awh7636.tmp

Setup

LLC

The file awh7636.tmp by LLC has been detected as adware by 14 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is a malicious Bitcoin miner. Bitcoin-mining malware is designed to force computers to generate Bitcoins for cybercriminals' use and consumes computing power. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from setup-14b7.kxcdn.com.
Publisher:
Open Source  (signed by LLC )

Product:
Setup

Version:
1.2

MD5:
77c1032164d235dc3b01589571c572d3

SHA-1:
4e1f0d084abaffc9d95a789e057ba04d05c23699

SHA-256:
86569232e270329bc4c59765c8ea4e2dea932595d7e1244c64f10ca32644a5db

Scanner detections:
14 / 68

Status:
Adware

Explanation:
The program will mine for BitCoins using the computer's GPU in the background and may be installed and run without the user's knowledge.

Analysis date:
12/26/2024 11:00:39 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/BitCoinMiner.4628256
8.3.2.2

avast!
Multi:BitCoinMiner-B [PUP]
2014.9-150924

AVG
CoinMiner
2016.0.2976

Dr.Web
Trojan.BtcMine.711
9.0.1.0267

ESET NOD32
Win32/BitCoinMiner.BY potentially unsafe (variant)
9.12296

Fortinet FortiGate
Riskware/BitCoinMiner
9/24/2015

IKARUS anti.virus
PUA.BitCoinMiner
t3scan.1.9.5.0

K7 AntiVirus
Unwanted-Program
13.210.17320

Kaspersky
not-a-virus:HEUR:RiskTool.Win32.BitCoinMiner
14.0.0.1377

Qihoo 360 Security
HEUR/QVM42.1.Malware.Gen
1.0.0.1015

Quick Heal
RiskTool.BitCoinMin.09327
9.15.14.00

Reason Heuristics
PUP.Amonitize.OpenSource.Installer (M)
15.9.24.14

Sophos
CpuMiner (PUA)
4.98

VIPRE Antivirus
Trojan.Win32.Generic
44014

File size:
4.2 MB (4,404,728 bytes)

Product version:
1.2

Copyright:
2015 - Open Source

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\awh7636.tmp

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/29/2015 3:00:00 AM

Valid to:
5/29/2016 2:59:59 AM

Subject:
CN="LLC ""Invest -Proekt""", O="LLC ""Invest -Proekt""", STREET="Geroev Stalingrada str., 156", L=Dnipropetrovsk, S=Dnipropetrovska obl., PostalCode=49000, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
587B444820E01109AE86078C4B64D02A

File PE Metadata
Compilation timestamp:
10/7/2014 7:40:10 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:L0UWJBZuG/G7x+HXBdpTnM4p4fKLGH8rHIkUETQ0t68Q:7EDF/AIHZTMw4fKL6QIk18IRQ

Entry address:
0x30B6

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 90, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, 1C, 71, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 09, A3, 98, 37, 42, 00, E8, A8, 2D, 00, 00, A3, E4, 36, 42, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, 98, EC, 41, 00, FF, 15, 64, 71, 40, 00, 68, 80, 91, 40, 00, 68, E0, 2E, 42, 00, E8, 52, 2A, 00, 00, FF, 15, 20, 71, 40, 00, BD, 00, 90, 42, 00, 50, 55, E8, 40, 2A...
 
[+]

Entropy:
7.9985

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file awh7636.tmp has been seen being distributed by the following URL.

Remove awh7636.tmp - Powered by Reason Core Security