cpuminer-gw64.exe

LLC

The application cpuminer-gw64.exe by LLC has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘cpuminer’. While running, it connects to the Internet address livingston.shortysmalls.biz on port 3201.
Publisher:
LLC   (signed and verified)

MD5:
4e668dd3f32ea831ea3dd244514dd51d

SHA-1:
5e9ca0c9d655ea3ca33ad531ff90935e1bb2c02c

SHA-256:
307018033fa4a2cdbe1daed1f23c49f683e413fcd7d505387b045952b8476f95

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
9/21/2024 4:34:17 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonitize (M)
15.7.11.10

File size:
1.4 MB (1,418,544 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\Windows\System32\cpuminer-gw64.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/29/2015 3:00:00 AM

Valid to:
6/29/2016 2:59:59 AM

Subject:
CN="LLC ""SOFT-STANDART""", O="LLC ""SOFT-STANDART""", STREET=Bud. 5 vul.Artema, L=Dnipropetrovsk, S=Dnipropetrovska, PostalCode=49000, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00A554F191FD67BB6012F1ABCA785158D0

File PE Metadata
OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
2.24

CTPH (ssdeep):
24576:rK6JFK0DGMBav6+qK62b9Z4+vTJjzc1os7k6T50jTqBXJi/Xte9T:rK6JFP+K24g5w77rTGjTqBXJYXteJ

Entry address:
0x38F3B0

Entry point:
53, 56, 57, 55, 48, 8D, 35, 6A, BC, EA, FF, 48, 8D, BE, DB, 5F, DC, FF, 48, 8D, 87, 0C, DB, 37, 00, FF, 30, C7, 00, 04, FC, FF, FF, 50, 57, 31, DB, 31, C9, 48, 83, CD, FF, E8, 50, 00, 00, 00, 01, DB, 74, 02, F3, C3, 8B, 1E, 48, 83, EE, FC, 11, DB, 8A, 16, F3, C3, 48, 8D, 04, 2F, 83, F9, 05, 8A, 10, 76, 21, 48, 83, FD, FC, 77, 1B, 83, E9, 04, 8B, 10, 48, 83, C0, 04, 83, E9, 04, 89, 17, 48, 8D, 7F, 04, 73, EF, 83, C1, 04, 8A, 10, 74, 10, 48, FF, C0, 88, 17, 83, E9, 01, 8A, 10, 48, 8D, 7F, 01, 75, F0, F3, C3...
 
[+]

Entropy:
7.9404  (probably packed)

Code size:
1.3 MB (1,396,736 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
cpuminer

Command:
C:\Windows\System32\cpuminer-gw64.exe


The executing file has been seen to make the following network communications in live environments.

TCP:
Connects to livingston.shortysmalls.biz  (66.117.6.3:3201)

TCP:
Connects to 198-178-124-50.static.hvvc.us  (198.178.124.50:3201)

Remove cpuminer-gw64.exe - Powered by Reason Core Security