cpuminer-x86.exe

cpuminer

The Group

The application cpuminer-x86.exe by The Group has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘cpuminer’. While running, it connects to the Internet address livingston.shortysmalls.biz on port 3200.
Publisher:
The Group  (signed and verified)

Product:
cpuminer

Version:
1.1

MD5:
4b56f33c5bcb68092c128a9da362c0b8

SHA-1:
381ce3c10953c90deefbb4a2ac2619089621812b

SHA-256:
2c291a64084c4c3c0e50b19c0a20597b566a645b859e310742c50fad45ac1daf

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/27/2024 6:41:04 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.BitcoinMiner.TheGroup.Meta (M)
15.6.26.23

File size:
2.4 MB (2,519,320 bytes)

Product version:
1.1

Copyright:
Copyright (C) 2015

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Windows\System32\cpuminer-x86.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/31/2015 7:00:00 AM

Valid to:
5/31/2016 6:59:59 AM

Subject:
CN=The Group, O=The Group, STREET="vul. Gagarina, 5", L=Khmelnytskyy, S=Khmelnytska obl, PostalCode=29000, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
47800CE335CF5196AC9AFB9061AA72E4

File PE Metadata
Compilation timestamp:
6/25/2015 12:29:26 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
12.0

CTPH (ssdeep):
49152:9OkOaF+jpm1Vh6wlO2vgVdhTrXdL+etNWMbYwBgBz4Y39rGMq7TKRPRmH1Q+wM38:MkAjpm1Vh6wlO2vgVdhTbdyetNWY1Bed

Entry address:
0x197EFB

Entry point:
E8, 81, 02, 00, 00, E9, 91, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 57, 56, 53, 33, FF, 8B, 44, 24, 14, 0B, C0, 7D, 14, 47, 8B, 54, 24, 10, F7, D8, F7, DA, 83, D8, 00, 89, 44, 24, 14, 89, 54, 24, 10, 8B, 44, 24, 1C, 0B, C0, 7D, 14, 47, 8B, 54, 24, 18, F7, D8, F7, DA, 83, D8, 00, 89, 44, 24, 1C, 89, 54, 24, 18, 0B, C0, 75, 18, 8B, 4C, 24, 18, 8B, 44, 24, 14, 33, D2, F7, F1, 8B, D8, 8B, 44, 24, 10, F7, F1, 8B, D3, EB, 41, 8B, D8, 8B, 4C, 24, 18, 8B, 54, 24, 14, 8B, 44, 24, 10, D1, EB, D1, D9...
 
[+]

Entropy:
6.9646

Code size:
1.6 MB (1,669,120 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
cpuminer

Command:
C:\Windows\System32\cpuminer-x86.exe


The executing file has been seen to make the following network communication in live environments.

TCP:
Connects to livingston.shortysmalls.biz  (66.117.6.3:3200)

Remove cpuminer-x86.exe - Powered by Reason Core Security