Program did not start
MALICIOUS | SUSPICIOUS | INFO |
---|---|---|
MINER was detected
|
No suspicious indicators. |
No info indicators. |
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x0011C418 | 0x0011C600 | IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ | 6.44211 |
.rdata | 0x0011E000 | 0x0001D5E0 | 0x0001D600 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ | 5.83179 |
.data | 0x0013C000 | 0x00009D84 | 0x00008600 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE | 5.19732 |
.rsrc | 0x00146000 | 0x00000580 | 0x00000600 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ | 3.92145 |
.reloc | 0x00147000 | 0x000095F0 | 0x00009600 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_DISCARDABLE,IMAGE_SCN_MEM_READ | 6.73006 |
No exports.
Click at the process to see the details.
Image |
---|
c:\users\admin\appdata\local\temp\dllhostex.exe.malware.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\ws2_32.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\nsi.dll |
c:\windows\system32\iphlpapi.dll |
c:\windows\system32\winnsi.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\powrprof.dll |
c:\windows\system32\setupapi.dll |
c:\windows\system32\cfgmgr32.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\devobj.dll |
c:\windows\system32\mswsock.dll |
c:\windows\system32\wshtcpip.dll |
c:\windows\system32\wship6.dll |
c:\windows\system32\wshqos.dll |
c:\windows\system32\nlaapi.dll |
c:\windows\system32\napinsp.dll |
c:\windows\system32\pnrpnsp.dll |
c:\windows\system32\dnsapi.dll |
c:\windows\system32\winrnr.dll |
c:\windows\system32\dhcpcsvc6.dll |
c:\windows\system32\dhcpcsvc.dll |
c:\windows\system32\rasadhlp.dll |
c:\windows\system32\fwpuclnt.dll |
PID | Process | IP | ASN | CN | Reputation |
---|---|---|---|---|---|
3736 | dllhostex.exe.malware.exe | 165.22.143.11:443 | US | suspicious |
Domain | IP | Reputation |
---|---|---|
cake.pilutce.com | 134.209.188.169
157.230.120.236 178.128.74.151 138.197.106.239 165.22.23.102 165.22.143.11 134.209.173.244 134.209.181.186 |
malicious |
PID | Process | Class | Message |
---|---|---|---|
3736 | dllhostex.exe.malware.exe | Potential Corporate Privacy Violation | ET POLICY Cryptocurrency Miner Checkin |
3736 | dllhostex.exe.malware.exe | Misc activity | MINER [PTsecurity] Riskware/CoinMiner JSON_RPC Response |
3736 | dllhostex.exe.malware.exe | Misc activity | MINER [PTsecurity] Risktool.W32.coinminer!c |
3736 | dllhostex.exe.malware.exe | Misc activity | MINER [PTsecurity] CoinMiner CryptoNight algo JSON_RPC server Response |
Process | Message |
---|---|
dllhostex.exe.malware.exe | m -o cake.pilutce.com:443 -u cake2 -p x -t 2 --donate-level=1 --nicehash |