isMiner.exe

isMiner worker and updater

isMiner

The executable isMiner.exe has been detected as malware by 5 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘isMiner Update’. While running, it connects to the Internet address otp003436.psi.ch on port 80 using the HTTP protocol.
Publisher:
isMiner

Product:
isMiner worker and updater

Description:
isMiner worker

Version:
1.1.1.125

MD5:
d6476dc8f05f2c134b8f266136c84794

SHA-1:
be630ba445d444bdd851bd43cd5509fd844e2633

SHA-256:
c51f1179155ea491f2c9bdfeb690f648534100c8839bfdd26b9eb79638598762

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
5/24/2024 5:53:49 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Dropper-gen [Drp]
2014.9-161209

Baidu Antivirus
Win32.Trojan.WisdomEyes.16070401.9500
4.0.3.16129

Bkav FE
W32.eHeur.Malware00
1.3.0.8455

Qihoo 360 Security
HEUR/QVM05.1.0000.Malware.Gen
1.0.0.1120

Rising Antivirus
Malware.Heuristic!ET#91% (rdm+)
23.00.65.161207

File size:
2.8 MB (2,931,200 bytes)

Product version:
1.9.0.0

Copyright:
isMiner corp

Trademarks:
isMiner corp

Original file name:
isMiner.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\isminer.exe

File PE Metadata
Compilation timestamp:
12/9/2016 8:28:34 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x28C630

Entry point:
55, 8B, EC, 83, C4, EC, 33, C0, 89, 45, EC, B8, 00, FB, 67, 00, E8, 97, 38, D8, FF, 33, C0, 55, 68, A7, C6, 68, 00, 64, FF, 30, 64, 89, 20, E8, 18, AC, D7, FF, 85, C0, 75, 30, E8, C7, 31, FE, FF, 84, C0, 75, 20, 8D, 55, EC, 33, C0, E8, 61, AC, D7, FF, 8B, 45, EC, 33, D2, E8, 4F, 32, FE, FF, A1, 90, 77, 69, 00, 8B, 00, E8, CF, 98, F0, FF, E8, 32, 34, FF, FF, EB, 05, E8, 2F, 0A, FF, FF, 33, C0, 5A, 59, 59, 64, 89, 10, 68, AE, C6, 68, 00, 8D, 45, EC, E8, AE, DB, D7, FF, C3, E9, 08, D1, D7, FF, EB, F0, E8, D1...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
2.5 MB (2,668,544 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
isMiner Update

Command:
"C:\users\{user}\appdata\roaming\isminer\isminer.exe" -checkforupdates


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to websafe.virginmedia.com  (62.254.123.86:80)

TCP (HTTP):
Connects to otp003436.psi.ch  (129.129.129.129:80)

Remove isMiner.exe - Powered by Reason Core Security