| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2021-Oct-09 15:10:52 |
| Detected languages |
English - United States
|
| TLS Callbacks | 1 callback(s) detected. |
| CompanyName | www.xmrig.com |
| FileDescription | XMRig miner |
| FileVersion | 6.15.2 |
| LegalCopyright | Copyright (C) 2016-2021 xmrig.com |
| OriginalFilename | xmrig.exe |
| ProductName | XMRig |
| ProductVersion | 6.15.2 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to MD5
Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES Uses constants related to Blowfish Uses constants related to base58 Uses known Diffie-Helman primes Uses known Mersenne Twister constants Microsoft's Cryptography API |
| Malicious | This program may be a miner. |
Contains a valid Monero address:
|
| Suspicious | The PE is possibly packed. |
Unusual section name found: _RANDOMX
Unusual section name found: _SHA3_25 Unusual section name found: _TEXT_CN Unusual section name found: _TEXT_CN |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| MD5 | e2070b9a33cf0112e6a317a56c69b395 🔍 |
|---|---|
| SHA1 | b7139bf0d4e3f42024900281c5738d80002c574e 🔍 |
| SHA256 | 1e30694b3b5ca0c82df50946485f8525e361d9e674fde808e5d238ba0177c2f7 🔍 |
| SHA3 | 70a90e2fc9034297eb2da9c524f7b3bfc590eee263593de7e466ee1549a14a9c 🔍 |
| SSDeep | 98304:65AfKZ70gcjrWgcTKUAEiLityOebCX+eXi7V6ENSUZi:NMmUAEqitCeXDiRXSUZ 🔍 |
| Imports Hash | 14ec8f3f7eee2e31d6dc574514386b4d 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x130 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 11 |
| TimeDateStamp | 2021-Oct-09 15:10:52 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x365600 |
| SizeOfInitializedData | 0x41a600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000030F3F8 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x786000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 9bb52bff25e1919f33a767c0c0883867 🔍 |
|---|---|
| SHA1 | 6b7f0c43c2d5803dcf046808eaccc1e3a4724790 🔍 |
| SHA256 | 76a64e4280853dede2869ac504af5f3bbc2edef1dd219f711822defbf2c66868 🔍 |
| SHA3 | b569c0af946c2b4f89419327d7672e0f9a17fa73081792c48ec400882146ef47 🔍 |
| VirtualSize | 0x366000 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x366000 |
| PointerToRawData | 0x1000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.50243 |
| MD5 | b26355ecb8950dfead2e2d5c0d2213cd 🔍 |
|---|---|
| SHA1 | 34474a10d94b241dd01c7ce010872029db7656ba 🔍 |
| SHA256 | f56a94c3f6b17a705d3cd9af5095d97b4afe819f7e892ce234b77429ff557b17 🔍 |
| SHA3 | bdd0b337c1ccf6e34b0623421a54e5024a685abf0e22ed20f95d9d27739b0eb4 🔍 |
| VirtualSize | 0x139000 |
| VirtualAddress | 0x367000 |
| SizeOfRawData | 0x139000 |
| PointerToRawData | 0x367000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.08186 |
| MD5 | a9cdfdc99caad319fce20d240ef599f7 🔍 |
|---|---|
| SHA1 | ba4582e4a17b6623490b058da38233c1a6b856cb 🔍 |
| SHA256 | f5400e54a3a0336918c42e7922c22096d67e0380ba041085f5b4bf2b937c8082 🔍 |
| SHA3 | 927b9baa95194297ef40575dcd8da92c7821d0176b4ed5ebbfe099f743d8f943 🔍 |
| VirtualSize | 0x2b3000 |
| VirtualAddress | 0x4a0000 |
| SizeOfRawData | 0x2b3000 |
| PointerToRawData | 0x4a0000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0.292318 |
| MD5 | 0fc8c190559a0c4848c8f3f783383c31 🔍 |
|---|---|
| SHA1 | 60b0e7f0c391165d66702d1d20dcfd5f1cd795b0 🔍 |
| SHA256 | bea37e01824c39f300e0c00a41be7eddd783c2b3d6ab122cef879c538f125092 🔍 |
| SHA3 | fc1c360530fe8a341a277ccb95dcaeb1d45a037df9a93759197b67932504d17f 🔍 |
| VirtualSize | 0x22000 |
| VirtualAddress | 0x753000 |
| SizeOfRawData | 0x22000 |
| PointerToRawData | 0x753000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.28663 |
| MD5 | c0ed5d1c55d07f063664217acc215bed 🔍 |
|---|---|
| SHA1 | 114f929e760551d386d1cb3dcea960cdce9a7838 🔍 |
| SHA256 | 72f725db51b0d7b89a56b7e9b377b7406395b47343e27909ffa780d85122e48e 🔍 |
| SHA3 | 491f53acb849937806db9492b14ece7cc2fe280e51f12a167944bde4343917cf 🔍 |
| VirtualSize | 0x1000 |
| VirtualAddress | 0x775000 |
| SizeOfRawData | 0x1000 |
| PointerToRawData | 0x775000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.19156 |
| MD5 | 8fe36a438eb9a67a0ab635f5ffd25f93 🔍 |
|---|---|
| SHA1 | e8f78493bc13b4f3416026e19d4baa7b062c0be2 🔍 |
| SHA256 | aa302df8303300c86f703ef4a592891c73a0ac4108346f97a1361af4ad7cb644 🔍 |
| SHA3 | f8b91b26618cc43753178009efc645760fcf03aff301bd56d2845b29aab2e31f 🔍 |
| VirtualSize | 0x1000 |
| VirtualAddress | 0x776000 |
| SizeOfRawData | 0x1000 |
| PointerToRawData | 0x776000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 3.1823 |
| MD5 | 325b24832a46de54de997ee69f8069ca 🔍 |
|---|---|
| SHA1 | 57d366dddb3f4e70f663538fb73de54c6d0e856b 🔍 |
| SHA256 | 5b63eb17f8df602752ca96942b9c3ac53c8fadbccb2764facab07d0268c8709a 🔍 |
| SHA3 | edb32e00eee2d2655744613707898ccbf22f63c113fbe5c0d586d6f906e65fb1 🔍 |
| VirtualSize | 0x2000 |
| VirtualAddress | 0x777000 |
| SizeOfRawData | 0x2000 |
| PointerToRawData | 0x777000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.00756 |
| MD5 | 3d4180b905dda96cf2654a24c59d07fc 🔍 |
|---|---|
| SHA1 | 4a3d6e1aa67a2ab91a7bbaaf67c0019a95ec663b 🔍 |
| SHA256 | daa7cf4c69af34346af923bf5d2f8173cfb4d3036dc136666d48da34f3992702 🔍 |
| SHA3 | de730897aff07cc3a87854aeeebcaeb55ab5dbc287934affa1ae4f08a363c754 🔍 |
| VirtualSize | 0x2000 |
| VirtualAddress | 0x779000 |
| SizeOfRawData | 0x2000 |
| PointerToRawData | 0x779000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 4.15833 |
| MD5 | 0e86e55de6ab0161d1b816bb941234f9 🔍 |
|---|---|
| SHA1 | beb0d11ad5590a86047b4924135b2b91bf41ea0e 🔍 |
| SHA256 | fb5cdd6fe1fa3595f3c9c10c3499c6ebbc17bac4287c3680394c81cb789383a0 🔍 |
| SHA3 | 8c99f698b040252b48f002645f8784b3d4fa2d473d1a6a3823a18aef3aa2b16b 🔍 |
| VirtualSize | 0x1000 |
| VirtualAddress | 0x77b000 |
| SizeOfRawData | 0x1000 |
| PointerToRawData | 0x77b000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 0.256546 |
| MD5 | 0ffd86ad2773988870b1ff559ce78445 🔍 |
|---|---|
| SHA1 | 62ca92637f91799d71a5b0243e34a905f2112a7e 🔍 |
| SHA256 | 150336cbbe6002b34529caba446ce99d9fb338a0f6380300b47ca15b4b74b8c9 🔍 |
| SHA3 | 6d002708f16da3d7169ae67a504e3785382c73a22e87ef429864e62490cf00ab 🔍 |
| VirtualSize | 0x1000 |
| VirtualAddress | 0x77c000 |
| SizeOfRawData | 0x1000 |
| PointerToRawData | 0x77c000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 1.62028 |
| MD5 | 1e54d9c7f6f296b595646de8ab3014d8 🔍 |
|---|---|
| SHA1 | fb0d178e504e2a510b16423d0c5f8d3cdf982dc3 🔍 |
| SHA256 | b8ac4197ffd5740d539d06c428815fe3859ed5e5d7dffc5badd508773b75e95f 🔍 |
| SHA3 | dfea736533b05b176bcc2acf0c25f2b2da0533d4cc21e7c732b6eef869e160e5 🔍 |
| VirtualSize | 0x9000 |
| VirtualAddress | 0x77d000 |
| SizeOfRawData | 0x9000 |
| PointerToRawData | 0x77d000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.40446 |
| WS2_32.dll |
htonl
htons ntohs WSARecvFrom WSASend WSARecv WSAIoctl WSADuplicateSocketW FreeAddrInfoW GetAddrInfoW gethostname listen bind getsockname WSASetLastError WSACleanup __WSAFDIsSet closesocket select shutdown WSASocketW inet_pton getaddrinfo WSAStartup getpeername send socket connect recv getsockopt freeaddrinfo ioctlsocket getnameinfo setsockopt WSAGetLastError |
|---|---|
| PSAPI.DLL |
GetProcessMemoryInfo
|
| IPHLPAPI.DLL |
GetAdaptersAddresses
|
| USERENV.dll |
GetUserProfileDirectoryW
|
| CRYPT32.dll |
CertCloseStore
CertGetCertificateContextProperty CertFreeCertificateContext CertOpenSystemStoreW CertEnumCertificatesInStore CertFindCertificateInStore CertOpenStore CertDuplicateCertificateContext |
| KERNEL32.dll |
GetStdHandle
SetConsoleMode GetConsoleMode GetComputerNameW SizeofResource LockResource LoadResource FindResourceW ExpandEnvironmentStringsA TerminateProcess OpenProcess CreateToolhelp32Snapshot Process32NextW Process32FirstW CloseHandle SetThreadExecutionState GetSystemFirmwareTable HeapFree HeapAlloc GetProcessHeap MultiByteToWideChar SetPriorityClass GetCurrentProcess SetThreadPriority GetSystemPowerStatus GetCurrentThread GetProcAddress GetModuleHandleW GetTickCount FreeConsole GetConsoleWindow VirtualProtect VirtualFree VirtualAlloc GetLargePageMinimum LocalAlloc GetLastError LocalFree FlushInstructionCache GetCurrentThreadId AddVectoredExceptionHandler DeviceIoControl GetModuleFileNameW CreateFileW SetLastError GetSystemTime SystemTimeToFileTime GetModuleHandleExW EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionAndSpinCount DeleteCriticalSection TlsAlloc TlsGetValue TlsSetValue TlsFree SwitchToFiber DeleteFiber CreateFiber FindClose FindFirstFileW FindNextFileW WideCharToMultiByte GetFileType WriteFile FormatMessageW ConvertFiberToThread ConvertThreadToFiber QueryPerformanceCounter GetCurrentProcessId GetSystemTimeAsFileTime FreeLibrary LoadLibraryA LoadLibraryW GetEnvironmentVariableW ReadConsoleA ReadConsoleW PostQueuedCompletionStatus CreateFileA DuplicateHandle SetEvent ResetEvent WaitForSingleObject CreateEventA Sleep QueueUserWorkItem RegisterWaitForSingleObject UnregisterWait GetNumberOfConsoleInputEvents ReadConsoleInputW FillConsoleOutputCharacterW FillConsoleOutputAttribute GetConsoleCursorInfo SetConsoleCursorInfo GetConsoleScreenBufferInfo SetConsoleTitleA WriteConsoleW WriteConsoleInputW CreateDirectoryW FlushFileBuffers GetDiskFreeSpaceW GetFileAttributesW GetFileInformationByHandle GetFileSizeEx GetFinalPathNameByHandleW GetFullPathNameW ReadFile RemoveDirectoryW SetFilePointerEx SetFileTime GetSystemInfo MapViewOfFile FlushViewOfFile UnmapViewOfFile CreateFileMappingA ReOpenFile CopyFileW MoveFileExW CreateHardLinkW GetFileInformationByHandleEx CreateSymbolicLinkW InitializeCriticalSection SetConsoleCtrlHandler GetCurrentDirectoryW GetLongPathNameW GetShortPathNameW CreateIoCompletionPort ReadDirectoryChangesW RtlUnwind GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableW SetCurrentDirectoryW GetTempPathW QueryPerformanceFrequency GlobalMemoryStatusEx GetVersionExW VerifyVersionInfoA FileTimeToSystemTime SetHandleInformation CancelIo SetFileCompletionNotificationModes LoadLibraryExW FormatMessageA SetErrorMode GetQueuedCompletionStatus ConnectNamedPipe PeekNamedPipe CreateNamedPipeW CancelIoEx CancelSynchronousIo SwitchToThread GetExitCodeProcess UnregisterWaitEx LCMapStringW DebugBreak TryEnterCriticalSection InitializeConditionVariable WakeConditionVariable SleepConditionVariableCS ReleaseSemaphore ResumeThread GetNativeSystemInfo CreateSemaphoreA GetModuleHandleA GetStartupInfoW GetModuleFileNameA GetVersionExA GetProcessAffinityMask SetProcessAffinityMask SetThreadAffinityMask GetComputerNameA CreateTimerQueue IsDebuggerPresent InitializeSListHead IsProcessorFeaturePresent SetUnhandledExceptionFilter UnhandledExceptionFilter RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext GetStringTypeW GetLocaleInfoW CompareStringW CreateEventW GetCPInfo DecodePointer SignalObjectAndWait SetConsoleTextAttribute CreateThread GetThreadPriority GetLogicalProcessorInformation CreateTimerQueueTimer ChangeTimerQueueTimer DeleteTimerQueueTimer GetNumaHighestNodeNumber GetThreadTimes FreeLibraryAndExitThread InterlockedPopEntrySList InterlockedPushEntrySList InterlockedFlushSList QueryDepthSList RtlUnwindEx SetStdHandle GetCommandLineA GetCommandLineW ExitThread GetDriveTypeW SystemTimeToTzSpecificLocalTime ExitProcess GetFileAttributesExW SetFileAttributesW GetConsoleCP IsValidLocale GetUserDefaultLCID EnumSystemLocalesW HeapReAlloc GetTimeZoneInformation HeapSize SetEndOfFile FindFirstFileExW IsValidCodePage GetACP GetOEMCP SetConsoleCursorPosition VerSetConditionMask EncodePointer RaiseException WaitForSingleObjectEx GetExitCodeThread RtlPcToFileHeader |
| USER32.dll |
GetSystemMetrics
MapVirtualKeyW DispatchMessageA TranslateMessage GetMessageA MessageBoxW GetUserObjectInformationW GetProcessWindowStation ShowWindow GetLastInputInfo |
| SHELL32.dll |
SHGetSpecialFolderPathA
SHGetFolderPathW |
| ADVAPI32.dll |
SystemFunction036
CryptEnumProvidersW CryptSignHashW CryptDestroyHash CryptCreateHash CryptExportKey CryptGetUserKey CryptGetProvParam CryptSetHashParam CryptDestroyKey CryptReleaseContext ReportEventW RegisterEventSourceW DeregisterEventSource CreateServiceW QueryServiceStatus CloseServiceHandle OpenSCManagerW QueryServiceConfigA DeleteService ControlService StartServiceW OpenServiceW LookupPrivilegeValueW AdjustTokenPrivileges OpenProcessToken LsaOpenPolicy LsaAddAccountRights LsaClose GetTokenInformation CryptAcquireContextW CryptDecrypt CryptSetKeyParam CryptImportKey GetUserNameW |
| bcrypt.dll |
BCryptGenRandom
|
| Type |
RT_VERSION
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x28c |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.40283 |
| MD5 | 1589a3dc59e4b08adf5a0e04e4ad4241 🔍 |
| SHA1 | e764d0b7abbd05222ef1f8371f451420ec327466 🔍 |
| SHA256 | 7dfe7b2c7423e82cb98ec9f56b9f1d64bedb0144858ee13ad8367b595aeab2f2 🔍 |
| SHA3 | 048642f0c390db5392c3a22f0bb3e921fba303e31c70b2aea6cc9de07b8df2c6 🔍 |
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x17d |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.91161 |
| MD5 | 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍 |
| SHA1 | 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍 |
| SHA256 | 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍 |
| SHA3 | 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 6.15.2.0 |
| ProductVersion | 6.15.2.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| CompanyName | www.xmrig.com |
| FileDescription | XMRig miner |
| FileVersion (#2) | 6.15.2 |
| LegalCopyright | Copyright (C) 2016-2021 xmrig.com |
| OriginalFilename | xmrig.exe |
| ProductName | XMRig |
| ProductVersion (#2) | 6.15.2 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2021-Oct-09 15:10:52 |
| Version | 0.0 |
| SizeofData | 1196 |
| AddressOfRawData | 0x47065c |
| PointerToRawData | 0x46f05c |
| StartAddressOfRawData | 0x140470b28 |
|---|---|
| EndAddressOfRawData | 0x140470b49 |
| AddressOfIndex | 0x14073f464 |
| AddressOfCallbacks | 0x140367eb0 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks |
0x000000014030FD80
|
| Size | 0x130 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1404a5618 |
| XOR Key | 0x92d27dd6 |
|---|---|
| Unmarked objects | 0 |
| C objects (VS2017 v14.15 compiler 26715) | 27 |
| ASM objects (VS2017 v14.15 compiler 26715) | 13 |
| C++ objects (VS2017 v14.15 compiler 26715) | 201 |
| 199 (41118) | 4 |
| C objects (VS 2015/2017/2019 runtime 28427) | 19 |
| ASM objects (VS 2015/2017/2019 runtime 28427) | 9 |
| C++ objects (VS 2015/2017/2019 runtime 28427) | 150 |
| C objects (VS2019 Update 5 (16.5.4-5) compiler 28614) | 18 |
| Imports (VS2017 v14.15 compiler 26715) | 21 |
| Total imports | 362 |
| C objects (VS2019 Update 6 (16.6.0) compiler 28805) | 595 |
| C++ objects (LTCG) (VS2019 Update 5 (16.5.4-5) compiler 28614) | 258 |
| ASM objects (VS2019 Update 5 (16.5.4-5) compiler 28614) | 4 |
| Resource objects (VS2019 Update 5 (16.5.4-5) compiler 28614) | 1 |
| 151 | 1 |
| Linker (VS2019 Update 5 (16.5.4-5) compiler 28614) | 1 |
No comments yet.