cpuminer-x86.exe

cpuminer-multi

LLC

The application cpuminer-x86.exe by LLC has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘cpuminer’. While running, it connects to the Internet address livingston.shortysmalls.biz on port 3202.
Publisher:
LLC   (signed and verified)

Product:
cpuminer-multi

Version:
1.1

MD5:
1acbc0a5fb5aa50033b623bdd044be70

SHA-1:
f194d30d5a3d5d5027d6dae094ae3e23500697c2

SHA-256:
c9f8832e9003b2db34e2ef2374db7988db26695f27c09141ad27e19f3853b896

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 3:07:36 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.BitcoinMiner.Meta (M)
16.2.14.3

File size:
2.3 MB (2,410,296 bytes)

Product version:
1.1

Copyright:
Copyright (C) 2015

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Windows\System32\cpuminer-x86.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/6/2015 7:00:00 AM

Valid to:
5/6/2016 6:59:59 AM

Subject:
CN="LLC ""LAYN-PROEKT""", O="LLC ""LAYN-PROEKT""", STREET="Vulitsya Bogdana Khmel''nits''kogo , Budinok 106", L=Lviv, S=Lvivska, PostalCode=79019, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E17C1DB2CCC44BCBE684F843F1CF4F3C

File PE Metadata
Compilation timestamp:
5/11/2015 9:57:01 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
12.0

CTPH (ssdeep):
49152:1VbTg9Yz2sC7kaLvYLDjI/X55GBz5YGZrGMhATfuBRPVmH4EK:nT32sC77TYLDjMp5f4LmK

Entry address:
0x17DCC1

Entry point:
E8, 7B, 02, 00, 00, E9, 91, FE, FF, FF, CC, CC, CC, CC, CC, 57, 56, 53, 33, FF, 8B, 44, 24, 14, 0B, C0, 7D, 14, 47, 8B, 54, 24, 10, F7, D8, F7, DA, 83, D8, 00, 89, 44, 24, 14, 89, 54, 24, 10, 8B, 44, 24, 1C, 0B, C0, 7D, 14, 47, 8B, 54, 24, 18, F7, D8, F7, DA, 83, D8, 00, 89, 44, 24, 1C, 89, 54, 24, 18, 0B, C0, 75, 18, 8B, 4C, 24, 18, 8B, 44, 24, 14, 33, D2, F7, F1, 8B, D8, 8B, 44, 24, 10, F7, F1, 8B, D3, EB, 41, 8B, D8, 8B, 4C, 24, 18, 8B, 54, 24, 14, 8B, 44, 24, 10, D1, EB, D1, D9, D1, EA, D1, D8, 0B, DB...
 
[+]

Entropy:
6.9828

Code size:
1.5 MB (1,562,112 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
cpuminer

Command:
C:\Windows\System32\cpuminer-x86.exe


The executing file has been seen to make the following network communication in live environments.

TCP:
Connects to livingston.shortysmalls.biz  (66.117.6.3:3202)

Remove cpuminer-x86.exe - Powered by Reason Core Security