MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 7dc50338d476cd0dfdfcf48dc7dbff682d6d04458c6ce2808f35779606576532. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
CoinMiner
Vendor detections: 17
| SHA256 hash: | 7dc50338d476cd0dfdfcf48dc7dbff682d6d04458c6ce2808f35779606576532 |
|---|---|
| SHA3-384 hash: | 626f1b7ce4618185bb09743454cd33df9e7af06c5c2a436ef1c1176438f50d0473a6fa697d7f8d66f36e00f1bef9f525 |
| SHA1 hash: | ce644189a561c6a2a6f6f6656fc6a46e006d1d87 |
| MD5 hash: | 43f595460b2fca77561c63e8a80178dd |
| humanhash: | triple-whiskey-march-high |
| File name: | SecuriteInfo.com.Win64.CoinminerX-gen.3295.9388 |
| Download: | download sample |
| Signature | CoinMiner |
| File size: | 2'983'424 bytes |
| First seen: | 2024-09-09 04:32:24 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 17fb7e76da9d0e277bd22cf9f3d5242c (2 x CoinMiner) |
| ssdeep | 49152:Ttx3zeCE99IyWGKUpZTGttu7FfdKRiIsA37SWje3b9VJMsdnee6GrhpIfI9umCzY:TrM9BpYttuBdK4FA3mWMbfN73r0fCulc |
| TLSH | T1D3D5337BB285D466E7B380362204F34AFE971F2799780242D7857B2DDC779A4AC7013A |
| TrID | 63.5% (.EXE) UPX compressed Win64 Executable (70117/5/12) 24.5% (.EXE) UPX compressed Win32 Executable (27066/9/6) 4.5% (.EXE) Win16 NE executable (generic) (5038/12/1) 1.8% (.ICL) Windows Icons Library (generic) (2059/9) 1.8% (.EXE) OS/2 Executable (generic) (2029/13) |
| Magika | pebin |
| File icon (PE): | |
| dhash icon | f8e4b4d959d6c678 (40 x CoinMiner) |
| Reporter | |
| Tags: | CoinMiner exe mirai XMRIG |
Intelligence
File Origin
# of uploads :
1
# of downloads :
461
Origin country :
FRVendor Threat Intelligence
Malware family:
xmrig
ID:
1
File name:
http://193.32.162.34/a.bat
Verdict:
Malicious activity
Analysis date:
2024-09-08 09:27:34 UTC
Tags:
miner loader xmrig upx
Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
94.1%
Tags:
Coinminer
Result
Verdict:
Clean
Maliciousness:
Behaviour
Searching for the window
Verdict:
Malicious
Threat level:
10/10
Confidence:
100%
Tags:
anti-debug anti-vm coinminer crypto lolbin miner monero overlay packed packed packed pup shell32 upx xmrig
Verdict:
Malicious
Labled as:
Malware
Malware family:
Cactus Ransomware
Verdict:
Malicious
Result
Threat name:
Xmrig
Detection:
malicious
Classification:
mine
Score:
84 / 100
Signature
AI detected suspicious sample
Antivirus / Scanner detection for submitted sample
Found strings related to Crypto-Mining
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Xmrig cryptocurrency miner
Behaviour
Behavior Graph:
Score:
94%
Verdict:
Malware
File Type:
PE
Threat name:
Win64.Coinminer.XMRig
Status:
Malicious
First seen:
2024-09-06 05:05:06 UTC
File Type:
PE+ (Exe)
Extracted files:
17
AV detection:
14 of 24 (58.33%)
Threat level:
4/5
Detection(s):
Suspicious file
Verdict:
malicious
Result
Malware family:
xmrig
Score:
10/10
Tags:
family:xmrig miner upx
Behaviour
UPX packed file
XMRig Miner payload
xmrig
Verdict:
Suspicious
Tags:
n/a
YARA:
n/a
Unpacked files
SH256 hash:
a253d7293f26b7debf38c55d20342b88695db5968d6d9080c3b492432bbdb568
MD5 hash:
9501946dfdc2324f4268c39b0cf40abe
SHA1 hash:
8986fcce41489e01d29c899950c98806835f705c
Detections:
XMRig
XMRIG_Monero_Miner
MAL_XMR_Miner_May19_1
SH256 hash:
7dc50338d476cd0dfdfcf48dc7dbff682d6d04458c6ce2808f35779606576532
MD5 hash:
43f595460b2fca77561c63e8a80178dd
SHA1 hash:
ce644189a561c6a2a6f6f6656fc6a46e006d1d87
Detections:
PUA_WIN_XMRIG_CryptoCoin_Miner_Dec20
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Suspicious File
Score:
0.56
File information
The table below shows additional information about this malware sample such as delivery method and external references.
No further information available
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.