ThreatFox IOC Database

You are viewing the ThreatFox database entry for sha256_hash adfa14deed04a850938bf48ef190b1f30b93d1bebe07ad2e7d0b48d8a03bdabc.

Database Entry


IOC ID:1820912
IOC: adfa14deed04a850938bf48ef190b1f30b93d1bebe07ad2e7d0b48d8a03bdabc
IOC Type :sha256_hash
Threat Type :payload
Malware: XMRIG
Confidence Level : Confidence level is high (90%)
Is compromised? : False
First seen:2026-06-02 13:48:43 UTC
Last seen:never
UUID:36bb132b-5e84-11f1-b930-42010aa4000a
Reporter nullblue67
Reward 5 credits from ThreatFox
Tags:alpine-container cryptojacking docker-api elf miner x86_64 xmrig
Reference: https://twitter.com/NullBlue67

Avatar
nullblue67
XMRig miner deployed via Docker API exploit alpine container drop path /tmp/._x. GCC 13.3.0 Ubuntu 24.04 build. Captured 2026-06-02 NullBlue67 honeypot.