve guuid=dfb96a0a-1b00-0000-c731-cd30180d0000 pid=3352 /usr/bin/sleep guuid=8052d8a6-1a00-0000-c731-cd30850c0000 pid=3205->guuid=dfb96a0a-1b00-0000-c731-cd30180d0000 pid=3352 execve guuid=2b19cf28-1b00-0000-c731-cd305a0d0000 pid=3418 /usr/bin/ps guuid=8052d8a6-1a00-0000-c731-cd30850c0000 pid=3205->guuid=2b19cf28-1b00-0000-c731-cd305a0d0000 pid=3418 execve guuid=f0b9cf32-1b00-0000-c731-cd30770d0000 pid=3447 /usr/bin/sleep guuid=8052d8a6-1a00-0000-c731-cd30850c0000 pid=3205->guuid=f0b9cf32-1b00-0000-c731-cd30770d0000 pid=3447 execve guuid=97ca4440-1c00-0000-c731-cd304c0f0000 pid=3916 /usr/bin/ps guuid=8052d8a6-1a00-0000-c731-cd30850c0000 pid=3205->guuid=97ca4440-1c00-0000-c731-cd304c0f0000 pid=3916 execve guuid=94b52f45-1c00-0000-c731-cd30590f0000 pid=3929 /usr/bin/rm guuid=8052d8a6-1a00-0000-c731-cd30850c0000 pid=3205->guuid=94b52f45-1c00-0000-c731-cd30590f0000 pid=3929 execve guuid=47849d45-1c00-0000-c731-cd305a0f0000 pid=3930 /usr/bin/rm guuid=8052d8a6-1a00-0000-c731-cd30850c0000 pid=3205->guuid=47849d45-1c00-0000-c731-cd305a0f0000 pid=3930 execve guuid=a8e32ba9-1a00-0000-c731-cd308c0c0000 pid=3212 /usr/bin/wget dns net send-data guuid=5c8713a9-1a00-0000-c731-cd308b0c0000 pid=3211->guuid=a8e32ba9-1a00-0000-c731-cd308c0c0000 pid=3212 execve guuid=a8e32ba9-1a00-0000-c731-cd308c0c0000 pid=3212->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B 0690ccd5-4816-5f11-94dc-7c585f38cdea ipv4.icanhazip.com:0 guuid=a8e32ba9-1a00-0000-c731-cd308c0c0000 pid=3212->0690ccd5-4816-5f11-94dc-7c585f38cdea con d0ecfe49-aa79-583f-85c6-85ac97075256 ipv4.icanhazip.com:80 guuid=a8e32ba9-1a00-0000-c731-cd308c0c0000 pid=3212->d0ecfe49-aa79-583f-85c6-85ac97075256 send: 133B guuid=240203af-1a00-0000-c731-cd30970c0000 pid=3223 /usr/bin/bash guuid=fd88f5ae-1a00-0000-c731-cd30960c0000 pid=3222->guuid=240203af-1a00-0000-c731-cd30970c0000 pid=3223 clone guuid=85d90aaf-1a00-0000-c731-cd30990c0000 pid=3225 /usr/bin/sed guuid=fd88f5ae-1a00-0000-c731-cd30960c0000 pid=3222->guuid=85d90aaf-1a00-0000-c731-cd30990c0000 pid=3225 execve guuid=7aa311af-1a00-0000-c731-cd309a0c0000 pid=3226 /usr/bin/cut guuid=fd88f5ae-1a00-0000-c731-cd30960c0000 pid=3222->guuid=7aa311af-1a00-0000-c731-cd309a0c0000 pid=3226 execve guuid=fae96cb0-1a00-0000-c731-cd309f0c0000 pid=3231->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 150B 75aab096-419b-50ef-be46-7d76b6a90e4c github.com:443 guuid=fae96cb0-1a00-0000-c731-cd309f0c0000 pid=3231->75aab096-419b-50ef-be46-7d76b6a90e4c send: 802B a13b061a-f048-5755-ac95-a8265477be45 objects.githubusercontent.com:0 guuid=fae96cb0-1a00-0000-c731-cd309f0c0000 pid=3231->a13b061a-f048-5755-ac95-a8265477be45 con 06a44d09-e679-52bb-9c81-7632368ac4a3 objects.githubusercontent.com:443 guuid=fae96cb0-1a00-0000-c731-cd309f0c0000 pid=3231->06a44d09-e679-52bb-9c81-7632368ac4a3 send: 1242B guuid=8f79aaf6-1a00-0000-c731-cd30eb0c0000 pid=3307 /usr/bin/gzip guuid=df9b4ef6-1a00-0000-c731-cd30e90c0000 pid=3305->guuid=8f79aaf6-1a00-0000-c731-cd30eb0c0000 pid=3307 execve 5b34c3af-d415-55dd-bdb3-d684a2b53711 116.202.3.220:23656 guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->5b34c3af-d415-55dd-bdb3-d684a2b53711 send: 489B guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3364 /usr/lib/dev/systemdev/systemd-mont write-file guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3364 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3365 /usr/lib/dev/systemdev/systemd-mont send-data guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3365 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3366 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3366 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3367 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3367 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3368 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3368 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3376 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3376 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3377 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3377 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3378 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3378 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3379 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3379 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3380 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3380 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3381 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3381 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3382 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3382 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3383 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3383 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3393 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3393 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3394 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3394 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3395 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3395 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3397 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3397 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3407 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3407 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3408 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3408 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3409 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3409 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3410 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3410 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3424 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3424 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3425 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3425 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3426 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3426 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3427 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3427 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3439 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3439 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3440 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3440 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3441 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3441 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3442 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3442 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3464 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3464 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3465 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3465 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3466 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3466 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3467 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3467 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3485 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3485 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3486 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3486 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3487 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3487 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3488 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3488 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3508 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3508 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3509 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3509 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3510 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3510 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3511 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3511 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3527 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3527 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3528 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3528 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3529 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3529 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3530 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3530 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3543 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3543 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3544 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3544 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3545 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3545 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3546 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3546 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3554 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3554 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3555 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3555 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3556 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3556 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3557 /usr/lib/dev/systemdev/systemd-mont guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3351->guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3557 clone guuid=b1cc620a-1b00-0000-c731-cd30170d0000 pid=3365->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2025-07-14 18:33:21 UTC
File Type:
Text (Shell)
AV detection:
7 of 24 (29.17%)
Threat level:
  5/5
Result
Malware family:
xmrig_linux
Score:
  10/10
Tags:
family:xmrig family:xmrig_linux antivm defense_evasion discovery execution linux miner persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads CPU attributes
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Enumerates running processes
Looks up external IP address via web service
Reads hardware information
File and Directory Permissions Modification
Executes dropped EXE
XMRig Miner payload
Xmrig family
Xmrig_linux family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Distributed via web download

Comments