lsass.exe

The executable lsass.exe has been detected as malware by 9 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from m.1h2ccnmjclickb6qdybkrszrgjfkar7gv22.com.
MD5:
04265c1a73baf053c70b8e87f9ee6abc

SHA-1:
26ac9e811090a7763d385807a22f96a9a9464ef5

SHA-256:
251f547f36d77ac59712b18b6e7727713250fb19b53984414513cfc916428167

Scanner detections:
9 / 68

Status:
Malware

Analysis date:
11/15/2024 7:12:07 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/CoinMiner.1659904
7.11.206.252

Baidu Antivirus
Trojan.Win64.CoinMiner
4.0.3.1525

Bkav FE
W64.HfsAutoA
1.3.0.6379

Comodo Security
UnclassifiedMalware
20959

Dr.Web
Trojan.BtcMine.630
9.0.1.036

ESET NOD32
Win64/CoinMiner (variant)
9.11122

IKARUS anti.virus
Trojan.Win64.CoinMiner
t3scan.1.8.6.0

McAfee
Artemis!04265C1A73BA
5600.6864

Panda Antivirus
Trj/Chgt.O
15.02.05.12

File size:
1.6 MB (1,659,904 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\temp\lsass.exe

File PE Metadata
Compilation timestamp:
10/10/2014 4:08:00 PM

OS version:
6.0

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
11.0

CTPH (ssdeep):
49152:ycEW6v2z+7ReMTfBcwtjXu+9cUvjZ1s7x:RExv2z+7ReMTyyXueciLs

Entry address:
0x3C5E64

Entry point:
E9, 6C, C4, 00, 00, 2E, 00, 21, 04, 86, 71, 98, 26, 56, C7, 8F, 8D, 74, 12, 44, CB, F0, 67, 22, CF, D4, 8C, 21, B9, 33, CF, F5, ED, 02, EA, 1F, E7, 5C, F0, E1, 44, 92, 76, 67, 8E, 77, CF, 35, E4, 74, FA, C8, 28, AC, CF, 28, B9, 9A, 95, 25, 50, 6F, AF, 3F, 8A, 82, 3B, 25, 9E, 24, 3A, 96, 36, 7B, 87, D6, 2A, F3, E4, BF, 51, 1C, 47, E3, 35, 71, 42, 9E, A8, 7D, 32, C2, 4C, 39, BE, 46, 67, 7B, AC, F4, 06, DC, 37, E9, E3, B8, 0B, AE, 27, 34, 53, EC, 14, EA, 2D, 8D, FE, 92, 58, F2, F3, 29, 6C, 35, E3, CB, CD, 3B...
 
[+]

Entropy:
7.9308

Packer / compiler:
Xtreme-Protector v1.05

Code size:
683 KB (699,392 bytes)

The file lsass.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP:
Connects to ec2-54-78-196-115.eu-west-1.compute.amazonaws.com  (54.78.196.115:3333)

TCP:
Connects to ec2-54-75-230-15.eu-west-1.compute.amazonaws.com  (54.75.230.15:3333)

Remove lsass.exe - Powered by Reason Core Security