# Adventures of poking at a cpu miner

**URL:** <https://forum.0cd.xyz/t/adventures-of-poking-at-a-cpu-miner/267>\
**Category:** Blog\
**Tags:** windows, miner\
**Created:** [July 14, 2018, 8:27am UTC](https://forum.0cd.xyz/t/adventures-of-poking-at-a-cpu-miner/267 "2018-07-14T08:27:05Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dje4321](https://forum.0cd.xyz/user_avatar/forum.0cd.xyz/dje4321/32/7355_2.png) [@Dje4321](https://forum.0cd.xyz/u/Dje4321)\
**Post date:** [July 14, 2018, 8:27am UTC](https://forum.0cd.xyz/t/adventures-of-poking-at-a-cpu-miner/267/1 "2018-07-14T08:27:05Z")

</div>

Mostly ramblings of me poking at a cpu miner with a stick. Making of thread because someone might like it. Will sound a bit rambly because it is. Sorry

* * *

So my windows install has been running fairly hot and loud lately but whenever i end up open task manager it reveals that the cpu usage is at what would be normal for idle.

The dip is me opening task manager  
 ![cpu-miner-windows-sad](https://forum.0cd.xyz/uploads/default/original/2X/f/f72d3cdb495f65ffc2c4c71256b95baff1cb0466.PNG)

Copying taskmgr to the desktop and renaming it tricks whatever is running into thinking its now open. This means i can see the true culprit

 ![lel-cpu-miner-windows](https://forum.0cd.xyz/uploads/default/original/2X/b/b14aaecb773084d33db5527cdbf6734afbd8c96e.PNG)

So time to rename a random binary. Lets go with rufus

 ![rufus-taskmgr-cpu-miner](https://forum.0cd.xyz/uploads/default/original/2X/7/7a24cb67f57f8c6fed5b8716472d2bd5e097fc8e.PNG)  
And that works. So i now know whats its looking for when it comes to deciding when it should and shouldnt mine.

Lets poke at it with task manager some

 ![cpu-miner-notepad-priority](https://forum.0cd.xyz/uploads/default/original/2X/a/a7ca8a8b7f9104e33a7dcabdcb4e98b5820cbd6e.png)  
Well. Its atleast nice enough to set itself to below normal priority.

hmmm. Something fishy is going on with notepad for sure

 ![cpu-miner-fishy-dates-notepad](https://forum.0cd.xyz/uploads/default/original/2X/0/0af0fd5d469a7a027c69f320e24f3c5bc5aa14dc.PNG)  
Was last modified on 2015 but was created on 5/30/2018. And no notepad is not signed by microsoft

A few notes so far.

- Killed the process and removed notepad with a bit of good timing (process respawns). Notepad no longer runs outside of the Windows folder. Putting something else called notepad does not cause it to be ran. Placing the OG notepad file back into the folder causes it to be immediately ran. So some kind of finger printing must be going on here.
- Dumping the strings of the file doesnt reveal anything of interest. Mostly random garbage it thinks is strings and some product info from microsoft.
- Notepad.exe process just simply dissapears whenever something is ran with the filename “taskmgr.exe”

* * *

Thats about the extent of my knowledge/willingness to poke at it. Ive uploaded both the binary and a process dump incase anyone else wants to take a look at it. Also @Cavemanthe0ne. Found out why my laptop was always running hot in windows XD

[https://drive.google.com/open?id=1nrF6fCpdg7j8eDhmjtZf\_s9Pl3NJGYoP](https://drive.google.com/open?id=1nrF6fCpdg7j8eDhmjtZf_s9Pl3NJGYoP)

Im nuking my install from orbit so wont be able to provide much info to you (ok a backup from a fresh install but close enough)

---

<div class="post-metadata">

**Author:** ![Cavemanthe0ne](https://forum.0cd.xyz/user_avatar/forum.0cd.xyz/cavemanthe0ne/32/8893_2.png) [@Cavemanthe0ne](https://forum.0cd.xyz/u/Cavemanthe0ne)\
**Post date:** [July 14, 2018, 9:21am UTC](https://forum.0cd.xyz/t/adventures-of-poking-at-a-cpu-miner/267/2 "2018-07-14T09:21:40Z")

</div>

Somewhat confused but ok lol  
Also how did you mamage to get… Notepad malware? Then again not surprised lol  
Good that you found it though because would explain weird performance and all that

---

<div class="post-metadata">

**Author:** ![Dje4321](https://forum.0cd.xyz/user_avatar/forum.0cd.xyz/dje4321/32/7355_2.png) [@Dje4321](https://forum.0cd.xyz/u/Dje4321)\
**Post date:** [July 14, 2018, 9:23am UTC](https://forum.0cd.xyz/t/adventures-of-poking-at-a-cpu-miner/267/3 "2018-07-14T09:23:25Z")

</div>

> [@Cavemanthe0ne](#):
>
> Also how did you mamage to get… Notepad malware? Then again not surprised lol

Catsay gave it a look over and it wasnt notepad that was bad. Just something hiding as notepad

---

<div class="post-metadata">

**Author:** ![Cavemanthe0ne](https://forum.0cd.xyz/user_avatar/forum.0cd.xyz/cavemanthe0ne/32/8893_2.png) [@Cavemanthe0ne](https://forum.0cd.xyz/u/Cavemanthe0ne)\
**Post date:** [July 14, 2018, 9:25am UTC](https://forum.0cd.xyz/t/adventures-of-poking-at-a-cpu-miner/267/4 "2018-07-14T09:25:34Z")

</div>

… K  
_Personally I havent ever needed antimalware because a) if I’m doing something and I’m stupid enough to download malware then I’ll deal with it and b) I dont generally download anything with the remotest chance of being malware lol so this isnt something i delve into much usually 😛_

---

<div class="post-metadata">

**Author:** ![Dje4321](https://forum.0cd.xyz/user_avatar/forum.0cd.xyz/dje4321/32/7355_2.png) [@Dje4321](https://forum.0cd.xyz/u/Dje4321)\
**Post date:** [July 14, 2018, 9:27am UTC](https://forum.0cd.xyz/t/adventures-of-poking-at-a-cpu-miner/267/5 "2018-07-14T09:27:44Z")

</div>

> [@Cavemanthe0ne](#):
>
> if I’m doing something and I’m stupid enough to download malware then I’ll deal with it

Dealt with it by nuking the install from orbit

> [@Cavemanthe0ne](#):
>
> I dont generally download anything with the remotest chance of being malware

Same here. First malware ive had in 3-4 years

> [@Cavemanthe0ne](#):
>
> something i delve into much usually

I just wanted to poke at it and see whats what. Install was at the nuking period anyway and it needed to be done

---

<div class="post-metadata">

**Author:** ![Michael](https://forum.0cd.xyz/user_avatar/forum.0cd.xyz/michael/32/9677_2.png) [@Michael](https://forum.0cd.xyz/u/Michael)\
**Post date:** [July 14, 2018, 11:39am UTC](https://forum.0cd.xyz/t/adventures-of-poking-at-a-cpu-miner/267/6 "2018-07-14T11:39:39Z")

</div>

An update on this to keep it relevant. Catsay went through the memory dump and found the IP address and port of the server it is communicating with:

```auto
185.144.29.36:5450 

```

It is a VPS running Windows Server 2008 R2 in the Russian Federation hosted by [profiteserver.ru](http://profiteserver.ru) and It also turns out that the server has RDP and SMB open to the internet XD

And that it was using the XMRig miner with CyptoNight with the dump also containing the password for the miner.

```auto
XMRig 2.6.2
 built on May 6 2018 with GCC
 %d.%d.%d
 features: 64-bit AES

```

It has now also been reported to the VPS host for abuse and the ip address and memory signatures forwarded to blacklist so this can hopefully be caught by security software in future.

> [@catsay](#):
>
> I’ve reported it to [abuse@profiteserver.ru](mailto:abuse@profiteserver.ru) - it seems to be a russian VPS host.  
> Hopefully they are a legit company and not part of the cryptomining operation.
> 
> Additionally I’ve added the IP and some signatures of the memory to a few blacklists & AV lists which should soon make their way to AV vendors.

All together a pretty good result from a little bit of poking and snooping 😃

Sources:

> **[Adventures of poking at a cpu miner](https://forum.level1techs.com/t/adventures-of-poking-at-a-cpu-miner/129226/12?u=michaellindman)**
>
> Dumped the memory Working with minidump files is a bit more annoying than full dumps But found an IP address+Port it’s connecting to pretty fast: 185.144.29.36:5450 Hmm interesting, this should look familiar to any crypto miners \[2018-07-13...

> **[Adventures of poking at a cpu miner](https://forum.level1techs.com/t/adventures-of-poking-at-a-cpu-miner/129226/13?u=michaellindman)**
>
> So where is that IP you may ask? Chelyabinsk in the Russian Federation of course! ;; ANSWER SECTION: 36.29.144.185.in-addr.arpa. 3600 IN PTR vps.joko.xyz. ;; AUTHORITY SECTION: 29.144.185.in-addr.arpa. 172799 IN NS ...

> **[Adventures of poking at a cpu miner](https://forum.level1techs.com/t/adventures-of-poking-at-a-cpu-miner/129226/15?u=michaellindman)**
>
> I’ve reported it to abuse@profiteserver.ru - it seems to be a russian VPS host. Hopefully they are a legit company and not part of the cryptomining operation. Additionally I’ve added the IP and some signatures of the memory to a few blacklists &...
