indexer.exe

The application indexer.exe has been detected as a potentially unwanted program by 27 anti-malware scanners. This is a malicious Bitcoin miner. Bitcoin-mining malware is designed to force computers to generate Bitcoins for cybercriminals' use and consumes computing power.
MD5:
47abca79304c18e4a5b28f06a2d91a96

SHA-1:
6348be0bbf24201618526e4b8ed3501a0556d29b

SHA-256:
56666cf6dbc681524f776e2069f0d97a14dda3d838bbf6e59e2b88793192b08e

Scanner detections:
27 / 68

Status:
Potentially unwanted

Explanation:
The program will mine for BitCoins using the computer's GPU in the background and may be installed and run without the user's knowledge.

Analysis date:
7/12/2025 4:00:39 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Graftor.162151
789

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
TR/Rogue.11672419.3
7.11.189.158

avast!
Win32:BitCoinMiner-FA [PUP]
2014.9-141208

Baidu Antivirus
Hacktool.Win32.BitCoinMiner
4.0.3.14128

Bitdefender
Gen:Variant.Graftor.162151
1.0.20.1710

Comodo Security
UnclassifiedMalware
20241

Dr.Web
Tool.BtcMine.480
9.0.1.0342

Emsisoft Anti-Malware
Gen:Variant.Graftor.162151
8.14.12.08.07

ESET NOD32
Win32/BitCoinMiner.CK (variant)
8.10803

Fortinet FortiGate
Riskware/BitCoinMiner
12/8/2014

F-Secure
Gen:Variant.Graftor.162151
11.2014-08-12_2

G Data
Gen:Variant.Graftor.162151
14.12.24

IKARUS anti.virus
Trojan.BitCoinMiner
t3scan.1.8.3.0

K7 AntiVirus
Trojan
13.186.14174

Kaspersky
not-a-virus:RiskTool.Win32.BitCoinMiner
14.0.0.2828

Malwarebytes
PUP.Optional.BitcoinMiner
v2014.12.08.07

McAfee
RDN/Generic PUP.x!cq3
5600.6923

MicroWorld eScan
Gen:Variant.Graftor.162151
15.0.0.1026

NANO AntiVirus
Riskware.Win32.BitCoinMiner.dfavcb
0.28.6.63726

Norman
BitCoinMiner.STR
11.20141208

Panda Antivirus
Trj/Genetic.gen
14.12.08.07

Qihoo 360 Security
Win32/Trojan.89d
1.0.0.1015

Sophos
Generic PUA GD
4.98

Trend Micro House Call
TROJ_GEN.R08NB01K314
7.2.342

VIPRE Antivirus
Trojan.Win32.Generic
35276

Zillya! Antivirus
Backdoor.PePatch.Win32.51965
2.0.0.1995

File size:
541 KB (553,984 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\indexer.exe

File PE Metadata
Compilation timestamp:
8/14/2014 8:05:38 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.23

CTPH (ssdeep):
12288:PokEV/gNoFsGQWxd5yaSkyJep+QdGceBRkL:PoJ/gNoFsGQm5yWtp+QgckW

Entry address:
0x1280

Entry point:
83, EC, 1C, C7, 04, 24, 01, 00, 00, 00, FF, 15, BC, 94, 48, 00, E8, 6B, FD, FF, FF, 8D, 74, 26, 00, 8D, BC, 27, 00, 00, 00, 00, 83, EC, 1C, C7, 04, 24, 02, 00, 00, 00, FF, 15, BC, 94, 48, 00, E8, 4B, FD, FF, FF, 8D, 74, 26, 00, 8D, BC, 27, 00, 00, 00, 00, A1, 0C, 95, 48, 00, FF, E0, 89, F6, 8D, BC, 27, 00, 00, 00, 00, A1, E8, 94, 48, 00, FF, E0, 90, 90, 90, 90, 90, 90, 90, 90, 90, 55, 89, E5, 83, EC, 18, C7, 04, 24, 00, E0, 46, 00, E8, BA, A6, 06, 00, 52, 85, C0, 74, 65, C7, 44, 24, 04, 13, E0, 46, 00, 89...
 
[+]

Entropy:
6.3739

Code size:
431.5 KB (441,856 bytes)

Remove indexer.exe - Powered by Reason Core Security