How to remove BIT3BAC.tmp
- File Details
- Overview
- Analysis
BIT3BAC.tmp
The module BIT3BAC.tmp has been detected as Trojan.CoinMiner
File Details
| Product Name: |
|
| Company Name: |
|
| MD5: |
3444ef19b247efa82d38c452ea6cf3b6 |
| Size: |
663 KB |
| First Published: |
2017-09-10 12:02:30 (8 years ago) |
| Latest Published: |
2021-11-30 21:18:19 (4 years ago) |
| Status: |
Trojan.CoinMiner (on last analysis) |
|
| Analysis Date: |
2021-11-30 21:18:19 (4 years ago) |
| %appdata%\msvc |
| %appdata%\appdata |
| %appdata%\ieservise |
| %appdata% |
| %appdata% |
| %appdata% |
| onedrive.exe |
| BIT3BAC.tmp |
| BIT7A93.tmp |
| BIT3468.tmp |
| BIT3F45.tmp |
| BIT253E.tmp |
| BIT3092.tmp |
| BITF035.tmp |
| BIT6203.tmp |
|
74.0% |
|
|
7.3% |
|
|
7.3% |
|
|
3.3% |
|
|
2.4% |
|
|
1.6% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
| Windows 10 |
76.4% |
|
| Windows 7 |
22.8% |
|
| Windows 8.1 |
0.8% |
|
Analysis
| Subsystem: |
Windows CUI |
| PE Type: |
pe |
| OS Bitness: |
64 |
| Image Base: |
0x0000000000400000 |
| Entry Address: |
0x00001510 |
| Name |
Size of data |
MD5 |
| .text |
463360 |
c8865e55d0d8fd31848264ff3a0caba0 |
| .data |
1536 |
4eb7cf9e269d2b87f5cba98f042b6794 |
| .rdata |
59392 |
5505af672a31e73c01be2aabf4acb609 |
| .pdata |
16896 |
fc841bf440fea2d8e2042a9510c7ff42 |
| .xdata |
16384 |
b70a41ade32c2156fcae10b86c313591 |
| .bss |
0 |
00000000000000000000000000000000 |
| .idata |
11776 |
81d62f4d23c1b2647ad0a5c578f8c84e |
| .CRT |
512 |
4420ebfd86a1a8972871e5208a5f01e1 |
| .tls |
512 |
c6ef436a7694889fcf45561cf2ca98d4 |
| .rsrc |
107344 |
00b50edab59040e230ae466308e4791e |