HWMonitor Download Compromised

Observable: CPUID Downloads with Malware
Observable Type: Supply Chain compromise (?)

Details: Users reporting getting a malware executable while downloading HWMonitor software from the official CPUID website

A discussion on Reddit from an everyday user, with some analysis in the comments: Reddit - Please wait for verification

Some press coverage: https://cybernews.com/security/cpuid-hwmonitor-hwinfo-cpuz-deliver-malware/

3 Likes

User Hattix has this analysis:

Quick analysis…
Download link on https://www.cpuid.com/softwares/hwmonitor.html

goes to httpx://pub-45c2577dbd174292a02137c18e7b1b5a.r2.dev/hwmonitor/HWiNFO_Monitor_Setup.exe which is obviously unusual.

This has the description “Установка — HWiNFO Monitor, версия 1.63” in it. Now I’m pretty sure CPUID is based out of France, so the presence of Russian there is not great. The term “HWiNFO” is not right here either, it’s a completely different tool.

The file is built with a customised “wrapped” Innosetup often used by malware, making it difficult to extract. “Real” Hwmonitor just uses regular InnoSetup and can be extracted with simple and common tools.

Their site has been hacked is the simplest explanation.

1 Like

It’s apparently quite similar to this:

Per:

VT links for samples:

1 Like

IoCs

(Per VXUG)

Portable HWMonitor Installer (1.63):
3d91f442ddc055e19e3710482e1605836c799249dacd43d99843257a3affd2d2

Fake CRYPTBASE.dll:
a27df06c7167eced1ddaeb8adccaa5f60500f52bc7030389eed2a0903cdf8286

Trojanized HWMonitor:
02db6764d1f13b837b0a525e5931bdbc67e7a2a4d071e849c7e087255d4a2d5b

Can't remember what this file did:
4547f3c7854413f9ae0806c51564684b796399bea0511a8b6c4d63a136c8ad56

Can't remember what this file did (1):
f633b48d5281709bcf3b1d8f54703792e51bb38ab507e9caa9c2fbe79b78aa53

Can't remember what this file did (2):
058f45b11fdd43ef51571577ec2ed9bcabe039a6615d05900aeb3655e9cec7e9

.cs file:
788d3f14ff6a701b114e0b40990379c0302e26c1bbbce22a7ee5c872c7df1d1f

.NET assembly:
47c17003d58cd609bff8ab788b51803b3b0de0648b40cd4e5591948298914753

C2:
https://welcome[.]supp0v3[.]com/d/callback
1 Like

Great work @stroz! I was just wondering if we need a thread, and here it is! It’s working!

2 Likes

Powermax is also in the mix, it seems.

Do we like these? Do we care?

1 Like