SearchIndexer.exe

The application SearchIndexer.exe has been detected as a potentially unwanted program by 28 anti-malware scanners. This is a malicious Bitcoin miner. Bitcoin-mining malware is designed to force computers to generate Bitcoins for cybercriminals' use and consumes computing power. The file has been seen being downloaded from flek1.free.fr. While running, it connects to the Internet address vip47.wemineltc.com on port 3334.
MD5:
65b4516eabbf4fb43789467efb918b40

SHA-1:
1d973728e92844511da0c875ddad2a80d9d68ee4

SHA-256:
f61f0734aec5390c828be6925defe6bf8fd85e50949ee112ad25e2f57d1a560c

Scanner detections:
28 / 68

Status:
Potentially unwanted

Explanation:
The program will mine for BitCoins using the computer's GPU in the background and may be installed and run without the user's knowledge.

Analysis date:
11/15/2024 7:15:33 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.BitCoinMiner.AX
1150

Agnitum Outpost
RiskTool.BitCoinMiner
7.1.1

AhnLab V3 Security
Trojan/Win32.BitMiner
2013.12.29

Avira AntiVirus
SPR/Tool.BitCoinMiner.AX.3
7.11.122.136

avast!
Win32:BitCoinMiner-DN [PUP]
2014.9-130829

Baidu Antivirus
Trojan.Win32.BitCoinMiner
4.0.3.131127

Bitdefender
Application.BitCoinMiner.AX
1.0.20.1205

Bkav FE
W32.Clod427.Trojan
1.3.0.4613

Comodo Security
UnclassifiedMalware
17511

Dr.Web
Trojan.BtcMine.208
9.0.1.0331

Emsisoft Anti-Malware
Application.BitCoinMiner.AX
8.13.08.29.12

ESET NOD32
Win32/BitCoinMiner.AF (variant)
7.9190

Fortinet FortiGate
W32/BitCoinMiner.N
8/29/2013

G Data
Application.BitCoinMiner.AX
13.8.22

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.2.2.29

K7 AntiVirus
Riskware
13.174.10656

Kaspersky
not-a-virus:RiskTool.Win32.BitCoinMiner
14.0.0.3808

Malwarebytes
Trojan.BitCoinMiner
v2013.08.29.12

McAfee
RDN/Generic PUP.x!b2r
5600.7181

MicroWorld eScan
Application.BitCoinMiner.AX
14.0.0.723

NANO AntiVirus
Trojan.Win32.BtcMine.cqlfsc
0.28.0.57029

Panda Antivirus
Trj/CI.A
13.08.29.12

Reason Heuristics
Unnamed.Threat.39
14.3.1.0

Rising Antivirus
PE:Trojan.Win32.Generic.14AF022E!347013678
23.00.65.131125

Sophos
Generic PUA BN
4.96

Trend Micro House Call
TROJ_SPNR.07H913
7.2.241

Trend Micro
TROJ_SPNR.07H913
10.465.29

VIPRE Antivirus
Trojan.Win32.Generic
24838

File size:
552.5 KB (565,774 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\searchindexer.exe

File PE Metadata
Compilation timestamp:
5/30/2013 11:32:09 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.22

CTPH (ssdeep):
12288:7cWV8TKeFEW9o/4mY1ORmcf8ZJN69EWxzoHBWpetgYN:74OKECo/o1ORmcf8ZJN4nxzoHBWp7YN

Entry address:
0x126C

Entry point:
55, 89, E5, 83, EC, 18, C7, 04, 24, 01, 00, 00, 00, FF, 15, 48, 17, 49, 00, E8, 7C, FD, FF, FF, 55, 89, E5, 83, EC, 18, C7, 04, 24, 02, 00, 00, 00, FF, 15, 48, 17, 49, 00, E8, 64, FD, FF, FF, 55, 89, E5, 83, EC, 08, A1, 90, 17, 49, 00, C9, FF, E0, 66, 90, 55, 89, E5, 83, EC, 08, A1, 70, 17, 49, 00, C9, FF, E0, 90, 90, 00, 00, 00, 00, 55, 89, E5, 83, EC, 18, C7, 04, 24, 00, A0, 46, 00, E8, E2, 3A, 06, 00, BA, 00, 00, 00, 00, 83, EC, 04, 85, C0, 74, 15, C7, 44, 24, 04, 13, A0, 46, 00, 89, 04, 24, E8, CE, 3A...
 
[+]

Entropy:
6.3512

Code size:
410 KB (419,840 bytes)

The file SearchIndexer.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP:
Connects to vip47.wemineltc.com  (37.59.20.223:3334)

TCP:
Connects to v7.srv.eligius.st  (107.170.221.41:3334)

TCP:
Connects to ns314679.ip-37-187-25.eu  (37.187.25.91:8888)

TCP:
Connects to ltc.kattare.com  (208.95.104.80:3333)

Remove SearchIndexer.exe - Powered by Reason Core Security