cpuminer-gw64.exe

DZHPI-PROEKT

The application cpuminer-gw64.exe by DZHPI-PROEKT has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘cpuminer’. While running, it connects to the Internet address livingston.shortysmalls.biz on port 3201.
Publisher:
DZHPI-PROEKT  (signed and verified)

MD5:
fc0f60969ad349a6418ad24b59f40bf8

SHA-1:
fb5768abb01c4f58a846503a4d5411804949c39d

SHA-256:
38b33284f0fd7e5d147de288d816a7d139317e175280af92760e6b4bab6512f5

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 3:07:22 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.BitcoinMiner.DZHPIPROEKT.Meta
15.6.12.16

File size:
1.3 MB (1,413,920 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\Windows\System32\cpuminer-gw64.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/28/2015 2:00:00 AM

Valid to:
5/28/2016 1:59:59 AM

Subject:
CN=DZHPI-PROEKT, O=DZHPI-PROEKT, STREET="vul. Hrafa Fon Shenborna, 49", L=Mukacheve, S=Zakarpatska, PostalCode=89600, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
391A6404F6B8400F91E0D33039F075C3

File PE Metadata
OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
2.24

CTPH (ssdeep):
24576:QqEolufDui7KQO//Vbd/62zmIrMDOz7KHXlE/2ynf4CbCy49/Q7xjPYT:QroYL7KF/L6nLOzYYPdCy49/Q7xjPG

Entry address:
0x38B150

Entry point:
53, 56, 57, 55, 48, 8D, 35, CA, CE, EA, FF, 48, 8D, BE, DB, 8F, DC, FF, 48, 8D, 87, 0C, 9E, 37, 00, FF, 30, C7, 00, 16, 7D, 10, 90, 50, 57, 31, DB, 31, C9, 48, 83, CD, FF, E8, 50, 00, 00, 00, 01, DB, 74, 02, F3, C3, 8B, 1E, 48, 83, EE, FC, 11, DB, 8A, 16, F3, C3, 48, 8D, 04, 2F, 83, F9, 05, 8A, 10, 76, 21, 48, 83, FD, FC, 77, 1B, 83, E9, 04, 8B, 10, 48, 83, C0, 04, 83, E9, 04, 89, 17, 48, 8D, 7F, 04, 73, EF, 83, C1, 04, 8A, 10, 74, 10, 48, FF, C0, 88, 17, 83, E9, 01, 8A, 10, 48, 8D, 7F, 01, 75, F0, F3, C3...
 
[+]

Code size:
1.3 MB (1,392,640 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
cpuminer

Command:
C:\Windows\System32\cpuminer-gw64.exe


The executing file has been seen to make the following network communication in live environments.

TCP:
Connects to livingston.shortysmalls.biz  (66.117.6.3:3201)

Remove cpuminer-gw64.exe - Powered by Reason Core Security