cpuminer-gw64.exe

The Group

The application cpuminer-gw64.exe by The Group has been detected as a potentially unwanted program by 2 anti-malware scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘cpuminer’. While running, it connects to the Internet address livingston.shortysmalls.biz on port 3200.
Publisher:
The Group  (signed and verified)

MD5:
0a1fb0581f0b9cfb1623ad4f11db70a6

SHA-1:
f5756c622a076e2736968d5b89910e4d3e1b9367

SHA-256:
b36230fa5252a27fcf36b1dea3b8b136f4d51b9d1dd6f5313be290313375b9d3

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
12/27/2024 6:12:19 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.BtcMine.711
9.0.1.0181

Reason Heuristics
PUP.BitcoinMiner.TheGroup.Meta (M)
15.6.30.12

File size:
1.3 MB (1,413,912 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\Windows\System32\cpuminer-gw64.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/31/2015 3:00:00 AM

Valid to:
5/31/2016 2:59:59 AM

Subject:
CN=The Group, O=The Group, STREET="vul. Gagarina, 5", L=Khmelnytskyy, S=Khmelnytska obl, PostalCode=29000, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
47800CE335CF5196AC9AFB9061AA72E4

File PE Metadata
OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
2.24

CTPH (ssdeep):
24576:9wPB10aJ+c+fPjK3UymSWKsxFjEU6PGn2lBydVca6H8w76c3oYFSTg:EB+aJJEPjKHmS3ejEU6+n2GdVca6H81M

Entry address:
0x38C160

Entry point:
53, 56, 57, 55, 48, 8D, 35, BA, CE, EA, FF, 48, 8D, BE, DB, 7F, DC, FF, 48, 8D, 87, 0C, AB, 37, 00, FF, 30, C7, 00, D3, EB, ED, 44, 50, 57, 31, DB, 31, C9, 48, 83, CD, FF, E8, 50, 00, 00, 00, 01, DB, 74, 02, F3, C3, 8B, 1E, 48, 83, EE, FC, 11, DB, 8A, 16, F3, C3, 48, 8D, 04, 2F, 83, F9, 05, 8A, 10, 76, 21, 48, 83, FD, FC, 77, 1B, 83, E9, 04, 8B, 10, 48, 83, C0, 04, 83, E9, 04, 89, 17, 48, 8D, 7F, 04, 73, EF, 83, C1, 04, 8A, 10, 74, 10, 48, FF, C0, 88, 17, 83, E9, 01, 8A, 10, 48, 8D, 7F, 01, 75, F0, F3, C3...
 
[+]

Entropy:
7.9407  (probably packed)

Code size:
1.3 MB (1,392,640 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
cpuminer

Command:
C:\Windows\System32\cpuminer-gw64.exe


The executing file has been seen to make the following network communication in live environments.

TCP:
Connects to livingston.shortysmalls.biz  (66.117.6.3:3200)

Remove cpuminer-gw64.exe - Powered by Reason Core Security