svchost.exe

The application svchost.exe has been detected as a potentially unwanted program by 27 anti-malware scanners. This is a setup program which is used to install the application. This is a malicious Bitcoin miner. Bitcoin-mining malware is designed to force computers to generate Bitcoins for cybercriminals' use and consumes computing power. Although this file uses the name svchost.exe, this is NOT the Windows SvcHost (Service Host) distributed with the OS. The file has been seen being downloaded from flek1.free.fr.
MD5:
02ec18066a7728b774099ff4215a41ba

SHA-1:
370e3f682102c7ef7a1613a39db5b0870307b036

SHA-256:
160861090d76c2ac1e2b6567ca89385e9baac0c3bcc6d31b372b5a1ff8bb4469

Scanner detections:
27 / 68

Status:
Potentially unwanted

Explanation:
The program will mine for BitCoins using the computer's GPU in the background and may be installed and run without the user's knowledge.

Analysis date:
4/26/2024 10:44:17 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.BitCoinMiner.AX
1050

Agnitum Outpost
RiskTool.BitCoinMiner
7.1.1

AhnLab V3 Security
Trojan/Win32.BitMiner
2013.12.29

Avira AntiVirus
SPR/Tool.BitCoinMiner.AX.3
7.11.122.136

avast!
Win32:BitCoinMiner-DN [PUP]
2014.9-140322

Baidu Antivirus
Trojan.Win32.BitCoinMiner
4.0.3.14322

Bitdefender
Application.BitCoinMiner.AX
1.0.20.405

Bkav FE
W32.Clod427.Trojan
1.3.0.4613

Comodo Security
UnclassifiedMalware
17511

Dr.Web
Trojan.BtcMine.208
9.0.1.081

Emsisoft Anti-Malware
Application.BitCoinMiner.AX
8.14.03.22.03

ESET NOD32
Win32/BitCoinMiner.AF (variant)
8.9190

Fortinet FortiGate
W32/BitCoinMiner.N
5/21/2014

G Data
Application.BitCoinMiner.AX
14.3.22

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.2.2.29

K7 AntiVirus
Riskware
13.174.10656

Kaspersky
not-a-virus:RiskTool.Win32.BitCoinMiner
14.0.0.3834

Malwarebytes
Trojan.BitCoinMiner
v2014.03.22.03

McAfee
RDN/Generic PUP.x!b2r
5600.7124

MicroWorld eScan
Application.BitCoinMiner.AX
15.0.0.243

NANO AntiVirus
Trojan.Win32.BtcMine.cqlfsc
0.28.0.57029

Panda Antivirus
Trj/CI.A
14.05.21.04

Rising Antivirus
PE:Trojan.Win32.Generic.14AF022E!347013678
23.00.65.14519

Sophos
Generic PUA BN
4.96

Trend Micro House Call
TROJ_SPNR.07H913
7.2.81

Trend Micro
TROJ_SPNR.07H913
10.465.22

VIPRE Antivirus
Trojan.Win32.Generic
24838

File size:
552.5 KB (565,777 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\microsoft\systemcertificates\my\updater\svchost.exe

File PE Metadata
Compilation timestamp:
5/31/2013 8:32:09 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.22

CTPH (ssdeep):
12288:7cWV8TKeFEW9o/4mY1ORmcf8ZJN69EWxzoHBWpetgYP:74OKECo/o1ORmcf8ZJN4nxzoHBWp7YP

Entry address:
0x126C

Entry point:
55, 89, E5, 83, EC, 18, C7, 04, 24, 01, 00, 00, 00, FF, 15, 48, 17, 49, 00, E8, 7C, FD, FF, FF, 55, 89, E5, 83, EC, 18, C7, 04, 24, 02, 00, 00, 00, FF, 15, 48, 17, 49, 00, E8, 64, FD, FF, FF, 55, 89, E5, 83, EC, 08, A1, 90, 17, 49, 00, C9, FF, E0, 66, 90, 55, 89, E5, 83, EC, 08, A1, 70, 17, 49, 00, C9, FF, E0, 90, 90, 00, 00, 00, 00, 55, 89, E5, 83, EC, 18, C7, 04, 24, 00, A0, 46, 00, E8, E2, 3A, 06, 00, BA, 00, 00, 00, 00, 83, EC, 04, 85, C0, 74, 15, C7, 44, 24, 04, 13, A0, 46, 00, 89, 04, 24, E8, CE, 3A...
 
[+]

Code size:
410 KB (419,840 bytes)

The file svchost.exe has been seen being distributed by the following URL.

Remove svchost.exe - Powered by Reason Core Security