cpuminer-gw64.exe

LLC `ELEKRAN SOFT`

The application cpuminer-gw64.exe by LLC `ELEKRAN SOFT` has been detected as a potentially unwanted program by 2 anti-malware scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘cpuminer’. While running, it connects to the Internet address livingston.shortysmalls.biz on port 3202.
Publisher:
LLC `ELEKRAN SOFT`  (signed and verified)

MD5:
2315691cd58f1d8f41048e098d4a7ef0

SHA-1:
34c074377327020e0c7836a64cb2d39c54655882

SHA-256:
4406a778911ecf9222b8b32326c85781ee9637f851cb4c4625b856bc0b00d242

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 2:23:55 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2016.0.3070

Reason Heuristics
PUP.BitcoinMiner.ELEKRANSOFT.Meta (M)
15.6.22.11

File size:
1.3 MB (1,413,400 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\Windows\System32\cpuminer-gw64.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/28/2015 5:00:00 PM

Valid to:
5/28/2016 4:59:59 PM

Subject:
CN=LLC `ELEKRAN SOFT`, O=LLC `ELEKRAN SOFT`, STREET=Malynovskoho 16A, L=Odesa, S=Odeska obl, PostalCode=65017, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
56BCC6EA7CBC1BF2C29E3B10B388CF8E

File PE Metadata
OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
2.24

CTPH (ssdeep):
24576:BsFaK8WRXanbg1k1DVB8Kdq6wG5rGi6oTmN40z+X5jOwuFoEu1rbUCDKFpCi22Th:Bs8WR2bqaVaKEErG/Tj+VuFo1rbUCDKR

Entry address:
0x38C090

Entry point:
53, 56, 57, 55, 48, 8D, 35, 8A, CF, EA, FF, 48, 8D, BE, DB, 7F, DC, FF, 48, 8D, 87, 0C, AB, 37, 00, FF, 30, C7, 00, C5, 6A, FE, 79, 50, 57, 31, DB, 31, C9, 48, 83, CD, FF, E8, 50, 00, 00, 00, 01, DB, 74, 02, F3, C3, 8B, 1E, 48, 83, EE, FC, 11, DB, 8A, 16, F3, C3, 48, 8D, 04, 2F, 83, F9, 05, 8A, 10, 76, 21, 48, 83, FD, FC, 77, 1B, 83, E9, 04, 8B, 10, 48, 83, C0, 04, 83, E9, 04, 89, 17, 48, 8D, 7F, 04, 73, EF, 83, C1, 04, 8A, 10, 74, 10, 48, FF, C0, 88, 17, 83, E9, 01, 8A, 10, 48, 8D, 7F, 01, 75, F0, F3, C3...
 
[+]

Entropy:
7.9411  (probably packed)

Code size:
1.3 MB (1,392,640 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
cpuminer

Command:
C:\Windows\System32\cpuminer-gw64.exe


The executing file has been seen to make the following network communication in live environments.

TCP:
Connects to livingston.shortysmalls.biz  (66.117.6.3:3202)

Remove cpuminer-gw64.exe - Powered by Reason Core Security