File name:

AwesomeMiner.msi

Full analysis: https://app.any.run/tasks/dffb6b63-a588-4bfb-a563-da77f681a8f3
Verdict: Malicious activity
Threats:

Crypto mining malware is a resource-intensive threat that infiltrates computers with the purpose of mining cryptocurrencies. This type of threat can be deployed either on an infected machine or a compromised website. In both cases the miner will utilize the computing power of the device and its network bandwidth.

Analysis date: November 15, 2020, 23:48:45
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
generated-doc
miner
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Awesome Miner, Author: IntelliBreeze Software AB, Keywords: Installer, Comments: This installer database contains the logic and data required to install Awesome Miner., Template: Intel;1033, Revision Number: {0647ACE6-9DAC-4436-A0AA-858F6651E14A}, Create Time/Date: Thu Feb 6 19:18:16 2020, Last Saved Time/Date: Thu Feb 6 19:18:16 2020, Number of Pages: 200, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.11.1.2318), Security: 2
MD5:

95773AD3CC23EC82E76B979563CCA621

SHA1:

05E7120C91D291153DBA2B12017FB1D50100478F

SHA256:

CF76C07959CB0B804918A9A2FB9C76CFAC56136DFFE8DB4063B993CDDF33B6B8

SSDEEP:

196608:9rdO3zy8RBeVa0BNjCt8u1eY42lDQ749vFFs/DmS7TT7TT7xYH4LOk/RdfeAuxdw:jOj9em1e7uDQ747Fs/vTTlE4Vabz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • IntelliBreeze.Maintenance.Service.exe (PID: 3604)
      • AwesomeMiner.exe (PID: 2420)
    • Application was dropped or rewritten from another process

      • IntelliBreeze.Maintenance.Service.exe (PID: 3604)
      • AwesomeMiner.exe (PID: 2420)
    • Loads the Task Scheduler COM API

      • IntelliBreeze.Maintenance.Service.exe (PID: 3604)
  • SUSPICIOUS

    • Executed as Windows Service

      • vssvc.exe (PID: 2408)
      • IntelliBreeze.Maintenance.Service.exe (PID: 3604)
    • Dropped object may contain URLs of mainers pools

      • msiexec.exe (PID: 2888)
      • AwesomeMiner.exe (PID: 2420)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 2888)
    • Modifies the open verb of a shell class

      • msiexec.exe (PID: 2888)
      • AwesomeMiner.exe (PID: 2420)
    • Creates files in the program directory

      • IntelliBreeze.Maintenance.Service.exe (PID: 3604)
      • AwesomeMiner.exe (PID: 2420)
    • Reads Environment values

      • AwesomeMiner.exe (PID: 2420)
    • Creates files in the user directory

      • AwesomeMiner.exe (PID: 2420)
  • INFO

    • Application launched itself

      • msiexec.exe (PID: 2888)
    • Searches for installed software

      • msiexec.exe (PID: 2888)
    • Creates files in the program directory

      • msiexec.exe (PID: 2888)
    • Low-level read access rights to disk partition

      • vssvc.exe (PID: 2408)
    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 604)
      • MsiExec.exe (PID: 2756)
      • MsiExec.exe (PID: 3028)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 2888)
    • Reads settings of System Certificates

      • AwesomeMiner.exe (PID: 2420)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: Awesome Miner
Author: IntelliBreeze Software AB
Keywords: Installer
Comments: This installer database contains the logic and data required to install Awesome Miner.
Template: Intel;1033
RevisionNumber: {0647ACE6-9DAC-4436-A0AA-858F6651E14A}
CreateDate: 2020:02:06 19:18:16
ModifyDate: 2020:02:06 19:18:16
Pages: 200
Words: 2
Software: Windows Installer XML Toolset (3.11.1.2318)
Security: Read-only recommended
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
8
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe no specs msiexec.exe msiexec.exe no specs vssvc.exe no specs msiexec.exe no specs msiexec.exe no specs intellibreeze.maintenance.service.exe no specs awesomeminer.exe

Process information

PID
CMD
Path
Indicators
Parent process
604C:\Windows\system32\MsiExec.exe -Embedding C88C578E27B72405A7742763D0CEA4A1C:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2408C:\Windows\system32\vssvc.exeC:\Windows\system32\vssvc.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2420"C:\Program Files\Awesome Miner\AwesomeMiner.exe" C:\Program Files\Awesome Miner\AwesomeMiner.exe
MsiExec.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Awesome Miner
Exit code:
0
Version:
7.3.1.0
Modules
Images
c:\program files\awesome miner\awesomeminer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2756C:\Windows\system32\MsiExec.exe -Embedding 81DC8CA0DBFCFC5E64A1A05253B12417 M Global\MSI0000C:\Windows\system32\MsiExec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2888C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3028C:\Windows\system32\MsiExec.exe -Embedding 4938B251032243DCCFA45C536EC1DC81 CC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3120"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\AwesomeMiner.msi"C:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3604"C:\Program Files\Awesome Miner\IntelliBreeze.Maintenance.Service.exe"C:\Program Files\Awesome Miner\IntelliBreeze.Maintenance.Service.exeservices.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Description:
IntelliBreeze.Maintenance.Service
Exit code:
0
Version:
7.3.1.0
Modules
Images
c:\program files\awesome miner\intellibreeze.maintenance.service.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
1 358
Read events
1 015
Write events
331
Delete events
12

Modification events

(PID) Process:(3120) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2888) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
40000000000000002AD032F4A9BBD601480B000090090000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2888) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
40000000000000002AD032F4A9BBD601480B000090090000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2888) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
43
(PID) Process:(2888) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
400000000000000010B97CF4A9BBD601480B000090090000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2888) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
40000000000000006A1B7FF4A9BBD601480B0000A8020000E803000001000000000000000000000067FD2F3D43EBF64298466201380DC1B40000000000000000
(PID) Process:(2408) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000D2A488F4A9BBD60168090000BC030000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2408) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000D2A488F4A9BBD6016809000090080000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2408) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000D2A488F4A9BBD60168090000CC0B0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2408) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000D2A488F4A9BBD6016809000020080000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
Executable files
57
Suspicious files
4
Text files
38
Unknown types
14

Dropped files

PID
Process
Filename
Type
3120msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI2AA0.tmp
MD5:
SHA256:
2888msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
2888msiexec.exeC:\Windows\Installer\195a4b.msi
MD5:
SHA256:
2888msiexec.exeC:\Users\admin\AppData\Local\Temp\~DF3C51E9BBEB9C2F63.TMP
MD5:
SHA256:
2408vssvc.exeC:
MD5:
SHA256:
2888msiexec.exeC:\Windows\Installer\195a4c.ipibinary
MD5:
SHA256:
2888msiexec.exeC:\Windows\Installer\MSI60A4.tmpbinary
MD5:
SHA256:
2888msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{3d2ffd67-eb43-42f6-9846-6201380dc1b4}_OnDiskSnapshotPropbinary
MD5:
SHA256:
2888msiexec.exeC:\Program Files\Awesome Miner\AwesomeMiner.exeexecutable
MD5:48C3533B47C7D9A237E73E3634F96A0C
SHA256:9BE0703DDE08FE326D825C0B542D456A9757E0B78B63991DB8FEA362098286DA
2888msiexec.exeC:\Program Files\Awesome Miner\alarm.wavwav
MD5:52BECF91C1B9634604F19EA04CED0B57
SHA256:22ADB4043B054EF31BC48BDAD408DDEB77F9B96AACA2D85D1E05208213784090
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
16
DNS requests
15
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2420
AwesomeMiner.exe
GET
301
172.67.69.193:80
http://www.zpool.ca/api/status
US
malicious
2420
AwesomeMiner.exe
GET
200
104.26.1.148:8080
http://api.zergpool.com:8080/api/status
US
text
38.1 Kb
suspicious
2420
AwesomeMiner.exe
GET
200
198.199.107.89:80
http://api.blazepool.com/s.json
US
text
9.72 Kb
unknown
2420
AwesomeMiner.exe
GET
302
198.199.107.89:80
http://api.blazepool.com/status
US
html
154 b
unknown
2420
AwesomeMiner.exe
GET
200
147.135.97.224:80
http://blockmasters.co/api/status
US
text
6.50 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2420
AwesomeMiner.exe
188.165.229.135:443
www.coincalculators.io
OVH SAS
FR
unknown
2420
AwesomeMiner.exe
143.204.201.24:443
5aozpdg9s2.execute-api.us-east-1.amazonaws.com
US
suspicious
2420
AwesomeMiner.exe
104.26.4.95:443
miningpoolhub.com
Cloudflare Inc
US
unknown
2420
AwesomeMiner.exe
99.86.7.109:443
www.awesomeminer.com
AT&T Services, Inc.
US
malicious
2420
AwesomeMiner.exe
172.67.69.193:80
www.zpool.ca
US
unknown
2420
AwesomeMiner.exe
104.26.12.88:443
whattomine.com
Cloudflare Inc
US
unknown
2420
AwesomeMiner.exe
50.220.121.209:443
prohashing.com
Comcast Cable Communications, LLC
US
unknown
2420
AwesomeMiner.exe
198.199.107.89:80
api.blazepool.com
Digital Ocean, Inc.
US
unknown
2420
AwesomeMiner.exe
147.135.97.224:80
blockmasters.co
OVH SAS
US
unknown
2420
AwesomeMiner.exe
172.67.69.193:443
www.zpool.ca
US
unknown

DNS requests

Domain
IP
Reputation
www.coincalculators.io
  • 188.165.229.135
malicious
www.awesomeminer.com
  • 99.86.7.109
  • 99.86.7.110
  • 99.86.7.126
  • 99.86.7.39
malicious
5aozpdg9s2.execute-api.us-east-1.amazonaws.com
  • 143.204.201.24
  • 143.204.201.49
  • 143.204.201.48
  • 143.204.201.90
malicious
whattomine.com
  • 104.26.12.88
  • 104.26.13.88
  • 172.67.68.82
whitelisted
api2.nicehash.com
  • 104.17.254.46
  • 104.17.255.46
suspicious
miningpoolhub.com
  • 104.26.4.95
  • 172.67.70.41
  • 104.26.5.95
whitelisted
prohashing.com
  • 50.220.121.209
malicious
api.blazepool.com
  • 198.199.107.89
unknown
www.ahashpool.com
  • 192.241.196.35
  • 128.199.93.104
suspicious
api.zergpool.com
  • 104.26.1.148
  • 104.26.0.148
  • 172.67.72.46
suspicious

Threats

Found threats are available for the paid subscriptions
1 ETPRO signatures available at the full report
Process
Message
AwesomeMiner.exe
Native library pre-loader is trying to load native SQLite library "C:\Program Files\Awesome Miner\x86\SQLite.Interop.dll"...