MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d44ff00fe9552510aefbf13c4b986dc094b5aefcd099fd3d7ad6dc816968a50b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 12


Intelligence 12 IOCs YARA 5 File information Comments

SHA256 hash: d44ff00fe9552510aefbf13c4b986dc094b5aefcd099fd3d7ad6dc816968a50b
SHA3-384 hash: 24bbaad6bec834566adacf5bd0390166a2e5ae3abf1713469b33494a82c8c8896a4470905b56429b1726e496c1c2af8d
SHA1 hash: c714a73211957aa0c71defa91d4d6beca8e4abb8
MD5 hash: 45899f8f753e57ded07eb20ca57be0f1
humanhash: victor-undress-wyoming-hot
File name:SecuriteInfo.com.Variant.Packed.Themida.21.63687778
Download: download sample
Signature CoinMiner
File size:8'763'800 bytes
First seen:2026-08-14 22:47:03 UTC
Last seen:2026-08-14 23:54:16 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 35a81d16af9f2ba6d515f11152d0364b (65 x CoinMiner, 2 x CobaltStrike)
ssdeep 196608:S+mu1iWy7DOesa7jxatMRlrIM31bxKyb0R5+x9CT1pf3:3m4YDO/a7jYelXldq+81p
TLSH T1AB9633572D9B6DEBC7B866B86C8E06336308C78D08F487DEE5A5480654335722EB42DF
TrID 33.6% (.EXE) OS/2 Executable (generic) (2029/13)
33.1% (.EXE) Generic Win/DOS Executable (2002/3)
33.1% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
Reporter SecuriteInfoCom
Tags:CoinMiner exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
190
Origin country :
FR FR
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
d44ff00fe9552510aefbf13c4b986dc094b5aefcd099fd3d7ad6dc816968a50b
Verdict:
No threats detected
Analysis date:
2026-08-14 00:04:28 UTC
Tags:
themida

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for analyzing tools
Searching for the window
Сreating synchronization primitives
Running batch commands
Launching a process
Creating a service
Creating a file
Launching a service
Creating a process from a recently created file
Creating a file in the Windows subdirectories
Deleting a recently created file
Searching for synchronization primitives
Creating a file in the system32 subdirectories
Enabling autorun for a service
Adding an exclusion to Microsoft Defender
Changing the hosts file
Unauthorized injection to a system process
Enabling autorun by creating a file
Using obfuscated Powershell scripts
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
obfuscated overlay packed packed themidawinlicense
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-08-14T04:12:00Z UTC
Last seen:
2026-08-15T11:04:00Z UTC
Hits:
~10
Result
Threat name:
Detection:
malicious
Classification:
adwa.spyw.evad.mine
Score:
100 / 100
Signature
.NET source code contains process injector
.NET source code references suspicious native API functions
Adds a directory exclusion to Windows Defender
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Contains functionality to compare user and computer (likely to detect sandboxes)
Contains functionality to inject code into remote processes
Creates a thread in another existing process (thread injection)
Creates files in the system32 config directory
DNS related to crypt mining pools
Found direct / indirect Syscall (likely to bypass EDR)
Found strings related to Crypto-Mining
Found suspicious powershell code related to unpacking or dynamic code loading
Hides threads from debuggers
Hooks files or directories query functions (used to hide files and directories)
Hooks processes query functions (used to hide processes)
Hooks registry keys query functions (used to hide registry keys)
Injects a PE file into a foreign processes
Injects code into the Windows Explorer (explorer.exe)
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Modifies power options to not sleep / hibernate
Modifies the context of a thread in another process (thread injection)
Modifies the hosts file
Modifies the prolog of user mode functions (user mode inline hooks)
Obfuscated command line found
PE file contains section with special chars
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sample is not signed and drops a device driver
Sigma detected: Disable power options
Sigma detected: Potential PowerShell Command Line Obfuscation
Sigma detected: Potential WinAPI Calls Via CommandLine
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Stop EventLog
Suspicious powershell command line found
Tries to detect process monitoring tools (Task Manager, Process Explorer etc.)
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Unusual module load detection (module proxying)
Uses powercfg.exe to modify the power settings
Writes to foreign memory regions
Yara detected Xmrig cryptocurrency miner
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1958028 Sample: CiU4PiHyFe Startdate: 14/08/2026 Architecture: WINDOWS Score: 100 64 xmr-eu1.nanopool.org 2->64 66 eip-terr-na.cdp1.digicert.com.akahost.net 2->66 90 Malicious sample detected (through community Yara rule) 2->90 92 Antivirus / Scanner detection for submitted sample 2->92 94 Yara detected Xmrig cryptocurrency miner 2->94 98 14 other signatures 2->98 9 CiU4PiHyFe.exe 1 3 2->9         started        13 powershell.exe 2 15 2->13         started        15 updater.exe 1 2->15         started        signatures3 96 DNS related to crypt mining pools 64->96 process4 file5 58 C:\ProgramDatabehaviorgraphoogle\Chrome\updater.exe, PE32+ 9->58 dropped 60 C:\Windows\System32\drivers\etc\hosts, ASCII 9->60 dropped 114 Uses powercfg.exe to modify the power settings 9->114 116 Modifies the context of a thread in another process (thread injection) 9->116 118 Modifies the hosts file 9->118 132 6 other signatures 9->132 17 powershell.exe 23 9->17         started        20 sc.exe 1 9->20         started        22 dialer.exe 1 9->22         started        32 13 other processes 9->32 120 Writes to foreign memory regions 13->120 122 Injects a PE file into a foreign processes 13->122 24 dllhost.exe 13->24         started        26 conhost.exe 13->26         started        62 C:\Windows\Temp\cazrpbojisdc.sys, PE32+ 15->62 dropped 124 Antivirus detection for dropped file 15->124 126 Tries to detect sandboxes and other dynamic analysis tools (window names) 15->126 128 Found strings related to Crypto-Mining 15->128 130 Sample is not signed and drops a device driver 15->130 28 powershell.exe 15->28         started        30 cmd.exe 15->30         started        34 12 other processes 15->34 signatures6 process7 dnsIp8 70 Found suspicious powershell code related to unpacking or dynamic code loading 17->70 72 Unusual module load detection (module proxying) 17->72 74 Loading BitLocker PowerShell Module 17->74 37 conhost.exe 17->37         started        76 Adds a directory exclusion to Windows Defender 20->76 78 Modifies power options to not sleep / hibernate 20->78 40 conhost.exe 20->40         started        80 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 22->80 82 Injects code into the Windows Explorer (explorer.exe) 24->82 84 Contains functionality to inject code into remote processes 24->84 86 Writes to foreign memory regions 24->86 88 3 other signatures 24->88 42 powershell.exe 24->42         started        44 lsass.exe 24->44 injected 48 3 other processes 24->48 46 conhost.exe 28->46         started        50 2 other processes 30->50 52 14 other processes 32->52 68 141.94.250.96, 10343, 49731 OVHFR France 34->68 54 9 other processes 34->54 signatures9 process10 signatures11 100 Suspicious powershell command line found 37->100 102 Obfuscated command line found 37->102 104 Creates files in the system32 config directory 42->104 106 Writes to foreign memory regions 42->106 108 Modifies the context of a thread in another process (thread injection) 42->108 110 Injects a PE file into a foreign processes 42->110 56 conhost.exe 42->56         started        112 Unusual module load detection (module proxying) 44->112 process12
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Packed.Themida
Status:
Malicious
First seen:
2026-08-14 13:34:22 UTC
File Type:
PE+ (Exe)
AV detection:
21 of 38 (55.26%)
Threat level:
  1/5
Result
Malware family:
Score:
  10/10
Tags:
family:xmrig defense_evasion execution miner persistence themida trojan
Behaviour
Checks SCSI registry key(s)
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Executes a command shell one-liner
Drops file in Windows directory
Launches sc.exe
Drops file in System32 directory
Suspicious use of NtSetInformationThreadHideFromDebugger
Suspicious use of SetThreadContext
Checks whether UAC is enabled
Power Settings
Checks BIOS information in registry
Creates new service(s)
Executes dropped EXE
Stops running service(s)
Themida packer
Command and Scripting Interpreter: PowerShell
Drops file in Drivers directory
Identifies VirtualBox via ACPI registry values (likely anti-VM)
XMRig Miner payload
Family: xmrig
Suspicious use of NtCreateProcessExOtherParentProcess
Suspicious use of NtCreateUserProcessOtherParentProcess
Unpacked files
SH256 hash:
d44ff00fe9552510aefbf13c4b986dc094b5aefcd099fd3d7ad6dc816968a50b
MD5 hash:
45899f8f753e57ded07eb20ca57be0f1
SHA1 hash:
c714a73211957aa0c71defa91d4d6beca8e4abb8
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:INDICATOR_EXE_Packed_Themida
Author:ditekSHen
Description:Detects executables packed with Themida
Rule name:pe_detect_tls_callbacks
Rule name:Windows_Generic_Threat_e8abb835
Author:Elastic Security

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments