MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f8a3b64aa3c1c639a5ce1b100de860d4f97703879df0d01ce0118ae97c1b7423. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner.XMRig


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: f8a3b64aa3c1c639a5ce1b100de860d4f97703879df0d01ce0118ae97c1b7423
SHA3-384 hash: b48bcc43303865beffa45f479217de51663f9ea2139383c30fb68121bfa29ad4e198f5712a71db0b0a11ccd1543d6804
SHA1 hash: 7042a5d0e49e6d4af43bfadf9800e45ad25b7016
MD5 hash: 7c2175b6e89729748f8c24f41f6283ae
humanhash: edward-delaware-papa-ohio
File name:SecuriteInfo.com.Artemis7C2175B6E897.27772
Download: download sample
Signature CoinMiner.XMRig
File size:556'032 bytes
First seen:2020-04-08 10:49:33 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 08c9561278fa9bbb6df9d2ef07ed89d6 (1 x CoinMiner.XMRig)
ssdeep 6144:0Yntn+wuymA4nRe7W62vvngTZ3kvaGAwypEafBdRoiuy/e/sZ23EqCzAU/Gag:FtM9e7W63VEiNhLysZ66kU/Gj
Threatray 425 similar samples on MalwareBazaar
TLSH 68C4B509D6A78825CF9B63BF4462B63581292F10A43303933DED771480BB6D365DBAED
Reporter SecuriteInfoCom
Tags:CoinMiner.XMRig

Intelligence


File Origin
# of uploads :
1
# of downloads :
115
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Phorpiex
Status:
Malicious
First seen:
2020-04-08 07:45:26 UTC
File Type:
PE (Exe)
Extracted files:
39
AV detection:
25 of 31 (80.65%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CoinMiner.XMRig

Executable exe f8a3b64aa3c1c639a5ce1b100de860d4f97703879df0d01ce0118ae97c1b7423

(this sample)

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
CHECK_NXMissing Non-Executable Memory Protectioncritical
Reviews
IDCapabilitiesEvidence
RAS_APIUses Remote AccessRASAPI32.dll::RasDialA
RASAPI32.dll::RasGetErrorStringA
RASAPI32.dll::RasHangUpA
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CloseHandle
KERNEL32.dll::CreateThread
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryExW
KERNEL32.dll::GetStartupInfoW
KERNEL32.dll::GetCommandLineA
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::WriteConsoleW
KERNEL32.dll::ReadConsoleW
KERNEL32.dll::SetStdHandle
KERNEL32.dll::GetConsoleMode
KERNEL32.dll::GetConsoleCP
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateFileW
KERNEL32.dll::GetFileAttributesA
VERSION.dll::GetFileVersionInfoSizeW
VERSION.dll::GetFileVersionInfoW
WIN_REG_APICan Manipulate Windows RegistryADVAPI32.dll::RegOpenKeyExA
WIN_USER_APIPerforms GUI ActionsUSER32.dll::AppendMenuA
USER32.dll::CreateWindowExA

Comments