MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 66fa2281567f268adefb54e91b88bfbd7a08eee6c40ff4aafa31472b8d49a3a6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 66fa2281567f268adefb54e91b88bfbd7a08eee6c40ff4aafa31472b8d49a3a6
SHA3-384 hash: 1721d38e301c302b64f7c7434fb050c1009d982d8748b91ac1a24f2fde676150be43e176fd468cee8e97d92cda1886cf
SHA1 hash: dc25ca8d22001ce234872aec3549d11fc7b05849
MD5 hash: 0fdb6dab6f29e54b5220292da7e33be3
humanhash: robert-arkansas-violet-iowa
File name:0fdb6dab6f29e54b5220292da7e33be3.exe
Download: download sample
Signature CoinMiner
File size:1'189'888 bytes
First seen:2022-03-21 08:12:42 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 3eb7622479f8b2c1a30189a3df7139f3 (25 x CoinMiner)
ssdeep 24576:2y+jMkaTDtuF6kYK2MS6+wxaD21EtYlsVVRylcOJLrTkHurKge:2yFkaTDtuMkxrU3t9icaLMur
TLSH T1A2453342D6E4FC32D92AA37A5205EF5EDF54F526C7CF823CF638407AC9A461610477A2
Reporter abuse_ch
Tags:CoinMiner exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
219
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Detection:
malicious
Classification:
mine
Score:
72 / 100
Signature
Found strings related to Crypto-Mining
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Xmrig cryptocurrency miner
Behaviour
Behavior Graph:
Threat name:
Win64.Coinminer.BitCoinMiner
Status:
Malicious
First seen:
2022-03-21 08:13:12 UTC
File Type:
PE+ (Exe)
Extracted files:
13
AV detection:
18 of 42 (42.86%)
Threat level:
  4/5
Verdict:
malicious
Result
Malware family:
n/a
Score:
  8/10
Tags:
upx
Unpacked files
SH256 hash:
66fa2281567f268adefb54e91b88bfbd7a08eee6c40ff4aafa31472b8d49a3a6
MD5 hash:
0fdb6dab6f29e54b5220292da7e33be3
SHA1 hash:
dc25ca8d22001ce234872aec3549d11fc7b05849
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments