SHA1:
- 801d764429fae92dbd56bb2a981ad85c0a09e246
A Trojan designed to mine cryptocurrency, an early version of a miner
Contains the following resources:
// 0x000072FC: Service.Payload.cm.dat (470520 bytes, Embedded, Public)
// 0x0021DF24: Service.Payload.libcurl.dat (572416 bytes, Embedded, Public)
// 0x002A9B2C: Service.Payload.libeay32.dat (1447424 bytes, Embedded, Public)
// 0x0040B134: Service.Payload.libgcc_s_seh-1.dat (75264 bytes, Embedded, Public)
// 0x0041D73C: Service.Payload.libstdc++-6.dat (957440 bytes, Embedded, Public)
// 0x00507344: Service.Payload.libwinpthread-1.dat (79637 bytes, Embedded, Public)
// 0x0007A0FC: Service.Payload.ph.dat (1719840 bytes, Embedded, Public)
// 0x0051AA64: Service.Payload.ssleay32.dat (314880 bytes, Embedded, Public)
// 0x0056786C: Service.Payload.zlib1.dat (89600 bytes, Embedded, Public)
// 0x0057D674: Service.Starter.exe (5120 bytes, Embedded, Public)
All resources with the DAT extension are encrypted using the XOR algorithm.
- ph.dat — a driver of a tool Process Hacker.
- cm.dat — a packed miner.
- Starter.exe —an application for launching Trojan’s components.
Attempts to delete the following system services:
mbamservice
defend
msmpsvc
It attempts to detect and shut down the following running processes:
anvir
mbamservice
avp
cmdagent
News about the Trojan |