Trojan

Trojan.Xmrminer.S24673691 (file analysis)

Malware Removal

The Trojan.Xmrminer.S24673691 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Xmrminer.S24673691 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Authenticode signature is invalid
  • CAPE detected the CoinMiner02 malware family

How to determine Trojan.Xmrminer.S24673691?


File Info:

name: FC724EB2894F34A3ACA4.mlw
path: /opt/CAPEv2/storage/binaries/7f986cd3c946f274cdec73f80b84855a77bc2a3c765d68897fbc42835629a5d5
crc32: EA34E6C4
md5: fc724eb2894f34a3aca4b952d2f816cd
sha1: 4b4453756ca29a3e3e0f39c3dda5d3ec8146f13e
sha256: 7f986cd3c946f274cdec73f80b84855a77bc2a3c765d68897fbc42835629a5d5
sha512: e5d37100b61e9266e666e3feba3e5d965e4394c62b97d2ceac1b6e5a8d818c2fda9c3a012c45f88ac85b99d22ad641a0428bbdf68285921230ef895182a34c50
ssdeep: 98304:1mhFMiUd/TPr9H3GYEIrcMGmMEsYlqxgrBN2T8knLys2UDeXa/Pl/+mnWN2SWxwG:1mLGwLLy5EEW+V4sf03PDx
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T18B765B1BF29350ECC67AC170865BA673F631F86942347D7B2764DB742E22E90522EF24
sha3_384: 0242150c03bf5c64e694591f368c615f0758266ef55d38b119a4bd511fff06eff6eebb0070e7f536f34f414f2219a44a
ep_bytes: 4883ec28488b05e5716800c700000000
timestamp: 2021-10-05 16:42:56

Version Info:

CompanyName: www.xmrig.com
FileDescription: XMRig miner
FileVersion: 6.15.2
LegalCopyright: Copyright (C) 2016-2021 xmrig.com
OriginalFilename: xmrig.exe
ProductName: XMRig
ProductVersion: 6.15.2
Translation: 0x0000 0x04b0

Trojan.Xmrminer.S24673691 also known as:

LionicTrojan.Win32.Miner.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.Miner.2
FireEyeGeneric.mg.fc724eb2894f34a3
CAT-QuickHealTrojan.Xmrminer.S24673691
ALYacTrojan.Agent.Miner
CylanceUnsafe
ZillyaTrojan.Miner.Win32.14774
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Miner.2ef68013
K7GWAdware ( 0055631f1 )
K7AntiVirusAdware ( 0055631f1 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/CoinMiner.PO potentially unwanted
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Coinminer.Generic-7151250-0
KasperskyTrojan.Win32.Miner.ayomj
BitDefenderGen:Variant.Application.Miner.2
AvastWin64:CoinminerX-gen [Trj]
TencentRisktool.Win64.Bitminer.16000063
Ad-AwareGen:Variant.Application.Miner.2
EmsisoftGen:Variant.Application.Miner.2 (B)
DrWebTool.BtcMine.2585
TrendMicroPUA.Win64.XMRig.KBO
SophosXMRig Miner (PUA)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Miner.qpz
WebrootW32.Coinminer.Xmrig
AviraHEUR/AGEN.1202894
Antiy-AVLTrojan/Generic.ASMalwS.34B76F9
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRisk.Win64.CoinMiner.vl!n
ViRobotAdware.Miner.7403008
GDataWin32.Application.CoinMiner.Y
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Miner.R374094
Acronissuspicious
MAXmalware (ai score=100)
VBA32Trojan.Miner
MalwarebytesRiskWare.BitCoinMiner
TrendMicro-HouseCallPUA.Win64.XMRig.KBO
RisingHackTool.XMRMiner!1.C2EC (CLOUD)
YandexTrojan.Miner!o5S2xBCt37E
IkarusPUA.CoinMiner
MaxSecureTrojan.Malware.121218.susgen
FortinetRiskware/CoinMiner.PO
AVGWin64:CoinminerX-gen [Trj]
Cybereasonmalicious.2894f3
PandaTrj/CI.A

How to remove Trojan.Xmrminer.S24673691?

Trojan.Xmrminer.S24673691 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment