How to remove BIT25F8.tmp
- File Details
- Overview
- Analysis
BIT25F8.tmp
The module BIT25F8.tmp has been detected as Trojan.CoinMiner
File Details
Product Name: |
|
MD5: |
0714938af515736671592e48c03708cd |
Size: |
1 MB |
First Published: |
2017-10-13 03:06:33 (7 years ago) |
Latest Published: |
2018-08-02 09:08:26 (6 years ago) |
Status: |
Trojan.CoinMiner (on last analysis) |
|
Analysis Date: |
2018-08-02 09:08:26 (6 years ago) |
%appdata%\hydrogen |
%appdata%\msvc |
%sysdrive%\msvc |
%appdata%\bthprops |
%appdata% |
|
33.3% |
|
|
16.7% |
|
|
16.7% |
|
|
16.7% |
|
|
8.3% |
|
|
8.3% |
|
Windows 7 |
75.0% |
|
Windows 10 |
16.7% |
|
Windows 8.1 |
8.3% |
|
Analysis
Subsystem: |
Windows CUI |
PE Type: |
pe |
OS Bitness: |
64 |
Image Base: |
0x0000000000400000 |
Entry Address: |
0x00001510 |
Name |
Size of data |
MD5 |
.text |
581120 |
a26a3fdbf82cb95efac817b17be23425 |
.data |
1536 |
b4cf67f93bd6355ec4b76c7f09d65e6a |
.rdata |
67072 |
276a6c11d6dbcfdbbed43b58f9d95aeb |
.pdata |
21504 |
b727775cb4601605d31610296a5d2499 |
.xdata |
19456 |
4cc7b80ee3bc984cbf69e53109bc76dd |
.bss |
0 |
00000000000000000000000000000000 |
.idata |
11776 |
43459538a203b65b634dbbc6a9a06b52 |
.CRT |
512 |
b2a84d17f9f3ea8d1fefe965c1097152 |
.tls |
512 |
4ef93367339f74ca704c65f026b1cb99 |
.rsrc |
372352 |
58f6f17eecb44a6b75ae7ed8243f2492 |