gputemp.exe

White Sea Media

The application gputemp.exe by White Sea Media has been detected as adware by 4 anti-malware scanners. This is a setup program which is used to install the application. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘GPUTemp’. This is a trojan Bot that uses IRC to communicate with a comand and control network. The Trojan drops other malicious software and opens a backdoor on the infected computer and will run automatically on each boot.
Publisher:
White Sea Media  (signed and verified)

MD5:
6f40b2a954dc1b38b3dd4945c48ce2c2

SHA-1:
7c67ea385ad29153e528c62c148edddd942d4644

SHA-256:
36e1444cfadff5a283c8359c2124f0cc4dd21c1eb034c6c82ad7bff50e1091ea

Scanner detections:
4 / 68

Status:
Adware

Explanation:
Part of a backdoor IRC bot network.

Analysis date:
11/5/2024 9:54:03 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.BtcMine.221
9.0.1.0352

Malwarebytes
Trojan.Vbkrypt.gen
v2013.12.18.12

Reason Heuristics
PUP.Startup.WhiteSeaMedia.H
14.8.7.21

VIPRE Antivirus
Backdoor.Win32.Ircbot.gen
24256

File size:
1.2 MB (1,299,680 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\gputemp.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/8/2013 2:00:00 AM

Valid to:
7/9/2014 1:59:59 AM

Subject:
CN=White Sea Media, O=White Sea Media, STREET=4142 Mariner Blvd, L=Spring Hill, S=FL, PostalCode=34609, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
1FB235ACA7565BA27ADC702B2BD05C7F

File PE Metadata
Compilation timestamp:
12/10/2013 4:54:30 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:8rdFh0AFyJTJTQG6xZovAzYkVzLcKn+aMflg4lJOQ:8F0AoJhQGcovmVkK+FahQ

Entry address:
0x345000

Entry point:
83, EC, 04, 50, 53, E8, 01, 00, 00, 00, CC, 58, 89, C3, 40, 2D, 00, 10, 13, 00, 2D, 8F, 8E, 0A, 10, 05, 84, 8E, 0A, 10, 80, 3B, CC, 75, 19, C6, 03, 00, BB, 00, 10, 00, 00, 68, BE, 3C, 07, 52, 68, 4C, 0F, C7, 6B, 53, 50, E8, 0A, 00, 00, 00, 83, C0, 00, 89, 44, 24, 08, 5B, 58, C3, 55, 89, E5, 50, 53, 51, 56, 8B, 75, 08, 8B, 4D, 0C, C1, E9, 02, 8B, 45, 10, 8B, 5D, 14, 85, C9, 74, 0A, 31, 06, 01, 1E, 83, C6, 04, 49, EB, F2, 5E, 59, 5B, 58, C9, C2, 10, 00, 9D, 00, 05, A6, 9C, 85, 26, 8C, 6B, 67, 1A, 45, 12, 3A...
 
[+]

Entropy:
7.9100  (probably packed)

Code size:
41 KB (41,984 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
GPUTemp

Command:
"C:\DOCUME~1\{user}\Locals~1\temp\gputemp.exe"


The file gputemp.exe has been seen being distributed by the following 2 URLs.

http://shoppingsuggestion.com/.../GPUTemp7.exe

Remove gputemp.exe - Powered by Reason Core Security