winsystemx86.exe

The application winsystemx86.exe has been detected as a potentially unwanted program by 27 anti-malware scanners. This is a malicious Bitcoin miner. Bitcoin-mining malware is designed to force computers to generate Bitcoins for cybercriminals' use and consumes computing power. The file has been seen being downloaded from gd-sirve.com.
MD5:
724f8dbbd067ff836dd8c757ee5e0661

SHA-1:
825a82d45fd22d2bd646abaa948d571a2f32aa25

SHA-256:
d26306c389429f00d8b37141c3fcc36581ca78c8a009140602ef711a987347e9

Scanner detections:
27 / 68

Status:
Potentially unwanted

Explanation:
The program will mine for BitCoins using the computer's GPU in the background and may be installed and run without the user's knowledge.

Analysis date:
12/29/2024 5:48:29 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1583875
383

Agnitum Outpost
Riskware.BitCoinMiner
7.1.1

Avira AntiVirus
TR/Rogue.556560
7.11.165.30

avast!
Win32:Miner-B [PUP]
2014.9-160117

AVG
Skodna.BitCoinMiner
2017.0.2861

Baidu Antivirus
Trojan.Win32.BitCoinMiner
4.0.3.16117

Bitdefender
Trojan.GenericKD.1583875
1.0.20.85

Bkav FE
W32.HfsAutoB
1.3.0.4959

Comodo Security
UnclassifiedMalware
19077

Dr.Web
Tool.BtcMine.130
9.0.1.017

Emsisoft Anti-Malware
Trojan.GenericKD.1583875
8.16.01.17.03

ESET NOD32
Win32/BitCoinMiner
10.10199

Fortinet FortiGate
Riskware/BitCoinMiner
1/17/2016

G Data
Trojan.GenericKD.1583875
16.1.24

K7 AntiVirus
Trojan
13.182.12926

Kaspersky
not-a-virus:RiskTool.Win32.BitCoinMiner
14.0.0.802

Malwarebytes
PUP.BitCoinMiner
v2016.01.17.03

McAfee
Artemis!724F8DBBD067
5600.6517

MicroWorld eScan
Trojan.GenericKD.1583875
17.0.0.51

NANO AntiVirus
Riskware.Win32.BitCoinMiner.cvikrw
0.28.2.61148

nProtect
Trojan.GenericKD.1583875
14.08.03.01

Panda Antivirus
HackTool/BitCoinMiner.A
16.01.17.03

Qihoo 360 Security
Win32/Virus.RiskTool.26e
1.0.0.1015

Sophos
Generic PUA IC
4.98

Trend Micro House Call
HKTL_BITMINE.SML
7.2.17

Trend Micro
HKTL_BITMINE.SML
10.465.17

VIPRE Antivirus
Trojan.Win32.CoinMiner.b
31904

File size:
541.5 KB (554,504 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\winsystemx86.exe

File PE Metadata
Compilation timestamp:
7/18/2013 9:00:44 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.23

CTPH (ssdeep):
12288:dvJsH/qrhMmC5eYUeUORy4m+A4TEWPvMUWmAAhWT:Q3rCd4IWPkUWmAbT

Entry address:
0x1290

Entry point:
55, 89, E5, 83, EC, 18, C7, 04, 24, 01, 00, 00, 00, FF, 15, F0, 02, 43, 00, E8, 58, FD, FF, FF, 90, 8D, B4, 26, 00, 00, 00, 00, 55, 89, E5, 83, EC, 18, C7, 04, 24, 02, 00, 00, 00, FF, 15, F0, 02, 43, 00, E8, 38, FD, FF, FF, 90, 8D, B4, 26, 00, 00, 00, 00, 55, 89, E5, 83, EC, 08, A1, 24, 03, 43, 00, C9, FF, E0, 66, 90, 55, 89, E5, 83, EC, 08, A1, 08, 03, 43, 00, C9, FF, E0, 90, 90, 55, 89, E5, 83, EC, 18, A1, 04, B7, 42, 00, 85, C0, 74, 3A, C7, 04, 24, 00, C0, 42, 00, E8, 49, 8C, 02, 00, BA, 00, 00, 00, 00...
 
[+]

Entropy:
6.6472

Code size:
166.5 KB (170,496 bytes)

The file winsystemx86.exe has been seen being distributed by the following URL.

Remove winsystemx86.exe - Powered by Reason Core Security