dopipjen.exe

The executable dopipjen.exe has been detected as malware by 12 anti-virus scanners. This is a malicious Bitcoin miner. Bitcoin-mining malware is designed to force computers to generate Bitcoins for cybercriminals' use and consumes computing power. While running, it connects to the Internet address lb-182-241.above.com on port 3000.
MD5:
d40da7822cfc1271be00839d969e0eb8

SHA-1:
706c0792d2685075a14590bdd0a8fee00f3c9482

SHA-256:
761fb0cb6a96a6aebd1dab9cc7453da4917f68285a3582aa73ebf86287c5b611

Scanner detections:
12 / 68

Status:
Malware

Explanation:
The program will mine for BitCoins using the computer's GPU in the background and may be installed and run without the user's knowledge.

Analysis date:
4/18/2024 2:30:24 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Skodna.BitCoinMiner
2015.0.3457

Baidu Antivirus
Trojan.Win32.BitCoinMiner
4.0.3.14531

Bkav FE
W32.Clodb08.Trojan
1.3.0.4613

Comodo Security
UnclassifiedMalware
17404

ESET NOD32
Win32/BitCoinMiner.AB (variant)
8.9146

Fortinet FortiGate
W32/BitCoinMiner.AB
5/31/2014

IKARUS anti.virus
possible-Threat.Skodna
t3scan.2.2.29

K7 AntiVirus
Trojan
13.174.10446

McAfee
Artemis!D40DA7822CFC
5600.7113

Norman
Suspicious_Gen5.ADLCW
11.20140531

Sophos
Bitcoin Miner
4.95

VIPRE Antivirus
Trojan.Win32.Generic
24138

File size:
546.5 KB (559,630 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\dopipjen.exe

File PE Metadata
Compilation timestamp:
7/25/2013 7:43:09 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.22

CTPH (ssdeep):
6144:WFczwnYW5dlVWOF2vDBLQ7yMP67zwt2IDSzI+XsTYsWkLhsApI9g4rfkuOTQpd:WFRnvHlVUDgyMP67U4tMhY+Lhmrfkwd

Entry address:
0x126C

Entry point:
55, 89, E5, 83, EC, 18, C7, 04, 24, 01, 00, 00, 00, FF, 15, E8, F6, 48, 00, E8, 7C, FD, FF, FF, 55, 89, E5, 83, EC, 18, C7, 04, 24, 02, 00, 00, 00, FF, 15, E8, F6, 48, 00, E8, 64, FD, FF, FF, 55, 89, E5, 83, EC, 08, A1, 20, F7, 48, 00, C9, FF, E0, 66, 90, 55, 89, E5, 83, EC, 08, A1, 04, F7, 48, 00, C9, FF, E0, 90, 90, 55, 89, E5, 83, EC, 18, C7, 04, 24, 00, D0, 46, 00, E8, 1A, 5F, 06, 00, 52, 85, C0, 74, 65, C7, 44, 24, 04, 13, D0, 46, 00, 89, 04, 24, E8, 0D, 5F, 06, 00, 83, EC, 08, 85, C0, 74, 11, C7, 44...
 
[+]

Code size:
421.5 KB (431,616 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP:
Connects to 140.ip-92-222-6.eu  (92.222.6.140:3334)

TCP:
Connects to 141.ip-92-222-6.eu  (92.222.6.141:3334)

TCP:
Connects to 115.ip-92-222-176.eu  (92.222.176.115:3334)

TCP:
Connects to vip47.wemineltc.com  (37.59.20.223:3333)

TCP:
Connects to ks208500.kimsufi.com  (94.23.224.7:3335)

TCP:
Connects to lb-182-241.above.com  (103.224.182.241:3000)

Remove dopipjen.exe - Powered by Reason Core Security