newinit.sh
Classification: Malicious
newinit.sh is a malicious file sample. Linked to Kinsing malware. Reported by 2 threat sources, last seen 2026-06-04. Detected by 33 antivirus engines.
Detection summary
- 33 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: KINSING (S0599)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Xmrig_linux | Triage | 2026-06-04 07:14:14 | 2026-06-04 07:14:14 | malicious-activity | |
| Kinsing | MalwareBazaar Abuse.ch | 2026-06-04 07:12:00 | 2026-06-04 07:12:00 | malicious-activity | S0599 Kinsing |
Tags
xmrig_linux antivm defense_evasion discovery execution linux miner persistence privilege_escalation rootkitSample information
- Filenames
- newinit.sh, _8abd78ff9af10b15c13d81069748286528939e62fe125d64ddb113d3c2561606.sh
- MD5
7b880fbc13863e984e110f3eb5879221- SHA-1
c7f71666822bae98936d64b151f1accbad532f58- SHA-256
8abd78ff9af10b15c13d81069748286528939e62fe125d64ddb113d3c2561606- First indexed
- 2026-06-04 07:12:00
- Last updated
- 2026-07-07 01:39:31
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Application.Linux.Miner.77 |
| AVG | BV:Agent-BRO [Trj] |
| AhnLab-V3 | CoinMiner/Shell.Generic.S2077 |
| Arcabit | Application.Linux.Miner.77 |
| Avast | BV:Agent-BRO [Trj] |
| Avira | TR/BAT.Agent.BRO |
| BitDefender | Application.Linux.Miner.77 |
| CAT-QuickHeal | ShellScript.Miner.44639 |
| CTX | shell.trojan.bash |
| ClamAV | Unix.Downloader.Rocke-6826000-0 |
| Cynet | Malicious (score: 99) |
| ESET-NOD32 | Linux/CoinMiner.UD trojan |
| Emsisoft | Application.Linux.Miner.77 (B) |
| F-Secure | Trojan.TR/BAT.Agent.BRO |
| Fortinet | BASH/CoinMiner.UW!tr |
| GData | Application.Linux.Miner.77 |
| Detected | |
| Kaspersky | HEUR:Trojan-Downloader.Shell.Miner.gen |
| Lionic | Trojan.Script.Shell.4!c |
| McAfeeD | ti!8ABD78FF9AF1 |
| MicroWorld-eScan | Application.Linux.Miner.77 |
| Microsoft | Trojan:Linux/CoinMiner.M!MTB |
| NANO-Antivirus | Riskware.Script.Miner.ixvqme |
| Rising | Trojan.[TeamTNT]YellowDye/BASH!9.732A7 (XSE:WFNFX0JBVDpovcOyvC/SdH2KOiGHGHiB) |
| Sangfor | Trojan.Generic-Bash.Save.1b44d042 |
| Skyhigh | Artemis!Trojan |
| Symantec | Trojan.Gen.NPE |
| Tencent | Win32.Trojan.Shell.Tdkl |
| VIPRE | Application.Linux.Miner.77 |
| Varist | Unix/Coinminer.O |
| Xcitium | Malware@#296rrt2ex5q2s |
| alibabacloud | Miner:Linux/CoinMiner.UF |
| huorong | Trojan/Linux.CoinMiner.dn |