MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 993469783885b67fa6c3da8ffe60224f9eb7cc5263e0261313ebb5893e41e148. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 993469783885b67fa6c3da8ffe60224f9eb7cc5263e0261313ebb5893e41e148
SHA3-384 hash: e81cdab89a76b8dc70115fade9d8dd7e27099015947482f65e6388f780847af53bd7b2aeecde241b190513d8e07d8bb2
SHA1 hash: dcfc8fc35bf688a1a8ff983d3ba64be37e5ed8d1
MD5 hash: 0d2afbd7e1a360fdc8a270e48b732e66
humanhash: six-seventeen-alabama-batman
File name:0d2afbd7e1a360fdc8a270e48b732e66.exe
Download: download sample
Signature CoinMiner
File size:1'186'304 bytes
First seen:2022-03-02 07:43:19 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 3eb7622479f8b2c1a30189a3df7139f3 (25 x CoinMiner)
ssdeep 24576:jy+jMkaTDtuF6kYK2MS6+wxaD21EtYlsVVRylcOJLrTkHurKgb:jyFkaTDtuMkxrU3t9icaLMur
TLSH T1C3453346EAE4F832D92B727A5205EF5EEF54F526C7CF823CF639407E8AA451110473A2
File icon (PE):PE icon
dhash icon 68d89afabc90e464 (1 x CoinMiner)
Reporter abuse_ch
Tags:CoinMiner exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
213
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug coinminer packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Detection:
malicious
Classification:
mine
Score:
72 / 100
Signature
Found strings related to Crypto-Mining
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Xmrig cryptocurrency miner
Behaviour
Behavior Graph:
Threat name:
Win64.Trojan.DisguisedXMRigMiner
Status:
Malicious
First seen:
2022-03-02 05:59:29 UTC
File Type:
PE+ (Exe)
Extracted files:
9
AV detection:
17 of 27 (62.96%)
Threat level:
  5/5
Verdict:
malicious
Result
Malware family:
n/a
Score:
  8/10
Tags:
upx
Unpacked files
SH256 hash:
993469783885b67fa6c3da8ffe60224f9eb7cc5263e0261313ebb5893e41e148
MD5 hash:
0d2afbd7e1a360fdc8a270e48b732e66
SHA1 hash:
dcfc8fc35bf688a1a8ff983d3ba64be37e5ed8d1
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CoinMiner

Executable exe 993469783885b67fa6c3da8ffe60224f9eb7cc5263e0261313ebb5893e41e148

(this sample)

  
Delivery method
Distributed via web download

Comments