Report - MinerXMR.exe

RAT Generic Malware PE File OS Processor Check .NET EXE PE32 PE64
ScreenShot
Created 2021.09.12 14:52 Machine s1_win7_x6401
Filename MinerXMR.exe
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
AI Score
4
Behavior Score
2.8
ZERO API file : malware
VT API (file) 44 detected (malicious, high confidence, MSILZilla, YakbeexMSIL, Unsafe, Save, Coinminer, BEJZ, Attribute, HighConfidence, Mino, Prometei, Miner, Ljuf, DownLoader32, GenericRXNH, R + Mal, Static AI, Malicious PE, azry, ATRAPS, ai score=85, kcloud, score, R338384, ZemsilF, 9p0@aaN3Gui, GdSda, confidence)
md5 3b29fe3eb1892fa6e766bd039b88eeec
sha256 27e2593d29c04065445c5462b5af5f77d555dc00318afa0cf7c68e70bbaca739
ssdeep 49152:qNDFFPJu8fBsVE6ij+RNg+UKpBvtqB3m1RC3:4zP88fBsnZTgOtqB3m1RC3
imphash f34d5f2d4577ed6d9ceec516c1f5a744
impfuzzy 3:rGsLdAIEK:tf
  Network IP location

Signature (5cnts)

Level Description
danger File has been identified by 44 AntiVirus engines on VirusTotal as malicious
watch Creates an executable file in a user folder
notice Performs some HTTP requests
notice Resolves a suspicious Top Level Domain (TLD)
info One or more processes crashed

Rules (8cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
info Is_DotNET_EXE (no description) binaries (upload)
info IsPE32 (no description) binaries (upload)
info IsPE64 (no description) binaries (download)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (download)
info PE_Header_Zero PE File Signature binaries (upload)
info Win_Backdoor_AsyncRAT_Zero Win Backdoor AsyncRAT binaries (upload)

Network (4cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://a0577836.xsph.ru/cmd.php?timeout=1 RU Sprinthost.ru LLC 141.8.192.6 clean
http://a0577836.xsph.ru/cmd.php?hwid=7C6024AD RU Sprinthost.ru LLC 141.8.192.6 clean
a0577836.xsph.ru RU Sprinthost.ru LLC 141.8.192.6 clean
141.8.192.6 RU Sprinthost.ru LLC 141.8.192.6 clean

Suricata ids

PE API

IAT(Import Address Table) Library

mscoree.dll
 0x402000 _CorExeMain

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure