Lowmine.exe Risk CoinMiner Analysis

Risk CoinMiner
Updated on 2024-03-18 (25 days ago)
Checked by Online Virus Scanner
Online Virus Checkerv.1.0.169.174
DB Version:2024-03-18 10:00:26

Risk.Win64.CoinMiner.sd!i

CoinMiner is a type of malware that harnesses the victim's computer resources, primarily CPU and RAM, to engage in cryptocurrency mining, such as for Monero or Zcash. This malware establishes persistence by integrating an open-source mining tool into the system's startup routine without the user's consent. Advanced coin miners often employ techniques like timer configurations or CPU usage limits to operate discreetly and avoid detection.

Filelowmine.exe
Checked2024-03-18 10:51:28
MD5ec8e7dd67dfd96326ec2f49048711018
SHA1369b6ebc913a03602b42347ea599c75216cfc752
SHA256851a76639026e11becee15b1506463ed1d77368b2cad8c9365badf9c8a584a62
SHA51215b795ad25161e4db2a83568f05846e29762a9abb3826e7bc163dad6744b8ceb77ab731a3867b3c17cb6abdf975989c469735f08b5ac79fd5a47e8878e7f469e
Imphasha1701842e84d7381d40b6b0f0aaef798
File Size5450752 bytes

Risk.Win64.CoinMiner.sd!i Removal

Risk.Win64.CoinMiner.sd!i Removal

Gridinsoft has the capability to identify and eliminate Risk.Win64.CoinMiner.sd!i without requiring further user intervention.

  • Start by downloading Gridinsoft Anti-Malware to your computer.
  • Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  • Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  • Click on the "Standard Scan" button.
  • After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  • If prompted, restart your system to complete the removal process.

File Version Information

CompanyNamewww.lowmine.com
FileDescriptionLOWMine miner
FileVersion6.21.1
LegalCopyrightCopyright (C) 2016-2024 lowmine.com
OriginalFilenamelowmine.exe
ProductNameLOWMine
ProductVersion6.21.1
Translation0x0000 0x04b0

Portable Executable Info

e35ef5b40987be4a81b37bdb1b3a8730
67b5702929aead99d08ec74265d272c5
e8f4b4d959d6a6f8
Image Base:0x140000000
Entry Point:0x14034f34c
Compilation:2024-03-18 10:49:57
Checksum:0x00000000 (Actual: 0x005361e3)
OS Version:6.0
PEiD:PE32+ executable (console) x86-64, for MS Windows
Sign:The PE file does not contain a certificate table.
Sections:10
Imports: WS2_32, IPHLPAPI, USERENV, CRYPT32, KERNEL32, USER32, SHELL32, ole32, ADVAPI32, bcrypt,
Exports: 0
Resources:7

Sections

Name Virtual Address Virtual Size Raw Size MD5 Entropy
.text 0x00001000 0x00388184 0x00388200 906e61bbbb5460ba3b6e293892daeb79 6.51
.rdata 0x0038a000 0x00168ca8 0x00168e00 aa8975db04c73fa8d4d15d73fd651f23 6.43
.data 0x004f3000 0x002afd34 0x0000f800 4093631db3565a63998f559a584f67fd 4.07
.pdata 0x007a3000 0x0001fa58 0x0001fc00 52c615e64cf27b5775e2500de40dad79 6.30
_RANDOMX 0x007c3000 0x00000c56 0x00000e00 9ee63642b94966ecb630ee0843e46b26 5.68
_TEXT_CN 0x007c4000 0x000026d1 0x00002800 afea7882aa31e5987db2f12b8933de56 6.08
_TEXT_CN 0x007c7000 0x00001184 0x00001200 409bf3f918f2402291cb56c2e9354b47 6.05
_RDATA 0x007c9000 0x000001f4 0x00000200 84595f5f1c3f876b1166d9b129d4d0d9 4.21
.rsrc 0x007ca000 0x000059d8 0x00005a00 e83de2c96f77b211fab320183b238797 5.43
.reloc 0x007d0000 0x00007ff0 0x00008000 85aa6f05d876ea94616b8953353d947e 5.46

Leave a comment*

Share your thoughts or insights about this file. Do you align with our conclusion?

*Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Please Wait...

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware