cpuminer-x86.exe

cpuminer

Realinvest SOFT, TOV

The application cpuminer-x86.exe by Realinvest SOFT, TOV has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘cpuminer’. While running, it connects to the Internet address livingston.shortysmalls.biz on port 3202.
Publisher:
Realinvest SOFT, TOV  (signed and verified)

Product:
cpuminer

Version:
1.1

MD5:
4cfc0f182a31ba33620279a4f75d6e56

SHA-1:
245b0185eabfb78c56b3259c2b468ba29342eef0

SHA-256:
b034355582e3bda904a113baa164dfabbd70ad1039b76277e56802aa9900e6ca

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 3:25:50 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.BitcoinMiner.RealinvestSOFTTOV.Meta
15.6.18.2

File size:
2.3 MB (2,412,320 bytes)

Product version:
1.1

Copyright:
Copyright (C) 2015

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Windows\System32\cpuminer-x86.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/29/2015 7:00:00 AM

Valid to:
5/29/2016 6:59:59 AM

Subject:
CN="Realinvest SOFT, TOV", O="Realinvest SOFT, TOV", STREET=Bud. 7a vul.Lodzka, L=Kharkiv, S=Kharkiv, PostalCode=61000, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00FE321D16ABD978B89260FC92F22CF774

File PE Metadata
Compilation timestamp:
6/6/2015 12:46:18 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
12.0

CTPH (ssdeep):
49152:qTaajHLWlEjWwKVjFVUV60eowBzpYk9rGMbeTgRPwmHFNQkmK:0aa+lEaLjFVUYvoQOmJ

Entry address:
0x17E054

Entry point:
E8, 78, 02, 00, 00, E9, 91, FE, FF, FF, CC, CC, 57, 56, 53, 33, FF, 8B, 44, 24, 14, 0B, C0, 7D, 14, 47, 8B, 54, 24, 10, F7, D8, F7, DA, 83, D8, 00, 89, 44, 24, 14, 89, 54, 24, 10, 8B, 44, 24, 1C, 0B, C0, 7D, 14, 47, 8B, 54, 24, 18, F7, D8, F7, DA, 83, D8, 00, 89, 44, 24, 1C, 89, 54, 24, 18, 0B, C0, 75, 18, 8B, 4C, 24, 18, 8B, 44, 24, 14, 33, D2, F7, F1, 8B, D8, 8B, 44, 24, 10, F7, F1, 8B, D3, EB, 41, 8B, D8, 8B, 4C, 24, 18, 8B, 54, 24, 14, 8B, 44, 24, 10, D1, EB, D1, D9, D1, EA, D1, D8, 0B, DB, 75, F4, F7...
 
[+]

Entropy:
6.9835

Code size:
1.5 MB (1,563,136 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
cpuminer

Command:
C:\Windows\System32\cpuminer-x86.exe


The executing file has been seen to make the following network communication in live environments.

TCP:
Connects to livingston.shortysmalls.biz  (66.117.6.3:3202)

Remove cpuminer-x86.exe - Powered by Reason Core Security