MALICIOUS — c66f9881bed79a550e18d54b9ae5cf03b91a0e881efdbf7962db2e58de0b4f7b.bin
MALICIOUS — c66f9881bed79a550e18d54b9ae5cf03b91a0e881efdbf7962db2e58de0b4f7b.bin is a macho sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (91/100), attributed to the XMRig family. 3 of 56 detection engines flagged it.
Identification
- SHA-256:
c66f9881bed79a550e18d54b9ae5cf03b91a0e881efdbf7962db2e58de0b4f7b - SHA-1:
dd2632ac778898c2766b87031af4539a03357820 - MD5:
b4d182ca304c331a15b1c25a13db0d1a - ssdeep:
98304:X1Qnp40oASZADVwdDtExbTAco1LkDC3aERlIK4JevJeihlz:ip40oAS2aBts1KAm3aaIKDV - TLSH:
T13267BF0615987E80EDE4F40DFC556B2DB7874CC0823A268EA1C758D6D3EBB7B0624693 - Submitted as: c66f9881bed79a550e18d54b9ae5cf03b91a0e881efdbf7962db2e58de0b4f7b.bin
- File type: macho · Size: 7374296 bytes
- Verdict: malicious (91/100) · Family: XMRig
Source: MalShare · first seen 2026-09-16T12:57:35.142Z · SHA-256 verified
Detections (3 of 56 engines)
- YARA: Intezer community: INTEZER_Linux_XMRig_Miner
- Microsoft Defender: Misleading:MacOS/CoinMiner.BC!MTB
- Kaspersky (KVRT): not-a-virus:HEUR:RiskTool.OSX.Miner.gen
Why this verdict
The malicious score of 91/100 is the fusion of 5 weighted signals:
- Microsoft Defender flagged Misleading:MacOS/CoinMiner.BC!MTB (rule
Misleading:MacOS/CoinMiner.BC!MTB) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged not-a-virus:HEUR:RiskTool.OSX.Miner.gen (rule
not-a-virus:HEUR:RiskTool.OSX.Miner.gen) - engine signal, weight 0.55, confidence 0.85 - YARA: Intezer community flagged INTEZER_Linux_XMRig_Miner (rule
INTEZER_Linux_XMRig_Miner) - engine signal, weight 0.65, confidence 0.70 - Embedded executable payload carved at offset 6752152 - static signal, weight 0.40, confidence 0.70
- Embedded network infrastructure: https://xmrig.com/docs/algorithms, https://xmrig.com/wizard, 1.101.3.4 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
This sample targets macOS, for which we operate no sandbox guest, so it was not detonated. The absence of runtime behaviour here is a coverage gap on our side, not a finding about the sample.
Embedded URLs
- https://xmrig.com/docs/algorithms
- https://xmrig.com/wizard
Embedded domains
- arm.com
- openssl.org
- randomx.xmrig.com
- xmrig.com
- nicehash.com
- api.xmrig.com
- donate.ssl.xmrig.com
- donate.v2.xmrig.com
Embedded IP addresses
- 0.22.14.1
- 1.101.3.4
- 12.2.2.8
- 12.2.1.16
- 5.3.1.9
- 61.1.1.1
- 1.9.16.3
More XMRig samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report