File Name | dlIhost.exe |
File Type |
PE32+ executable (console) x86-64, for MS Windows
|
Scanner Version | 1.0.185.174 |
Database Version | 2024-08-24 09:00:20 UTC |
Malware family: CoinMiner
Hash Type | Value | Action |
---|---|---|
MD5 |
5d70f8c5b7a48db9df556346def8a471
|
|
SHA1 |
616680fafb83a81ff5979bc7bb0ffdf0df42eb9b
|
|
SHA256 |
696bc3a058478d16c2a353bc3514fba556469925cbc4f4610377b661ac0bce1c
|
|
SHA512 |
4809a899c7135801b1409a6efe715cc4e3f7564b22f3e81e6132fe1457cddb8511fc7615af65372b140123e45c757d2174b8dee6874a451d5c6b97c5a6239d9a
|
|
ImpHash |
72b6ec48223e4d450dd235275dfa42a4
|
Image Base | 0x140000000 |
Entry Point | 0x14031d44c |
Compilation Time | 2024-06-03 15:54:33 |
Checksum | 0x00000000 (Actual: 0x004a3d8a) |
OS Version | 6.0 |
PEiD Signatures |
PE32+ executable (console) x86-64, for MS Windows
|
Digital Signature | The PE file does not contain a certificate table. |
Imports |
10 libraries
WS2_32, PSAPI, IPHLPAPI, USERENV, CRYPT32, KERNEL32, USER32, ole32, ADVAPI32, bcrypt |
Exports | 0 functions |
Resources | 2 Resources |
Sections | 10 Sections |
CompanyName | Microsoft Corporation |
FileDescription | COM Surrogate |
FileVersion | 10.0.18362.1 (WinBuild.160101.0800) |
InternalName | dllhost.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | dllhost.exe |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 10.0.18362.1 |
Translation | 0x0000 0x04b0 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
3,491,492 bytes | 3,491,840 bytes | 6.52 (Compressed) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
3266D0BCB109D9D7C79596F936429509 |
.rdata |
0x00356000 |
1,139,742 bytes | 1,140,224 bytes | 6.32 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
1E1B63A43BFE8D0979FB4CEFE8D1973B |
.data |
0x0046d000 |
2,790,732 bytes | 38,912 bytes | 3.78 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
6DCE77F130CCA25421FEE38E61F8D83F |
.pdata |
0x00717000 |
123,132 bytes | 123,392 bytes | 6.31 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
4A59E2865A83B6C09276CFB8524E006D |
_RANDOMX |
0x00736000 |
3,158 bytes | 3,584 bytes | 5.68 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
9EE63642B94966ECB630EE0843E46B26 |
_TEXT_CN |
0x00737000 |
9,937 bytes | 10,240 bytes | 6.08 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
AFEA7882AA31E5987DB2F12B8933DE56 |
_TEXT_CN |
0x0073a000 |
4,484 bytes | 4,608 bytes | 6.05 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
409BF3F918F2402291CB56C2E9354B47 |
_RDATA |
0x0073c000 |
500 bytes | 512 bytes | 4.19 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
0EF7E40F0EFAAEC74EE5FC2D4909D33F |
.rsrc |
0x0073d000 |
1,432 bytes | 1,536 bytes | 3.96 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
390525D5761115C2C78E89E12906A097 |
.reloc |
0x0073e000 |
31,748 bytes | 32,256 bytes | 5.44 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
20796ACEAD4B376DB56A1DE604CDF735 |
1 section(s) with elevated entropy (≥6.5) - possible compression
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_VERSION | 1 | 888 bytes | |
RT_MANIFEST | 1 | 381 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
The PE file does not contain a certificate table.
Recommendation: Verify the file source and ensure it comes from a trusted publisher.
Gridinsoft has the capability to identify and eliminate Trojan.Win64.CoinMiner.ca without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system