cpuminer-gw64.exe

Promgazstroi Proekt, TOV

The application cpuminer-gw64.exe by Promgazstroi Proekt, TOV has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘cpuminer’. While running, it connects to the Internet address livingston.shortysmalls.biz on port 3200.
Publisher:
Promgazstroi Proekt, TOV  (signed and verified)

MD5:
50e7271bca167d94a4bb76db523a2302

SHA-1:
9b1912fbbc0efa046bdc0ac3b7037496073eac8a

SHA-256:
7c9f170303db1980b491ed9c06e3d2e9094874aadb713dcdd42114397dfad089

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 12:37:33 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.BitcoinMiner.PromgazstroiProektTOV.Meta (M)
15.6.26.11

File size:
4 MB (4,240,616 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\Windows\System32\cpuminer-gw64.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/28/2015 5:00:00 PM

Valid to:
5/28/2016 4:59:59 PM

Subject:
CN="Promgazstroi Proekt, TOV", O="Promgazstroi Proekt, TOV", STREET="Bud. 33 kv. 53, vul.Bela Kuna", L=Simferopol, S=Avtonomna Respublika Krym, PostalCode=95000, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00FC0D6AD78022749D360DBAA6D8E84B1E

File PE Metadata
Compilation timestamp:
11/20/1971 2:38:48 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
2.24

CTPH (ssdeep):
49152:q82YZYHynJ5Lb22jYGxDtpNshiPH2C/zvrEfc8rYvTDhfEHihsU0iHSckSlwPF2M:q+YoJN22xxuKPrqZcJ0iHSckSlwPF2M

Entry address:
0x14D0

Entry point:
48, 83, EC, 28, C7, 05, 42, A6, 37, 00, 00, 00, 00, 00, E8, FD, 85, 28, 00, E8, 98, FC, FF, FF, 90, 90, 48, 83, C4, 28, C3, 90, 48, 83, EC, 38, 4C, 89, 4C, 24, 58, 4C, 8D, 4C, 24, 58, 4C, 89, 4C, 24, 28, E8, A8, 91, 28, 00, 48, 83, C4, 38, C3, 0F, 1F, 00, 53, 48, 83, EC, 20, 85, C9, 89, CB, 74, 1D, FF, 15, DF, D5, 37, 00, 48, 8D, 15, D8, 1A, 2A, 00, 48, 8D, 48, 60, E8, FF, 65, 10, 00, 89, D9, E8, 08, EC, 28, 00, 48, 8D, 0D, C1, 37, 2A, 00, E8, 1C, 66, 10, 00, EB, EB, 66, 2E, 0F, 1F, 84, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.4928

Code size:
2.6 MB (2,688,000 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
cpuminer

Command:
C:\Windows\System32\cpuminer-gw64.exe


The executing file has been seen to make the following network communication in live environments.

TCP:
Connects to livingston.shortysmalls.biz  (66.117.6.3:3200)

Remove cpuminer-gw64.exe - Powered by Reason Core Security