2009-12-06 00:51:50
7fa974366048f9c551ef45714595665e
| Name | Virtual Address | Virtual Size | Size of Raw Data | Entropy |
|---|---|---|---|---|
| .text | 0x00001000 | 0x00005a2c | 0x00005c00 | 6.44711303359 |
| .rdata | 0x00007000 | 0x00001190 | 0x00001200 | 5.17976375781 |
| .data | 0x00009000 | 0x003bc798 | 0x00000400 | 4.61455988146 |
| .ndata | 0x003c6000 | 0x00040000 | 0x00000000 | 0.0 |
| .rsrc | 0x00406000 | 0x0000fbd8 | 0x0000fc00 | 7.02457148864 |
| Name | Offset | Size | Language | Sub-language | File type |
|---|---|---|---|---|---|
| RT_ICON | 0x004154c8 | 0x00000128 | LANG_ENGLISH | SUBLANG_ENGLISH_US | Device independent bitmap graphic, 16 x 32 x 4, image size 128 |
| RT_ICON | 0x004154c8 | 0x00000128 | LANG_ENGLISH | SUBLANG_ENGLISH_US | Device independent bitmap graphic, 16 x 32 x 4, image size 128 |
| RT_ICON | 0x004154c8 | 0x00000128 | LANG_ENGLISH | SUBLANG_ENGLISH_US | Device independent bitmap graphic, 16 x 32 x 4, image size 128 |
| RT_ICON | 0x004154c8 | 0x00000128 | LANG_ENGLISH | SUBLANG_ENGLISH_US | Device independent bitmap graphic, 16 x 32 x 4, image size 128 |
| RT_ICON | 0x004154c8 | 0x00000128 | LANG_ENGLISH | SUBLANG_ENGLISH_US | Device independent bitmap graphic, 16 x 32 x 4, image size 128 |
| RT_ICON | 0x004154c8 | 0x00000128 | LANG_ENGLISH | SUBLANG_ENGLISH_US | Device independent bitmap graphic, 16 x 32 x 4, image size 128 |
| RT_ICON | 0x004154c8 | 0x00000128 | LANG_ENGLISH | SUBLANG_ENGLISH_US | Device independent bitmap graphic, 16 x 32 x 4, image size 128 |
| RT_ICON | 0x004154c8 | 0x00000128 | LANG_ENGLISH | SUBLANG_ENGLISH_US | Device independent bitmap graphic, 16 x 32 x 4, image size 128 |
| RT_ICON | 0x004154c8 | 0x00000128 | LANG_ENGLISH | SUBLANG_ENGLISH_US | Device independent bitmap graphic, 16 x 32 x 4, image size 128 |
| RT_ICON | 0x004154c8 | 0x00000128 | LANG_ENGLISH | SUBLANG_ENGLISH_US | Device independent bitmap graphic, 16 x 32 x 4, image size 128 |
| RT_DIALOG | 0x00415810 | 0x00000060 | LANG_ENGLISH | SUBLANG_ENGLISH_US | data |
| RT_DIALOG | 0x00415810 | 0x00000060 | LANG_ENGLISH | SUBLANG_ENGLISH_US | data |
| RT_DIALOG | 0x00415810 | 0x00000060 | LANG_ENGLISH | SUBLANG_ENGLISH_US | data |
| RT_GROUP_ICON | 0x00415870 | 0x00000092 | LANG_ENGLISH | SUBLANG_ENGLISH_US | data |
| RT_MANIFEST | 0x00415908 | 0x000002cc | LANG_ENGLISH | SUBLANG_ENGLISH_US | XML 1.0 document, ASCII text, with very long lines (716), with no line terminators |
| IRMA | Signature |
|---|---|
| Trend Micro SProtect (Linux) | Clean |
| Avast Core Security (Linux) | Win32:Miner-EG [Trj] |
| C4S ClamAV (Linux) | Win.Trojan.Coinminer-6622864-0 |
| Trellix (Linux) | W32/CoinMiner.d trojan |
| Sophos Anti-Virus (Linux) | Mal/Miner-BA |
| Bitdefender Antivirus (Linux) | Trojan.GenericKD.37723270 |
| G Data Antivirus (Windows) | Virus: Trojan.GenericKD.37723270 (Engine A) |
| WithSecure (Linux) | Clean |
| ESET Security (Windows) | multiple detections |
| DrWeb Antivirus (Linux) | Trojan.BtcMine.815 |
| ClamAV (Linux) | Win.Trojan.Coinminer-6622864-0 |
| eScan Antivirus (Linux) | Trojan.GenericKD.37723270(DB) |
| Kaspersky Standard (Windows) | Trojan.NSIS.Agent.pf |
| Emsisoft Commandline Scanner (Windows) | Trojan.GenericKD.37723270 (B) |