cpuminer-x86.exe

cpuminer

LLC

The application cpuminer-x86.exe by LLC has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘cpuminer’. While running, it connects to the Internet address livingston.shortysmalls.biz on port 3202.
Publisher:
LLC   (signed and verified)

Product:
cpuminer

Version:
1.1

MD5:
b3a3cc8213a056b342d5eeb7f15efacd

SHA-1:
674cdc3a6550ee0f5e26963fc5545c7078a18f5a

SHA-256:
81eddcf820b95f52495c3b512f7be533dc5c401295f8e194b059c80dea2fb4d6

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/27/2024 5:47:32 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonitize (M)
16.1.6.4

File size:
2.4 MB (2,535,704 bytes)

Product version:
1.1

Copyright:
Copyright (C) 2015

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Windows\System32\cpuminer-x86.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/26/2015 9:00:00 PM

Valid to:
6/26/2016 8:59:59 PM

Subject:
CN="LLC ""SOFT-GLOBAL""", O="LLC ""SOFT-GLOBAL""", STREET="str. Zhelyabova, 8/4", L=Kiev, S=Kiev, PostalCode=03680, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B36870BF55993A07D317A20F776B7615

File PE Metadata
Compilation timestamp:
7/15/2015 1:02:59 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
12.0

CTPH (ssdeep):
49152:b+9r3JMMjDr3/Qt1Vh6wtO2vgVdhglcr/qcPWPl+BzNY1HrGMWnT7RPUmHo4/UXG:69TdjDrYt1Vh6wtO2vgVdhglcr/qAAlK

Entry address:
0x19BBEB

Entry point:
E8, 81, 02, 00, 00, E9, 91, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 57, 56, 53, 33, FF, 8B, 44, 24, 14, 0B, C0, 7D, 14, 47, 8B, 54, 24, 10, F7, D8, F7, DA, 83, D8, 00, 89, 44, 24, 14, 89, 54, 24, 10, 8B, 44, 24, 1C, 0B, C0, 7D, 14, 47, 8B, 54, 24, 18, F7, D8, F7, DA, 83, D8, 00, 89, 44, 24, 1C, 89, 54, 24, 18, 0B, C0, 75, 18, 8B, 4C, 24, 18, 8B, 44, 24, 14, 33, D2, F7, F1, 8B, D8, 8B, 44, 24, 10, F7, F1, 8B, D3, EB, 41, 8B, D8, 8B, 4C, 24, 18, 8B, 54, 24, 14, 8B, 44, 24, 10, D1, EB, D1, D9...
 
[+]

Code size:
1.6 MB (1,684,992 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
cpuminer

Command:
C:\Windows\System32\cpuminer-x86.exe


The executing file has been seen to make the following network communication in live environments.

TCP:
Connects to livingston.shortysmalls.biz  (66.117.6.3:3202)

Remove cpuminer-x86.exe - Powered by Reason Core Security