Gridinsoft Logo
File Icon

MarvelousDesigner12_Personal_x64.exe Trojan CoinMiner Analysis

Technical Analysis

File Name MarvelousDesigner12_Personal_x64.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.187.174
Database Version 2024-09-12 23:00:38 UTC

Trojan.Win64.CoinMiner.cl

Malware family: CoinMiner

CoinMiner malware utilizes system resources including CPU and RAM for unauthorized cryptocurrency mining. It establishes persistence through startup integration and may use resource management techniques to avoid detection while mining currencies like Monero or Zcash.
N/A
Detection Rate
42,080,256
File Size (bytes)
2024-09-12
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
b8a9ba10aad52e79d07d95e4912be9cb
SHA1
593ccd25484688bf395d5dadaf19102c770d9367
SHA256
925431d9ad6dde0970110c701b45d78ba2ef5806cd56eb8b2014efc5bb73ee5b
SHA512
72147568d9cdc16430b0aae483af2ce332a647bc62915ce5761e1c110e0996a834c9bb9dbe47e99f4d43557dba6e2bce3a6498e85a1da2ea381d98d2e0b241fc
ImpHash
a589ba7bbee6e12ef05d757f0a9f4ead

PE Analysis

Basic Information

Icon
Hash: cfd8046d4ce61aa494c11f056d257c32
Fuzzy: 6e52000f98ea8404a09e57eb6e4b6e0a
dHash: 70fc6d330f2bd0f0
Image Base 0x140000000
Entry Point 0x14d0be9c7
Compilation Time 2022-12-06 07:15:59
Checksum 0x028258b2 (Actual: 0x028258b2)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
PDB Path C:\Users\admin\Documents\BuildAgent\work\477ea84496986ea8\Marvelous\Distribution\Release_MDX_Personal\x64\MarvelousDesigner12_Personal_x64.pdb
Digital Signature The PE file does not contain a certificate table.
Imports 26 libraries
Exports 1 functions
Resources 4 Resources
Sections 15 Sections

Version Information

FileVersion 7, 1, 143, 41692
ProductVersion 7, 1, 143, 41692
ProductName Marvelous Designer Personal
LegalCopyright Copyright 2022 CLO Virtual Fashion Inc. All rights reserved.
Translation 0x0412 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.textbss 0x00001000 42,971,319 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.text 0x028fd000 87,750,885 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.rdata 0x07cad000 67,140,277 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.data 0x0bcb5000 3,248,345 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.pdata 0x0bfcf000 2,457,888 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.idata 0x0c228000 345,602 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.msvcjmc 0x0c27d000 257 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.tls 0x0c27e000 55,107 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.nv_fatb 0x0c28c000 9,665,804 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.nvFatBi 0x0cbc4000 284 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.00cfg 0x0cbc5000 283 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
_RDATA 0x0cbc6000 50,010 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.vmp0 0x0cbd3000 1,353,990 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.vmp1 0x0cd1e000 41,833,468 bytes 41,833,472 bytes 7.99 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 73691DF470464423968DF60C953E0B68
.rsrc 0x0f504000 245,069 bytes 245,248 bytes 4.43 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ A0ADF2C78DCE3E7C1BCB107D165CFFD9
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

Total Resources: 4 (244,761 bytes)
Resource Type Count Total Size Percentage
RT_ICON 1 243,752 bytes
99.6%
RT_GROUP_ICON 1 20 bytes
0%
RT_VERSION 1 608 bytes
0.2%
RT_MANIFEST 1 381 bytes
0.2%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

The PE file does not contain a certificate table.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Win64.CoinMiner.cl Removal

Gridinsoft has the capability to identify and eliminate Trojan.Win64.CoinMiner.cl without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware