Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2020-Jul-27 03:03:23 |
Detected languages |
English - United States
|
TLS Callbacks | 1 callback(s) detected. |
OriginalFilename | xmrig.exe |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Looks for VMWare presence:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to MD5
Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES Uses constants related to Blowfish Uses known Diffie-Helman primes Microsoft's Cryptography API |
Suspicious | The PE is possibly packed. |
Unusual section name found: _TEXT_ad
Unusual section name found: _RANDOMX Unusual section name found: _SHA3_25 Unusual section name found: _TEXT_CN Unusual section name found: _TEXT_CN |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 23/71 (Scanned on 2020-08-01 02:46:57) |
MicroWorld-eScan:
Gen:Variant.Razy.704958
ESET-NOD32: a variant of Win64/CoinMiner.QG potentially unwanted APEX: Malicious ClamAV: Win.Coinminer.Generic-7151250-0 Kaspersky: not-a-virus:HEUR:RiskTool.Win32.BitMiner.gen BitDefender: Gen:Variant.Razy.704958 Ad-Aware: Gen:Variant.Razy.704958 Sophos: XMRig Miner (PUA) Invincea: heuristic FireEye: Generic.mg.a198b777e1edc475 Emsisoft: Gen:Variant.Razy.704958 (B) SentinelOne: DFI - Suspicious PE Endgame: malicious (high confidence) Arcabit: Trojan.Razy.DAC1BE ZoneAlarm: not-a-virus:HEUR:RiskTool.Win32.BitMiner.gen GData: Gen:Variant.Razy.704958 AhnLab-V3: Win-Trojan/Miner3.Exp ALYac: Gen:Variant.Razy.704958 MAX: malware (ai score=81) Rising: HackTool.CoinMiner!1.B971 (CLASSIC) Ikarus: PUA.CoinMiner Cybereason: malicious.c09ad5 Qihoo-360: Win32/Virus.RiskTool.435 |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x120 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 11 |
TimeDateStamp | 2020-Jul-27 03:03:23 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x2ed600 |
SizeOfInitializedData | 0x4a1400 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000000000029DDE4 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x795000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
WS2_32.dll |
#111
#19 #16 #112 #15 WSASend #10 #18 WSARecvFrom WSAIoctl #9 #22 WSASocketW #5 WSARecv FreeAddrInfoW GetAddrInfoW #57 #8 #23 #21 #13 #3 #2 #116 #115 #7 #6 |
---|---|
PSAPI.DLL |
GetProcessMemoryInfo
|
IPHLPAPI.DLL |
GetAdaptersAddresses
|
USERENV.dll |
GetUserProfileDirectoryW
|
CRYPT32.dll |
CertDuplicateCertificateContext
CertFreeCertificateContext CertGetCertificateContextProperty CertEnumCertificatesInStore CertCloseStore CertFindCertificateInStore CertOpenStore |
KERNEL32.dll |
ExpandEnvironmentStringsA
GetModuleFileNameA FindFirstFileA GetCurrentProcess FindNextFileA GetEnvironmentVariableA FindClose GetFileAttributesA CloseHandle ExitProcess MultiByteToWideChar SetPriorityClass SetThreadPriority GetCurrentThread GetProcAddress GetModuleHandleW FreeConsole GetConsoleWindow VirtualProtect VirtualFree VirtualAlloc GetLargePageMinimum LocalAlloc GetLastError LocalFree FlushInstructionCache DeviceIoControl GetModuleFileNameW CreateFileW GetCurrentThreadId AddVectoredExceptionHandler SetLastError GetSystemTime SystemTimeToFileTime GetModuleHandleExW EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionAndSpinCount DeleteCriticalSection TlsAlloc TlsGetValue TlsSetValue TlsFree SwitchToFiber DeleteFiber CreateFiber FindFirstFileW FindNextFileW WideCharToMultiByte GetFileType WriteFile ConvertFiberToThread ConvertThreadToFiber QueryPerformanceCounter GetCurrentProcessId GetSystemTimeAsFileTime FreeLibrary LoadLibraryA LoadLibraryW GetEnvironmentVariableW ReadConsoleA ReadConsoleW GetConsoleScreenBufferInfo SetConsoleTextAttribute RegisterWaitForSingleObject UnregisterWait GetConsoleCursorInfo DuplicateHandle PostQueuedCompletionStatus QueueUserWorkItem SetConsoleCursorInfo FillConsoleOutputCharacterW ReadConsoleInputW CreateFileA WriteConsoleInputW FillConsoleOutputAttribute WriteConsoleW GetNumberOfConsoleInputEvents SetConsoleCursorPosition VerifyVersionInfoA SetEnvironmentVariableW InitializeCriticalSection GetTempPathW GetVersionExW FreeEnvironmentStringsW LoadResource FileTimeToSystemTime QueryPerformanceFrequency LockResource GetSystemInfo GetCurrentDirectoryW SetCurrentDirectoryW VerSetConditionMask GlobalMemoryStatusEx GetEnvironmentStringsW CreateDirectoryW ReadFile GetFileInformationByHandleEx GetFileSizeEx GetDiskFreeSpaceW RemoveDirectoryW GetFinalPathNameByHandleW SetFileTime ReOpenFile CreateHardLinkW GetFileAttributesW UnmapViewOfFile GetFileInformationByHandle FlushViewOfFile SetFilePointerEx CreateFileMappingA MoveFileExW CopyFileW CreateSymbolicLinkW MapViewOfFile FlushFileBuffers SetConsoleCtrlHandler Sleep GetLongPathNameW RtlUnwind ReadDirectoryChangesW CreateIoCompletionPort CancelIo SetHandleInformation CreateEventA SetFileCompletionNotificationModes FormatMessageA LoadLibraryExW SetErrorMode GetQueuedCompletionStatus GetQueuedCompletionStatusEx SetNamedPipeHandleState CreateNamedPipeW PeekNamedPipe WaitForSingleObject CancelSynchronousIo GetNamedPipeHandleStateA CancelIoEx SwitchToThread ConnectNamedPipe TerminateProcess UnregisterWaitEx LCMapStringW GetExitCodeProcess SleepConditionVariableCS TryEnterCriticalSection ReleaseSemaphore WakeConditionVariable InitializeConditionVariable ResumeThread SetEvent GetNativeSystemInfo CreateSemaphoreA GetModuleHandleA DebugBreak GetStartupInfoW GetProcessAffinityMask SetProcessAffinityMask SetThreadAffinityMask GetThreadTimes GetNumaHighestNodeNumber DeleteTimerQueueTimer ChangeTimerQueueTimer CreateTimerQueueTimer GetLogicalProcessorInformation GetThreadPriority CreateThread SignalObjectAndWait CreateTimerQueue InitializeSListHead IsDebuggerPresent IsProcessorFeaturePresent SizeofResource GetConsoleMode SetConsoleMode FreeLibraryAndExitThread InterlockedPopEntrySList FindResourceW GetStdHandle SetConsoleTitleA InterlockedPushEntrySList InterlockedFlushSList QueryDepthSList RtlUnwindEx RtlPcToFileHeader RaiseException GetCommandLineA GetCommandLineW GetDriveTypeW SystemTimeToTzSpecificLocalTime SetStdHandle GetConsoleCP GetFileAttributesExW SetFileAttributesW ExitThread GetACP HeapReAlloc HeapFree HeapAlloc IsValidLocale GetUserDefaultLCID EnumSystemLocalesW HeapSize GetFullPathNameW SetEndOfFile GetTimeZoneInformation FindFirstFileExA IsValidCodePage GetOEMCP SetEnvironmentVariableA GetProcessHeap GetShortPathNameW SetUnhandledExceptionFilter UnhandledExceptionFilter ResetEvent GetStringTypeW GetLocaleInfoW CompareStringW GetTickCount CreateEventW GetCPInfo WaitForSingleObjectEx GetExitCodeThread EncodePointer DecodePointer |
USER32.dll |
TranslateMessage
DispatchMessageA GetProcessWindowStation ShowWindow MessageBoxW GetUserObjectInformationW MapVirtualKeyW GetSystemMetrics GetMessageA |
SHELL32.dll |
ShellExecuteExA
SHGetSpecialFolderPathA |
ADVAPI32.dll |
CryptAcquireContextA
CryptGenRandom GetUserNameW CryptEnumProvidersW CryptSignHashW CryptDestroyHash CryptCreateHash CryptDecrypt CryptExportKey CryptGetUserKey CryptGetProvParam CryptSetHashParam CryptDestroyKey CryptReleaseContext CryptAcquireContextW ReportEventW RegisterEventSourceW DeregisterEventSource CreateServiceW QueryServiceStatus CloseServiceHandle OpenSCManagerW QueryServiceConfigA DeleteService ControlService StartServiceW OpenServiceW LookupPrivilegeValueW AdjustTokenPrivileges LsaOpenPolicy LsaAddAccountRights LsaClose RegCreateKeyA RegSetValueA RegQueryValueExA RegSetValueExA OpenProcessToken RegOpenKeyExA GetTokenInformation |
urlmon.dll |
URLDownloadToFileA
|
ntdll.dll |
RtlCaptureContext
RtlLookupFunctionEntry RtlVirtualUnwind NtQuerySystemInformation |
bcrypt.dll |
BCryptGenRandom
|
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 6.2.3.0 |
ProductVersion | 6.2.3.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | UNKNOWN |
OriginalFilename | xmrig.exe |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2020-Jul-27 03:03:23 |
Version | 0.0 |
SizeofData | 1208 |
AddressOfRawData | 0x3f2ac4 |
PointerToRawData | 0x3f14c4 |
StartAddressOfRawData | 0x1403f2fa0 |
---|---|
EndAddressOfRawData | 0x1403f2fbc |
AddressOfIndex | 0x1404394c8 |
AddressOfCallbacks | 0x1402efdb0 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
Callbacks |
0x000000014029DB34
|
Size | 0x100 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x140429598 |
XOR Key | 0x199b51cb |
---|---|
Unmarked objects | 0 |
C objects (24610) | 24 |
ASM objects (24610) | 13 |
C++ objects (24610) | 188 |
199 (41118) | 4 |
ASM objects (VS 2015/2017 runtime 26706) | 9 |
C++ objects (VS 2015/2017 runtime 26706) | 128 |
C objects (VS 2015/2017 runtime 26706) | 38 |
C objects (27042) | 16 |
Imports (24610) | 25 |
Total imports | 365 |
C objects (VS2017 v15.9.14-15 compiler 27032) | 564 |
265 (27042) | 256 |
ASM objects (27042) | 5 |
Resource objects (27042) | 1 |
151 | 1 |
Linker (27042) | 1 |