cpuminer-gw64.exe

TELE MAKS, TOV

The application cpuminer-gw64.exe by TELE MAKS, TOV has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘cpuminer’. While running, it connects to the Internet address livingston.shortysmalls.biz on port 3202.
Publisher:
TELE MAKS, TOV  (signed and verified)

MD5:
6b7e4a83636374fa4c29b0a16e61b482

SHA-1:
73e48abd8452addf40a20372ac871b002cfc4b18

SHA-256:
57f5c7e84eebf6baece48a3aa81147ad0d0509dbcfccad55bf669aa39044625c

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 2:56:40 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.BitcoinMiner.TELEMAKSTOV.Meta
15.6.7.2

File size:
1.3 MB (1,386,272 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\Windows\System32\cpuminer-gw64.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/27/2015 9:00:00 PM

Valid to:
5/27/2016 8:59:59 PM

Subject:
CN="TELE MAKS, TOV", O="TELE MAKS, TOV", STREET="Bud. 1 Litera Ch, vul.Magnitogorska", L=Kiev, S=Kiev, PostalCode=02094, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
009DE6D11840C4D7D02B3DB3EB46E21329

File PE Metadata
OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
2.24

CTPH (ssdeep):
24576:ND0/NuxNZFFsq9fcoGpzhMINFoq0n+7xuFGDXBT/3T3f7ZRR3xJbhuSsO13O:tUuRFR9koqzOINaqbx1DXBT/T73Rnluv

Entry address:
0x368610

Entry point:
53, 56, 57, 55, 48, 8D, 35, 0A, 3A, EB, FF, 48, 8D, BE, DB, 4F, DE, FF, 48, 8D, 87, CC, 6B, 35, 00, FF, 30, C7, 00, 41, B7, 84, 3F, 50, 57, 31, DB, 31, C9, 48, 83, CD, FF, E8, 50, 00, 00, 00, 01, DB, 74, 02, F3, C3, 8B, 1E, 48, 83, EE, FC, 11, DB, 8A, 16, F3, C3, 48, 8D, 04, 2F, 83, F9, 05, 8A, 10, 76, 21, 48, 83, FD, FC, 77, 1B, 83, E9, 04, 8B, 10, 48, 83, C0, 04, 83, E9, 04, 89, 17, 48, 8D, 7F, 04, 73, EF, 83, C1, 04, 8A, 10, 74, 10, 48, FF, C0, 88, 17, 83, E9, 01, 8A, 10, 48, 8D, 7F, 01, 75, F0, F3, C3...
 
[+]

Code size:
1.3 MB (1,363,968 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
cpuminer

Command:
C:\Windows\System32\cpuminer-gw64.exe


The executing file has been seen to make the following network communication in live environments.

TCP:
Connects to livingston.shortysmalls.biz  (66.117.6.3:3202)

Remove cpuminer-gw64.exe - Powered by Reason Core Security