TROYANOSYVIRUS
🦠
Severity: LOW

CoinMiner

Type: Unknown

SHA2565a0ad9c6e04897fff74fc9c0a2cabcd62115335c315d3c9b64c82641867f43c7
First Capture4/4/2026
Last Activity4/4/2026
Countries1
🎯
1
Times Captured
🌍
1
Countries
🖥️
1
Source IPs
🛡️
0
AV Detections
🔬

MalwareBazaar Intelligence

abuse.ch • Updated: 4/4/2026

View in MalwareBazaar
FamilyCoinMiner
File Typeelf(2304.0 KB)
First seen in MB3/5/2026
Tags
Coinminerelf
YARA Rules (8)
CP_Script_Inject_Detector
by DiegoAnalytics
Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
golang_duffcopy_amd64
Linux_Generic_Threat_902cfdc5
by Elastic Security
MD5_Constants
by phoul (@phoul)
Look for MD5 constants
RIPEMD160_Constants
by phoul (@phoul)
Look for RIPEMD-160 constants
SHA1_Constants
by phoul (@phoul)
Look for SHA1 constants
Vendor Intel (8)
Triage
Detected
Intezer
not_supported
Kaspersky
Malware
YOROI_YOMI
Legit File
FileScan-IO
Detected
CERT-PL_MWDB
Detected
Spamhaus_HBL
Detected
ReversingLabs
MALICIOUS

Countries of Origin

Antivirus Detections (0)

No antivirus detections recorded

Source IPs

Severity

15
/100
LowMediumHighCritical