cpuminer-gw64.exe

Promgazstroi Proekt, TOV

The application cpuminer-gw64.exe by Promgazstroi Proekt, TOV has been detected as a potentially unwanted program by 2 anti-malware scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘cpuminer’. While running, it connects to the Internet address livingston.shortysmalls.biz on port 3200.
Publisher:
Promgazstroi Proekt, TOV  (signed and verified)

MD5:
716c276f6720792f6bfb56d6ee14bf44

SHA-1:
51c55b169d1db23f44cc1168850d0ae4dd027dc9

SHA-256:
25e192dc2c22e9bfb45e6a1545570aa151b936151c888d73dd6552ed5e17804d

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 1:10:56 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.BtcMine.711
9.0.1.0181

Reason Heuristics
PUP.BitcoinMiner.PromgazstroiProektTOV.Meta (M)
15.6.30.13

File size:
1.3 MB (1,413,448 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\Windows\System32\cpuminer-gw64.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/29/2015 2:00:00 AM

Valid to:
5/29/2016 1:59:59 AM

Subject:
CN="Promgazstroi Proekt, TOV", O="Promgazstroi Proekt, TOV", STREET="Bud. 33 kv. 53, vul.Bela Kuna", L=Simferopol, S=Avtonomna Respublika Krym, PostalCode=95000, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00FC0D6AD78022749D360DBAA6D8E84B1E

File PE Metadata
OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
2.24

CTPH (ssdeep):
24576:EsFaK8WRXanbg1k1DVB8Kdq6wG5rGi6oTmN40z+X5jOwuFoEu1h1trfxCg:Es8WR2bqaVaKEErG/Tj+VuFo1h1dR

Entry address:
0x38C090

Entry point:
53, 56, 57, 55, 48, 8D, 35, 8A, CF, EA, FF, 48, 8D, BE, DB, 7F, DC, FF, 48, 8D, 87, 0C, AB, 37, 00, FF, 30, C7, 00, FE, 79, 4D, 63, 50, 57, 31, DB, 31, C9, 48, 83, CD, FF, E8, 50, 00, 00, 00, 01, DB, 74, 02, F3, C3, 8B, 1E, 48, 83, EE, FC, 11, DB, 8A, 16, F3, C3, 48, 8D, 04, 2F, 83, F9, 05, 8A, 10, 76, 21, 48, 83, FD, FC, 77, 1B, 83, E9, 04, 8B, 10, 48, 83, C0, 04, 83, E9, 04, 89, 17, 48, 8D, 7F, 04, 73, EF, 83, C1, 04, 8A, 10, 74, 10, 48, FF, C0, 88, 17, 83, E9, 01, 8A, 10, 48, 8D, 7F, 01, 75, F0, F3, C3...
 
[+]

Code size:
1.3 MB (1,392,640 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
cpuminer

Command:
C:\Windows\System32\cpuminer-gw64.exe


The executing file has been seen to make the following network communication in live environments.

TCP:
Connects to livingston.shortysmalls.biz  (66.117.6.3:3200)

Remove cpuminer-gw64.exe - Powered by Reason Core Security