cpuminer-gw64.exe

LLC

The application cpuminer-gw64.exe by LLC has been detected as adware by 2 anti-malware scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘cpuminer’. While running, it connects to the Internet address livingston.shortysmalls.biz on port 3202.
Publisher:
LLC   (signed and verified)

MD5:
c1f5ddbff69708accc292a49bc071093

SHA-1:
c45f6e757514c08593cd5f2a3ee73b22f91575b0

SHA-256:
a4ca8356d597b2079938a718930f637ab7739dd6d24d25235f6b6fa1e05af284

Scanner detections:
2 / 68

Status:
Adware

Analysis date:
12/27/2024 6:43:42 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.BtcMine.711
9.0.1.0172

Reason Heuristics
PUP.Amonitize (M)
15.6.21.22

File size:
1.7 MB (1,766,216 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\Windows\System32\cpuminer-gw64.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/28/2015 7:00:00 AM

Valid to:
5/28/2016 6:59:59 AM

Subject:
CN="LLC ""ALGOL-SOFT Nikolaev""", O="LLC ""ALGOL-SOFT Nikolaev""", STREET="Komsomolskaya Street, Building 103-A", L=Mykolayiv, S=Mykolayivska obl., PostalCode=54000, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
737C76E85D361C6445D01F94882D618F

File PE Metadata
OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
2.24

CTPH (ssdeep):
49152:2jlrrTXnO5+//DOHz44zySRMbVVMCZQy17dv:2jpnO5+QWCgQY

Entry address:
0x38C120

Entry point:
53, 56, 57, 55, 48, 8D, 35, FA, 6E, E5, FF, 48, 8D, BE, DB, DF, E1, FF, 48, 8D, 87, 0C, AB, 37, 00, FF, 30, C7, 00, F6, E3, 09, F1, 50, 57, 31, DB, 31, C9, 48, 83, CD, FF, E8, 50, 00, 00, 00, 01, DB, 74, 02, F3, C3, 8B, 1E, 48, 83, EE, FC, 11, DB, 8A, 16, F3, C3, 48, 8D, 04, 2F, 83, F9, 05, 8A, 10, 76, 21, 48, 83, FD, FC, 77, 1B, 83, E9, 04, 8B, 10, 48, 83, C0, 04, 83, E9, 04, 89, 17, 48, 8D, 7F, 04, 73, EF, 83, C1, 04, 8A, 10, 74, 10, 48, FF, C0, 88, 17, 83, E9, 01, 8A, 10, 48, 8D, 7F, 01, 75, F0, F3, C3...
 
[+]

Code size:
1.7 MB (1,744,896 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
cpuminer

Command:
C:\Windows\System32\cpuminer-gw64.exe


The executing file has been seen to make the following network communication in live environments.

TCP:
Connects to livingston.shortysmalls.biz  (66.117.6.3:3202)

Remove cpuminer-gw64.exe - Powered by Reason Core Security