guiminer-20120219.exe

7-Zip

Igor Pavlov

The application guiminer-20120219.exe has been detected as a potentially unwanted program by 18 anti-malware scanners. The program is a setup application that uses the 7z Setup installer, however the file is not signed with an authenticode signature from a trusted source. This is a malicious Bitcoin miner. Bitcoin-mining malware is designed to force computers to generate Bitcoins for cybercriminals' use and consumes computing power. The file has been seen being downloaded from cloud.github.com and multiple other hosts.
Publisher:
Igor Pavlov

Product:
7-Zip

Description:
7z SFX

Version:
4.65

MD5:
f7748768066c3f5684e1b07f99acf394

SHA-1:
e0f37e2561f38afce968cc891ddcefd1abf7639a

SHA-256:
80ec8ad8700c3e3db2b01f3fa73ce8d1dbfe1c538ea89cfbcadc3137735f2f86

Scanner detections:
18 / 68

Status:
Potentially unwanted

Explanation:
The program will mine for BitCoins using the computer's GPU in the background and may be installed and run without the user's knowledge.

Analysis date:
4/19/2024 3:43:13 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.BitCoinMiner.AL
1040

avast!
Win32:BitCoinMiner-AX [PUP]
2014.9-140331

Bkav FE
W32.Clod69e.Trojan
1.3.0.4959

Dr.Web
Tool.BtcMine.80
9.0.1.090

ESET NOD32
Win32/BitCoinMiner (variant)
8.9564

F-Secure
Application.BitCoinMiner.AL
11.2014-31-03_2

IKARUS anti.virus
Application.BitCoinMiner
t3scan.2.2.29

K7 AntiVirus
Trojan
13.176.11496

Kaspersky
not-a-virus:RiskTool.Win32.BitCoinMiner
14.0.0.4087

Malwarebytes
Riskware.BitCoinMiner
v2014.03.31.03

McAfee
Artemis!F7748768066C
5600.7174

MicroWorld eScan
Application.BitCoinMiner.AL
15.0.0.270

NANO AntiVirus
Riskware.Win32.BitCoinMiner.ugvbc
0.28.0.58491

Rising Antivirus
PE:Trojan.Win32.Generic.12B9CDA6!314166694
23.00.65.14329

Sophos
Generic PUA OA
4.98

Trend Micro House Call
TROJ_SPNR.0CEF13
7.2.90

Trend Micro
TROJ_SPNR.0CEF13
10.465.31

VIPRE Antivirus
Trojan.Win32.Generic
27552

File size:
7.7 MB (8,117,913 bytes)

Product version:
4.65

Copyright:
Copyright (c) 1999-2009 Igor Pavlov

Original file name:
7z.sfx.exe

File type:
Executable application (Win32 EXE)

Installer:
7z Setup

Common path:
C:\Documents and Settings\{user}\My documents\downloads\guiminer-20120219.exe

File PE Metadata
Compilation timestamp:
2/3/2009 11:21:07 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:hiHhNfJ1mDeKiqaXNQ2SF50Vpx6e+RCkDtCApEcu+AWzWjf:hijJ1mDCtNQ2Q0VKTCAqh+ADjf

Entry address:
0x1939C

Entry point:
55, 8B, EC, 6A, FF, 68, 78, CD, 41, 00, 68, 96, 93, 41, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, F0, C0, 41, 00, 59, 83, 0D, 64, 6C, 42, 00, FF, 83, 0D, 68, 6C, 42, 00, FF, FF, 15, F4, C0, 41, 00, 8B, 0D, 4C, 4C, 42, 00, 89, 08, FF, 15, F8, C0, 41, 00, 8B, 0D, 48, 4C, 42, 00, 89, 08, A1, FC, C0, 41, 00, 8B, 00, A3, 60, 6C, 42, 00, E8, 1C, 01, 00, 00, 39, 1D, 40, 29, 42, 00, 75, 0C, 68, 24, 95, 41, 00, FF, 15, 00, C1...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
106.5 KB (109,056 bytes)

The file guiminer-20120219.exe has been seen being distributed by the following 2 URLs.

Remove guiminer-20120219.exe - Powered by Reason Core Security