bfgminer.exe

The application bfgminer.exe has been detected as a potentially unwanted program by 13 anti-malware scanners. This is a malicious Bitcoin miner. Bitcoin-mining malware is designed to force computers to generate Bitcoins for cybercriminals' use and consumes computing power. While running, it connects to the Internet address static.176.102.76.144.clients.your-server.de on port 3333.
MD5:
99623c63b2aa36c33079bb25310d7136

SHA-1:
b5726c7375338f699e20d330c960873cae3b9e1e

SHA-256:
87641cb30bcaeccc4880e943ad914c8658a0a52920b355604ecfe1aac6fcf0fe

Scanner detections:
13 / 68

Status:
Potentially unwanted

Explanation:
The program will mine for BitCoins using the computer's GPU in the background and may be installed and run without the user's knowledge.

Analysis date:
7/14/2025 5:29:50 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Trojan/Win64.BitCoinMiner
14.03.24

Avira AntiVirus
APPL/Bitcoinminer.Gen
7.11.138.108

avast!
Win32:BitCoinMiner-EJ [PUP]
2014.9-140324

Baidu Antivirus
Trojan.Win32.BitCoinMiner
4.0.3.14324

Comodo Security
UnclassifiedMalware
17972

ESET NOD32
Win32/BitCoinMiner (variant)
8.9576

K7 AntiVirus
Trojan
13.176.11524

Kaspersky
not-a-virus:RiskTool.Win32.BitCoinMiner
14.0.0.4122

McAfee
Artemis!99623C63B2AA
5600.7181

Sophos
Bitcoin Miner
4.98

Trend Micro House Call
TROJ_GEN.F47V0116
7.2.83

VIPRE Antivirus
VirTool.Win32.Obfuscator.hg!b1
27642

ViRobot
Trojan.Win64.S.BitCoinMiner.2603453
2011.4.7.4223

File size:
2.5 MB (2,603,453 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
11/23/1972 12:29:01 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.24

CTPH (ssdeep):
49152:Cy8g5rzExBNfMN6taKtGHtTtYtJpTtptGtmtkL7K/4:C0UBdMstbtQtTtYtrtptGtmtE

Entry address:
0x12A0

Entry point:
83, EC, 1C, C7, 04, 24, 01, 00, 00, 00, FF, 15, EC, B8, 4C, 00, E8, 4B, FD, FF, FF, 8D, 74, 26, 00, 8D, BC, 27, 00, 00, 00, 00, 83, EC, 1C, C7, 04, 24, 02, 00, 00, 00, FF, 15, EC, B8, 4C, 00, E8, 2B, FD, FF, FF, 8D, 74, 26, 00, 8D, BC, 27, 00, 00, 00, 00, A1, 20, B9, 4C, 00, FF, E0, 89, F6, 8D, BC, 27, 00, 00, 00, 00, A1, 08, B9, 4C, 00, FF, E0, 90, 90, 90, 90, 90, 90, 90, 90, 90, A1, 84, C2, 4A, 00, 85, C0, 74, 41, 55, 89, E5, 83, EC, 18, C7, 04, 24, 00, D0, 4A, 00, E8, 11, 6A, 0A, 00, BA, 00, 00, 00, 00...
 
[+]

Code size:
668.5 KB (684,544 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP:
Connects to static.176.102.76.144.clients.your-server.de  (144.76.102.176:3333)

Remove bfgminer.exe - Powered by Reason Core Security