awh835c.tmp

Setup

LLC

The file awh835c.tmp by LLC has been detected as adware by 14 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is a malicious Bitcoin miner. Bitcoin-mining malware is designed to force computers to generate Bitcoins for cybercriminals' use and consumes computing power. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from setup-14b7.kxcdn.com.
Publisher:
Open Source  (signed by LLC )

Product:
Setup

Version:
1.2

MD5:
994edcc551fdffd6c014825f3bbc6b4d

SHA-1:
778d9e1c6016af28efde3829bb98c7994d06d9c5

SHA-256:
02a298d8e9dc710e3b930908b546a2ddd5b4c09977b3450cfcfe1a3ae4828c81

Scanner detections:
14 / 68

Status:
Adware

Explanation:
The program will mine for BitCoins using the computer's GPU in the background and may be installed and run without the user's knowledge.

Analysis date:
12/26/2024 10:47:16 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Unwanted/Win32.BitCoinMiner
2015.09.12

Avira AntiVirus
TR/BitCoinMiner.4628256
8.3.2.2

avast!
Win32:Amonetize-JS [PUP]
2014.9-150912

AVG
Generic
2016.0.2988

Baidu Antivirus
Hacktool.Win32.BitCoinMiner
4.0.3.15912

Dr.Web
Trojan.Amonetize.2893
9.0.1.0255

ESET NOD32
Win32/BitCoinMiner.BY potentially unsafe (variant)
9.12242

Fortinet FortiGate
Riskware/BitCoinMiner
9/12/2015

IKARUS anti.virus
Trojan.BitCoinMiner
t3scan.1.9.5.0

K7 AntiVirus
Unwanted-Program
13.210.17196

Quick Heal
RiskTool.BitCoinMin.09327
9.15.14.00

Reason Heuristics
PUP.Amonitize.OpenSource.Installer (M)
15.9.12.16

Sophos
Bitcoin Miner (PUA)
4.98

VIPRE Antivirus
Trojan.Win32.Generic
43690

File size:
4.2 MB (4,385,168 bytes)

Product version:
1.2

Copyright:
2015 - Open Source

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\awh835c.tmp

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
4/1/2015 8:00:00 AM

Valid to:
4/1/2016 7:59:59 AM

Subject:
CN="LLC ""DIIL-SOFT""", O="LLC ""DIIL-SOFT""", STREET="Bud. 1/1 kv. 53, vul.Artyleriiska", L=Odesa, S=Odesa, PostalCode=65000, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
156BBAD6D18CB9FA0E8C2027D2B39A9C

File PE Metadata
Compilation timestamp:
10/7/2014 12:40:10 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:tJKjtrWq0zZuU64WcE7Z65EY9BTnM4p4fMOrfOjiGFZkYFwP:tJK1W1zNFWT7ZFYvTMw4ftrmWGFZHFwP

Entry address:
0x30B6

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 90, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, 1C, 71, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 09, A3, 98, 37, 42, 00, E8, A8, 2D, 00, 00, A3, E4, 36, 42, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, 98, EC, 41, 00, FF, 15, 64, 71, 40, 00, 68, 80, 91, 40, 00, 68, E0, 2E, 42, 00, E8, 52, 2A, 00, 00, FF, 15, 20, 71, 40, 00, BD, 00, 90, 42, 00, 50, 55, E8, 40, 2A...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file awh835c.tmp has been seen being distributed by the following URL.

Remove awh835c.tmp - Powered by Reason Core Security