| File name: | AwesomeMiner.msi |
| Full analysis: | https://app.any.run/tasks/dffb6b63-a588-4bfb-a563-da77f681a8f3 |
| Verdict: | Malicious activity |
| Threats: | Crypto mining malware is a resource-intensive threat that infiltrates computers with the purpose of mining cryptocurrencies. This type of threat can be deployed either on an infected machine or a compromised website. In both cases the miner will utilize the computing power of the device and its network bandwidth. |
| Analysis date: | November 15, 2020, 23:48:45 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Awesome Miner, Author: IntelliBreeze Software AB, Keywords: Installer, Comments: This installer database contains the logic and data required to install Awesome Miner., Template: Intel;1033, Revision Number: {0647ACE6-9DAC-4436-A0AA-858F6651E14A}, Create Time/Date: Thu Feb 6 19:18:16 2020, Last Saved Time/Date: Thu Feb 6 19:18:16 2020, Number of Pages: 200, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.11.1.2318), Security: 2 |
| MD5: | 95773AD3CC23EC82E76B979563CCA621 |
| SHA1: | 05E7120C91D291153DBA2B12017FB1D50100478F |
| SHA256: | CF76C07959CB0B804918A9A2FB9C76CFAC56136DFFE8DB4063B993CDDF33B6B8 |
| SSDEEP: | 196608:9rdO3zy8RBeVa0BNjCt8u1eY42lDQ749vFFs/DmS7TT7TT7xYH4LOk/RdfeAuxdw:jOj9em1e7uDQ747Fs/vTTlE4Vabz |
| .msi | | | Microsoft Windows Installer (98.5) |
|---|---|---|
| .msi | | | Microsoft Installer (100) |
| CodePage: | Windows Latin 1 (Western European) |
|---|---|
| Title: | Installation Database |
| Subject: | Awesome Miner |
| Author: | IntelliBreeze Software AB |
| Keywords: | Installer |
| Comments: | This installer database contains the logic and data required to install Awesome Miner. |
| Template: | Intel;1033 |
| RevisionNumber: | {0647ACE6-9DAC-4436-A0AA-858F6651E14A} |
| CreateDate: | 2020:02:06 19:18:16 |
| ModifyDate: | 2020:02:06 19:18:16 |
| Pages: | 200 |
| Words: | 2 |
| Software: | Windows Installer XML Toolset (3.11.1.2318) |
| Security: | Read-only recommended |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 604 | C:\Windows\system32\MsiExec.exe -Embedding C88C578E27B72405A7742763D0CEA4A1 | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2408 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2420 | "C:\Program Files\Awesome Miner\AwesomeMiner.exe" | C:\Program Files\Awesome Miner\AwesomeMiner.exe | MsiExec.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Awesome Miner Exit code: 0 Version: 7.3.1.0 Modules
| |||||||||||||||
| 2756 | C:\Windows\system32\MsiExec.exe -Embedding 81DC8CA0DBFCFC5E64A1A05253B12417 M Global\MSI0000 | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2888 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3028 | C:\Windows\system32\MsiExec.exe -Embedding 4938B251032243DCCFA45C536EC1DC81 C | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3120 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\AwesomeMiner.msi" | C:\Windows\System32\msiexec.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3604 | "C:\Program Files\Awesome Miner\IntelliBreeze.Maintenance.Service.exe" | C:\Program Files\Awesome Miner\IntelliBreeze.Maintenance.Service.exe | — | services.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Description: IntelliBreeze.Maintenance.Service Exit code: 0 Version: 7.3.1.0 Modules
| |||||||||||||||
| (PID) Process: | (3120) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2888) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 40000000000000002AD032F4A9BBD601480B000090090000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2888) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 40000000000000002AD032F4A9BBD601480B000090090000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2888) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 43 | |||
| (PID) Process: | (2888) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 400000000000000010B97CF4A9BBD601480B000090090000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2888) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000006A1B7FF4A9BBD601480B0000A8020000E803000001000000000000000000000067FD2F3D43EBF64298466201380DC1B40000000000000000 | |||
| (PID) Process: | (2408) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000D2A488F4A9BBD60168090000BC030000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2408) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000D2A488F4A9BBD6016809000090080000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2408) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000D2A488F4A9BBD60168090000CC0B0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2408) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000D2A488F4A9BBD6016809000020080000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3120 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI2AA0.tmp | — | |
MD5:— | SHA256:— | |||
| 2888 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 2888 | msiexec.exe | C:\Windows\Installer\195a4b.msi | — | |
MD5:— | SHA256:— | |||
| 2888 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DF3C51E9BBEB9C2F63.TMP | — | |
MD5:— | SHA256:— | |||
| 2408 | vssvc.exe | C: | — | |
MD5:— | SHA256:— | |||
| 2888 | msiexec.exe | C:\Windows\Installer\195a4c.ipi | binary | |
MD5:— | SHA256:— | |||
| 2888 | msiexec.exe | C:\Windows\Installer\MSI60A4.tmp | binary | |
MD5:— | SHA256:— | |||
| 2888 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{3d2ffd67-eb43-42f6-9846-6201380dc1b4}_OnDiskSnapshotProp | binary | |
MD5:— | SHA256:— | |||
| 2888 | msiexec.exe | C:\Program Files\Awesome Miner\AwesomeMiner.exe | executable | |
MD5:48C3533B47C7D9A237E73E3634F96A0C | SHA256:9BE0703DDE08FE326D825C0B542D456A9757E0B78B63991DB8FEA362098286DA | |||
| 2888 | msiexec.exe | C:\Program Files\Awesome Miner\alarm.wav | wav | |
MD5:52BECF91C1B9634604F19EA04CED0B57 | SHA256:22ADB4043B054EF31BC48BDAD408DDEB77F9B96AACA2D85D1E05208213784090 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2420 | AwesomeMiner.exe | GET | 301 | 172.67.69.193:80 | http://www.zpool.ca/api/status | US | — | — | malicious |
2420 | AwesomeMiner.exe | GET | 200 | 104.26.1.148:8080 | http://api.zergpool.com:8080/api/status | US | text | 38.1 Kb | suspicious |
2420 | AwesomeMiner.exe | GET | 200 | 198.199.107.89:80 | http://api.blazepool.com/s.json | US | text | 9.72 Kb | unknown |
2420 | AwesomeMiner.exe | GET | 302 | 198.199.107.89:80 | http://api.blazepool.com/status | US | html | 154 b | unknown |
2420 | AwesomeMiner.exe | GET | 200 | 147.135.97.224:80 | http://blockmasters.co/api/status | US | text | 6.50 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2420 | AwesomeMiner.exe | 188.165.229.135:443 | www.coincalculators.io | OVH SAS | FR | unknown |
2420 | AwesomeMiner.exe | 143.204.201.24:443 | 5aozpdg9s2.execute-api.us-east-1.amazonaws.com | — | US | suspicious |
2420 | AwesomeMiner.exe | 104.26.4.95:443 | miningpoolhub.com | Cloudflare Inc | US | unknown |
2420 | AwesomeMiner.exe | 99.86.7.109:443 | www.awesomeminer.com | AT&T Services, Inc. | US | malicious |
2420 | AwesomeMiner.exe | 172.67.69.193:80 | www.zpool.ca | — | US | unknown |
2420 | AwesomeMiner.exe | 104.26.12.88:443 | whattomine.com | Cloudflare Inc | US | unknown |
2420 | AwesomeMiner.exe | 50.220.121.209:443 | prohashing.com | Comcast Cable Communications, LLC | US | unknown |
2420 | AwesomeMiner.exe | 198.199.107.89:80 | api.blazepool.com | Digital Ocean, Inc. | US | unknown |
2420 | AwesomeMiner.exe | 147.135.97.224:80 | blockmasters.co | OVH SAS | US | unknown |
2420 | AwesomeMiner.exe | 172.67.69.193:443 | www.zpool.ca | — | US | unknown |
Domain | IP | Reputation |
|---|---|---|
www.coincalculators.io |
| malicious |
www.awesomeminer.com |
| malicious |
5aozpdg9s2.execute-api.us-east-1.amazonaws.com |
| malicious |
whattomine.com |
| whitelisted |
api2.nicehash.com |
| suspicious |
miningpoolhub.com |
| whitelisted |
prohashing.com |
| malicious |
api.blazepool.com |
| unknown |
www.ahashpool.com |
| suspicious |
api.zergpool.com |
| suspicious |
Process | Message |
|---|---|
AwesomeMiner.exe | Native library pre-loader is trying to load native SQLite library "C:\Program Files\Awesome Miner\x86\SQLite.Interop.dll"...
|