Summary | ZeroBOX

PhoenixMiner.exe

Generic Malware Malicious Library UPX Malicious Packer MSOffice File PE64 PE File OS Processor Check
Category Machine Started Completed
FILE s1_win7_x6402 Sept. 20, 2021, 10:13 a.m. Sept. 20, 2021, 10:16 a.m.
Size 8.4MB
Type PE32+ executable (console) x86-64, for MS Windows
MD5 33b49643272dc9044096dc01c71213b6
SHA256 3394c9c3619c41f5b5b23c4a7cb61356d148bf528f1ed41d3dc2d40453ad364f
CRC32 06B243F0
ssdeep 98304:WhpOjgmb/arLyVlwQXiEEEsbME3rSCJ11MBqx5yN/OTfE:8pOjQLyIQXiEEEmME3WC7K+5yYw
Yara
  • Malicious_Packer_Zero - Malicious Packer
  • UPX_Zero - UPX packed file
  • IsPE64 - (no description)
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
  • Malicious_Library_Zero - Malicious_Library
  • Microsoft_Office_File_Zero - Microsoft Office File

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section .gfids
section {u'size_of_data': u'0x00340c00', u'virtual_address': u'0x0041d000', u'entropy': 7.487491345112725, u'name': u'.rdata', u'virtual_size': u'0x00340b88'} entropy 7.48749134511 description A section with a high entropy has been found
entropy 0.389362945646 description Overall entropy of this PE file is high
Lionic Riskware.Win64.Miner.1!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Application.Miner.43
ALYac Gen:Variant.Application.Miner.43
Malwarebytes RiskWare.BitCoinMiner
Zillya Tool.Miner.Win64.307
K7GW Adware ( 0057f2531 )
K7AntiVirus Adware ( 0057f2531 )
Arcabit Trojan.Application.Miner.43
Symantec Trojan.Gen.MBT
ESET-NOD32 a variant of Win64/CoinMiner.SQ potentially unwanted
Kaspersky not-a-virus:HEUR:RiskTool.Win64.Convagent.gen
BitDefender Gen:Variant.Application.Miner.43
Avast Win64:Malware-gen
Ad-Aware Gen:Variant.Application.Miner.43
Emsisoft Gen:Variant.Application.Miner.43 (B)
McAfee-GW-Edition BehavesLike.Win64.Injector.rc
FireEye Gen:Variant.Application.Miner.43
Sophos Generic PUA LE (PUA)
SentinelOne Static AI - Suspicious PE
Jiangmin RiskTool.Miner.acg
Webroot W32.Malware.Gen
Avira PUA/CoinMiner.Gen
MAX malware (ai score=71)
Antiy-AVL Trojan/Generic.ASMalwS.349A93D
Gridinsoft Trojan.Win64.CoinMiner.vb
Microsoft Trojan:Win32/Tnega!ml
ZoneAlarm not-a-virus:HEUR:RiskTool.Win64.Miner.gen
GData Gen:Variant.Application.Miner.43
Cynet Malicious (score: 99)
AhnLab-V3 CoinMiner/Win.PhoenixMiner.R263897
McAfee GenericRXAA-AA!33B49643272D
Fortinet Riskware/Miner
AVG Win64:Malware-gen
Panda Trj/CI.A