SYMBOLCOMMON_NAMEaka. SYNONYMS
win.coinminer (Back to overview)

Coinminer

VTCollection    

Coinminer is an unwanted malicious software which uses the victim's computational power (CPU and RAM mostly) to mine for coins (for example Monero or Zcash). The malware achieves persistence by adding one of the opensource miners on startup without the victim's consensus. Most sophisticated coin miners use timer settings or cap the CPU usage in order to remain stealthy.

References
2026-07-24 ⋅ AhnLab ⋅ ASEC
Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN
XMRIG Coinminer GoToHTTP HackBrowserData MimiKatz Monero Miner VShell xmrig Larva-26009
2022-09-15 ⋅ Sekoia ⋅ Threat & Detection Research Team
PrivateLoader: the loader of the prevalent ruzki PPI service
Agent Tesla Coinminer DanaBot DCRat Eternity Stealer Glupteba Mars Stealer NetSupportManager RAT Nymaim Nymaim2 Phoenix Keylogger PrivateLoader Raccoon RedLine Stealer SmokeLoader Socelars STOP Vidar YTStealer
2022-08-30 ⋅ Cisco ⋅ Vanja Svajcer
ModernLoader delivers multiple stealers, cryptominers and RATs
Coinminer DCRat ModernLoader RedLine Stealer SapphireMiner SystemBC
2022-01-01 ⋅ Triskele Labs ⋅ Brecht Snijders
Investigating a Monero Coin Miner
Coinminer
2021-01-18 ⋅ The DFIR Report ⋅ The DFIR Report
All That for a Coinminer?
Coinminer Monero Miner
2018-01-17 ⋅ Malwarebytes ⋅ hasherezade
A coin miner with a “Heaven’s Gate”
Coinminer
2018-01-01 ⋅ Malwarebytes ⋅ hasherezade
A coin miner with a “Heaven’s Gate”
Coinminer
2017-07-30 ⋅ Secrary Blog ⋅ Secrary
CoinMiner
Coinminer
Yara Rules
[TLP:WHITE] win_coinminer_auto (20260917 | Detects win.coinminer.)
rule win_coinminer_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.coinminer."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.coinminer"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 57 41 752f a0???????? }
            // n = 4, score = 100
            //   57                   | push                edi
            //   41                   | inc                 ecx
            //   752f                 | jne                 0x31
            //   a0????????           |                     

        $sequence_1 = { ffd5 48 8d87af010000 80207f 8060287f 4c }
            // n = 6, score = 100
            //   ffd5                 | call                ebp
            //   48                   | dec                 eax
            //   8d87af010000         | lea                 eax, [edi + 0x1af]
            //   80207f               | and                 byte ptr [eax], 0x7f
            //   8060287f             | and                 byte ptr [eax + 0x28], 0x7f
            //   4c                   | dec                 esp

        $sequence_2 = { 8b8554ffffff 8975e4 85c9 7504 85c0 7451 85f6 }
            // n = 7, score = 100
            //   8b8554ffffff         | mov                 eax, dword ptr [ebp - 0xac]
            //   8975e4               | mov                 dword ptr [ebp - 0x1c], esi
            //   85c9                 | test                ecx, ecx
            //   7504                 | jne                 6
            //   85c0                 | test                eax, eax
            //   7451                 | je                  0x53
            //   85f6                 | test                esi, esi

        $sequence_3 = { a2???????? 5f d024e2 37 90 3402 ed }
            // n = 7, score = 100
            //   a2????????           |                     
            //   5f                   | pop                 edi
            //   d024e2               | shl                 byte ptr [edx], 1
            //   37                   | aaa                 
            //   90                   | nop                 
            //   3402                 | xor                 al, 2
            //   ed                   | in                  eax, dx

        $sequence_4 = { 57 f30f7f442440 b920000000 be???????? f30f6f05???????? 8dbc24b8040000 }
            // n = 6, score = 100
            //   57                   | push                edi
            //   f30f7f442440         | movdqu              xmmword ptr [esp + 0x40], xmm0
            //   b920000000           | mov                 ecx, 0x20
            //   be????????           |                     
            //   f30f6f05????????     |                     
            //   8dbc24b8040000       | lea                 edi, [esp + 0x4b8]

        $sequence_5 = { 5d c3 8b45e4 0fb70c50 8b45dc }
            // n = 5, score = 100
            //   5d                   | pop                 ebp
            //   c3                   | ret                 
            //   8b45e4               | mov                 eax, dword ptr [ebp - 0x1c]
            //   0fb70c50             | movzx               ecx, word ptr [eax + edx*2]
            //   8b45dc               | mov                 eax, dword ptr [ebp - 0x24]

        $sequence_6 = { af f1 b28e 2c48 dc11 }
            // n = 5, score = 100
            //   af                   | scasd               eax, dword ptr es:[edi]
            //   f1                   | int1                
            //   b28e                 | mov                 dl, 0x8e
            //   2c48                 | sub                 al, 0x48
            //   dc11                 | fcom                qword ptr [ecx]

        $sequence_7 = { 50 51 e8???????? 83c408 84c0 7559 }
            // n = 6, score = 100
            //   50                   | push                eax
            //   51                   | push                ecx
            //   e8????????           |                     
            //   83c408               | add                 esp, 8
            //   84c0                 | test                al, al
            //   7559                 | jne                 0x5b

        $sequence_8 = { e8???????? 83c408 833d????????00 0f8474010000 }
            // n = 4, score = 100
            //   e8????????           |                     
            //   83c408               | add                 esp, 8
            //   833d????????00       |                     
            //   0f8474010000         | je                  0x17a

        $sequence_9 = { 50 ff742420 ff15???????? 83c604 83fe0c 7cd4 }
            // n = 6, score = 100
            //   50                   | push                eax
            //   ff742420             | push                dword ptr [esp + 0x20]
            //   ff15????????         |                     
            //   83c604               | add                 esi, 4
            //   83fe0c               | cmp                 esi, 0xc
            //   7cd4                 | jl                  0xffffffd6

    condition:
        7 of them and filesize < 1523712
}
Download all Yara Rules