ThreatFox IOC Database

You are viewing the ThreatFox database entry for sha256_hash f01cac66a63b3bfd7409e4bceef30973a813f6ed4e99958313657449b1c7490f.

Database Entry


IOC ID:1816913
IOC: f01cac66a63b3bfd7409e4bceef30973a813f6ed4e99958313657449b1c7490f
IOC Type :sha256_hash
Threat Type :payload
Malware: XMRIG
Confidence Level : Confidence level is high (90%)
Is compromised? : False
First seen:2026-05-21 11:55:05 UTC
Last seen:never
UUID:1adfeabd-54f7-11f1-b930-42010aa4000a
Reporter nullblue67
Reward 5 credits from ThreatFox
Tags:go-binary libpam-hijack linux multiverze ssh-sftp-dropper x86_64

Avatar
nullblue67
Captured 2026-05-21 via Cowrie SSH honeypot SFTP upload (uploaded as fake /usr/sbin/sshd to backdoor root SSH auth). ELF Go binary with libpam hijack (cgo bindings: pam_authenticate, pam_acct_mgmt, pam_setcred, pam_open_session). VT 37/75 detection ratio. Family: multiverze/malxmr (Linux XMRig dropper). Heavy anti-analysis: ELF section headers forged (claim 30MB content in 224KB file), Go runtime symbols stripped. First seen on VT 2023-06-22. Known to target SSH honeypots via root SFTP.