Gridinsoft Logo
File Icon

Assassins Creed Odyssey (virus)v1.0.2-v1.5.4 Plus 28 Trainer.exe Trojan CoinMiner Analysis

Technical Analysis

File Name Assassins Creed Odyssey (virus)v1.0.2-v1.5.4 Plus 28 Trainer.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.233.174
Database Version 2026-01-10 23:00:16 UTC

Trojan.Win64.CoinMiner.ns

Malware family: CoinMiner

CoinMiner malware utilizes system resources including CPU and RAM for unauthorized cryptocurrency mining. It establishes persistence through startup integration and may use resource management techniques to avoid detection while mining currencies like Monero or Zcash.
N/A
Detection Rate
1,413,120
File Size (bytes)
2026-01-10
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
d5e098531d6c0d3d59541f934b62dfba
SHA1
182489876f54e3f51fbcb468a04e18f5589f872c
SHA256
06b4d1399741e9af55f549e9940319e1ef6ddf42266662142c214d85fd1f72af
SHA512
b3c4a064c7603c0f737c805aee4b402634d8e1412a73c9a3acf5a2e9ad9d7e61ef06faa1e6ff3351caba6c2c7869dab6999f978ef6342019cc5a7a4da4660f33
ImpHash
cf68394e6217c2041e6113c35a9269c6

PE Analysis

Basic Information

Icon
Hash: 7249d5fc6221a5b21411aa2ad27aa387
Fuzzy: a1c738eea59667290c83d00f50a19604
dHash: 70f8fc7a7e2eaa70
Image Base 0x140000000
Entry Point 0x140030128
Compilation Time 2020-12-19 09:56:07
Checksum 0x00000000 (Actual: 0x0016344a)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 8 libraries
KERNEL32, USER32, SHELL32, OLEAUT32, mscoree, WININET, VERSION, WINMM
Exports 0 functions
Resources 12 Resources
Sections 6 Sections

Version Information

CompanyName 3DMGAME
FileDescription Assassins Creed Odyssey v1.0.2-v1.5.4 Plus 28 Trainer
FileVersion 1.0.0.0
InternalName Assassins Creed Odyssey v1.0.2-v1.5.4 Plus 28 Trainer
LegalCopyright FLiNG Copyright (C) 2020
OriginalFilename Assassins Creed Odyssey v1.0.2-v1.5.4 Plus 28 Trainer.exe
ProductName Assassins Creed Odyssey v1.0.2-v1.5.4 Plus 28 Trainer
ProductVersion 1.0.597.12
Translation 0x0000 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 468,244 bytes 468,480 bytes 6.44 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 3CF6A71169B74C6CD966216F2EBCC8B7
.rdata 0x00074000 182,352 bytes 182,784 bytes 4.93 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 9AA9F86A47CFDF24F85C07D8EE7EFB6A
.data 0x000a1000 22,540 bytes 12,800 bytes 4.29 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE B64233E4036C0B5054F277727C1CE4DE
.pdata 0x000a7000 24,492 bytes 24,576 bytes 5.81 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 762ACC737AD92CFC33BB9714C6254CA4
.rsrc 0x000ad000 718,056 bytes 718,336 bytes 7.39 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 9E28DB90A6B2C8C794AD87C2788FB28D
.reloc 0x0015d000 4,948 bytes 5,120 bytes 5.39 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 26DD58E099508663724CC4285416347D
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 12 (717,203 bytes)
Resource Type Count Total Size Percentage
COVER 1 113,664 bytes
15.8%
REMOTE 2 308,228 bytes
43%
UI 1 181,248 bytes
25.3%
WAVE 2 22,222 bytes
3.1%
RT_ICON 3 90,092 bytes
12.6%
RT_GROUP_ICON 1 48 bytes
0%
RT_VERSION 1 1,048 bytes
0.1%
RT_MANIFEST 1 653 bytes
0.1%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Win64.CoinMiner.ns Removal

Gridinsoft has the capability to identify and eliminate Trojan.Win64.CoinMiner.ns without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Your Score for

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware