cdn.exe

CPU Miner - Setup

LLC

The application cdn.exe by LLC has been detected as adware by 16 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is a malicious Bitcoin miner. Bitcoin-mining malware is designed to force computers to generate Bitcoins for cybercriminals' use and consumes computing power. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from cdn-14b7.kxcdn.com.
Publisher:
Open Source  (signed by LLC )

Product:
CPU Miner - Setup

Version:
1.1

MD5:
310a7716672dab67e09d27210f57d743

SHA-1:
5df976fec78f487f2f022254679740545cc584bd

SHA-256:
e306db01e05e4eb1fefc5664a8e86e71d772d84564464afd13609f4fd12d0692

Scanner detections:
16 / 68

Status:
Adware

Explanation:
The program will mine for BitCoins using the computer's GPU in the background and may be installed and run without the user's knowledge.

Analysis date:
12/27/2024 5:28:47 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Strictor.87902
546

Avira AntiVirus
TR/BitCoinMiner.4634392.1
8.3.1.6

Arcabit
Trojan.Strictor.D1575E
1.0.0.425

AVG
CoinMiner
2016.0.3024

Baidu Antivirus
Hacktool.Win32.BitCoinMiner
4.0.3.1587

Bitdefender
Gen:Variant.Strictor.87902
1.0.20.1095

Dr.Web
Trojan.BtcMine.711
9.0.1.0219

Emsisoft Anti-Malware
Gen:Variant.Strictor.87902
8.15.08.07.01

ESET NOD32
Win64/BitCoinMiner.AT potentially unsafe (variant)
9.12056

F-Secure
Gen:Variant.Strictor.87902
11.2015-07-08_6

G Data
Gen:Variant.Strictor.87902
15.8.25

IKARUS anti.virus
not-a-virus:RiskTool.BitCoinMiner
t3scan.1.9.5.0

MicroWorld eScan
Gen:Variant.Strictor.87902
16.0.0.657

NANO AntiVirus
Riskware.Nsis.BitCoinMiner.dqgttf
0.30.24.2996

Reason Heuristics
PUP.Amonitize.OpenSource.Installer (M)
15.8.7.13

VIPRE Antivirus
Trojan.Win32.Generic
42682

File size:
4.4 MB (4,611,040 bytes)

Product version:
1.1

Copyright:
2015 - Open Source

Original file name:
cpuminer.exe

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\cdn.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/28/2015 8:00:00 AM

Valid to:
6/28/2016 7:59:59 AM

Subject:
CN="LLC ""SOFT ERA""", O="LLC ""SOFT ERA""", STREET="str. Parkhomenka, 11", L=Brovary, S=Kievska, PostalCode=07400, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
68E455B0112EE583E54746EAF224F225

File PE Metadata
Compilation timestamp:
10/7/2014 12:40:23 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:du+WeYzUVufWFsWPxoQ6g4hFv2TeoVOokMfXEsEheQQtEhjbOIHX0s4:du+W3a4WFsWPWQ6vDv6eTqPEheQkEhj6

Entry address:
0x30E2

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 90, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, 1C, 71, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 09, A3, 78, E4, 42, 00, E8, A8, 2D, 00, 00, A3, C4, E3, 42, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, 00, 88, 42, 00, FF, 15, 64, 71, 40, 00, 68, 80, 91, 40, 00, 68, C0, DB, 42, 00, E8, 52, 2A, 00, 00, FF, 15, 20, 71, 40, 00, BD, 00, 40, 43, 00, 50, 55, E8, 40, 2A...
 
[+]

Entropy:
7.9970

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file cdn.exe has been seen being distributed by the following URL.

Remove cdn.exe - Powered by Reason Core Security