File Name | Map Downloader Installer.exe |
File Type |
PE32 executable (console) Intel 80386, for MS Windows
|
Scanner Version | 1.0.223.174 |
Database Version | 2025-08-16 21:00:25 UTC |
Malware family: CoinMiner
Hash Type | Value | Action |
---|---|---|
MD5 |
ae11e1f4c857933e2018c1e333262103
|
|
SHA1 |
85c2ed175dbe7682e7fdae0e28e4968c8b50d76c
|
|
SHA256 |
c5c78bd1d00ee698f6ade60e2f48fcc617f0f439cdfcbad0270de80ada585b57
|
|
SHA512 |
f14a1a787dba325195e58d1c02cbfa1279c132444c1d352ace356e67d0a7bc89e0d472e66419648d242d5cb0c3aaa4ae93de334a3a741e5f51c91ab5aebcb1e0
|
|
ImpHash |
6c83ba1796fcc2cd0567a52e2bdc2062
|
Icon |
Hash: 07ee3252cfe615b18867aa4d1b453e08
Fuzzy: 9ad0be240e1afce6d5526e2bd3b55088 dHash: f0d0aa331df0f0f0 |
Image Base | 0x00400000 |
Entry Point | 0x01206ac1 |
Compilation Time | 2021-04-09 09:51:56 |
Checksum | 0x00000000 (Actual: 0x0153af43) |
OS Version | 6.0 |
PEiD Signatures |
PE32 executable (console) Intel 80386, for MS Windows
|
Digital Signature | No valid SignedData structure was found. |
Imports | 33 libraries |
Exports | 132 functions |
Resources | 19 Resources |
Sections | 9 Sections |
FileVersion | 䅐 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
15,110,980 bytes | 15,111,168 bytes | 6.63 (Compressed) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
FAC20B6D7BAF497013759898765599E2 |
.rdata |
0x00e6b000 |
6,046,240 bytes | 6,046,720 bytes | 6.43 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
24D61021AB807F8B828128E583F375A7 |
.data |
0x01430000 |
413,452 bytes | 269,312 bytes | 4.90 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
C0D29284BD4CD71E822F158BC5FFF689 |
.qtmetad |
0x01495000 |
239 bytes | 512 bytes | 3.38 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ
|
A08A0B80E7308C45C4F74D0CD9C559EF |
.tls |
0x01496000 |
13 bytes | 512 bytes | 0.02 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
8E3343EFA9AFC26AC6CAF49228CBE049 |
.gfids |
0x01497000 |
52 bytes | 512 bytes | 0.26 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
029D95E2B9A2EE9B2E8D7314C2124FCE |
_RDATA |
0x01498000 |
292 bytes | 512 bytes | 3.52 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
8C48BC5FDFE8016FF88837FDFDF83D8D |
.rsrc |
0x01499000 |
137,408 bytes | 137,728 bytes | 4.77 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
4A57D3B7F52D4F2982FACAE1A0A3441F |
.reloc |
0x014bb000 |
587,496 bytes | 587,776 bytes | 6.59 (Compressed) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
35378A9C485CDC43D62FB22584D6E95E |
2 section(s) with elevated entropy (≥6.5) - possible compression
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_ICON | 15 | 134,971 bytes | |
RT_GROUP_ICON | 2 | 222 bytes | |
RT_VERSION | 1 | 186 bytes | |
RT_MANIFEST | 1 | 1,145 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
No valid SignedData structure was found.
Recommendation: Verify the file source and ensure it comes from a trusted publisher.
Gridinsoft has the capability to identify and eliminate Virtool.Win32.CoinMiner.vl!i without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system