cpuminer-gw64.exe

SEIL SOFT, TOV

The application cpuminer-gw64.exe by SEIL SOFT, TOV has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘cpuminer’. While running, it connects to the Internet address livingston.shortysmalls.biz on port 3200.
Publisher:
SEIL SOFT, TOV  (signed and verified)

MD5:
7f7eff623c5dc75c4d9e59bf1dfd9a85

SHA-1:
634541ed72af7d658ca6047a421f96327037546a

SHA-256:
fd4a2eba722541df31beabf05699e7ff279e7c3034108500ae7f3f943238a736

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 2:38:55 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.BitcoinMiner.SEILSOFTTOV
15.5.22.10

File size:
1.3 MB (1,353,504 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\Windows\System32\cpuminer-gw64.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/7/2015 7:00:00 AM

Valid to:
5/7/2016 6:59:59 AM

Subject:
CN="SEIL SOFT, TOV", O="SEIL SOFT, TOV", STREET="Bud. 11 kv. 106, vul.Malynovskogo", L=Kiev, S=Kiev, PostalCode=04212, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0095763363F9FC73188565050F489D9878

File PE Metadata
OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
2.24

CTPH (ssdeep):
24576:HKcl6fH1+/+0sIfOsE9eRQBA0cJD+BznF+kNa37f2XO4auVSC5ixwXlf2iY:HKcl6fV4N2sEAR7XFnhrfeO4DUC5iSXI

Entry address:
0x3685E0

Entry point:
53, 56, 57, 55, 48, 8D, 35, 3A, BA, EB, FF, 48, 8D, BE, DB, CF, DD, FF, 48, 8D, 87, CC, 6B, 35, 00, FF, 30, C7, 00, 26, 7C, 94, 0F, 50, 57, 31, DB, 31, C9, 48, 83, CD, FF, E8, 50, 00, 00, 00, 01, DB, 74, 02, F3, C3, 8B, 1E, 48, 83, EE, FC, 11, DB, 8A, 16, F3, C3, 48, 8D, 04, 2F, 83, F9, 05, 8A, 10, 76, 21, 48, 83, FD, FC, 77, 1B, 83, E9, 04, 8B, 10, 48, 83, C0, 04, 83, E9, 04, 89, 17, 48, 8D, 7F, 04, 73, EF, 83, C1, 04, 8A, 10, 74, 10, 48, FF, C0, 88, 17, 83, E9, 01, 8A, 10, 48, 8D, 7F, 01, 75, F0, F3, C3...
 
[+]

Entropy:
7.9399  (probably packed)

Code size:
1.3 MB (1,331,200 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
cpuminer

Command:
C:\Windows\System32\cpuminer-gw64.exe


The executing file has been seen to make the following network communication in live environments.

TCP:
Connects to livingston.shortysmalls.biz  (66.117.6.3:3200)

Remove cpuminer-gw64.exe - Powered by Reason Core Security