SYMBOLCOMMON_NAMEaka. SYNONYMS
win.monero_miner (Back to overview)

Monero Miner

aka: CoinMiner
VTCollection    

According to ESET, first seen in-the-wild on 26th May, 2017, the malicious mining software is a fork of a legitimate open source Monero CPU miner called xmrig.

References
2026-07-24 ⋅ AhnLab ⋅ ASEC
Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN
XMRIG Coinminer GoToHTTP HackBrowserData MimiKatz Monero Miner VShell xmrig Larva-26009
2022-09-06 ⋅ AT&T ⋅ Ofer Caspi
Shikitega - New stealthy malware targeting Linux
BotenaGo EnemyBot Meterpreter Monero Miner
2022-08-08 ⋅ AhnLab ⋅ ASEC Analysis Team
Monero CoinMiner Being Distributed via Webhards
Monero Miner
2021-10-24 ⋅ Sophos ⋅ Sean Gallagher
Node poisoning: hijacked package delivers coin miner and credential-stealing backdoor
DanaBot Monero Miner
2021-01-18 ⋅ The DFIR Report ⋅ The DFIR Report
All That for a Coinminer?
Coinminer Monero Miner
2017-09-28 ⋅ ESET Research ⋅ Michal Poslušný, Peter Kálnai
Money‑making machine: Monero‑mining malware
Monero Miner
Yara Rules
[TLP:WHITE] win_monero_miner_auto (20260917 | Detects win.monero_miner.)
rule win_monero_miner_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.monero_miner."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.monero_miner"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { a801 0f8481fcffff e9???????? 89c3 31c0 e9???????? bb1b000000 }
            // n = 7, score = 100
            //   a801                 | test                al, 1
            //   0f8481fcffff         | je                  0xfffffc87
            //   e9????????           |                     
            //   89c3                 | mov                 ebx, eax
            //   31c0                 | xor                 eax, eax
            //   e9????????           |                     
            //   bb1b000000           | mov                 ebx, 0x1b

        $sequence_1 = { e8???????? 817b3c00010000 0f843e020000 8d5308 8954242c 8b7314 85f6 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   817b3c00010000       | cmp                 dword ptr [ebx + 0x3c], 0x100
            //   0f843e020000         | je                  0x244
            //   8d5308               | lea                 edx, [ebx + 8]
            //   8954242c             | mov                 dword ptr [esp + 0x2c], edx
            //   8b7314               | mov                 esi, dword ptr [ebx + 0x14]
            //   85f6                 | test                esi, esi

        $sequence_2 = { c7430400000000 c7431800000000 894310 b802000000 66894308 8d4314 89430c }
            // n = 7, score = 100
            //   c7430400000000       | mov                 dword ptr [ebx + 4], 0
            //   c7431800000000       | mov                 dword ptr [ebx + 0x18], 0
            //   894310               | mov                 dword ptr [ebx + 0x10], eax
            //   b802000000           | mov                 eax, 2
            //   66894308             | mov                 word ptr [ebx + 8], ax
            //   8d4314               | lea                 eax, [ebx + 0x14]
            //   89430c               | mov                 dword ptr [ebx + 0xc], eax

        $sequence_3 = { 8b4c2424 c7042400000000 89442404 8b442420 e8???????? 85c0 89c3 }
            // n = 7, score = 100
            //   8b4c2424             | mov                 ecx, dword ptr [esp + 0x24]
            //   c7042400000000       | mov                 dword ptr [esp], 0
            //   89442404             | mov                 dword ptr [esp + 4], eax
            //   8b442420             | mov                 eax, dword ptr [esp + 0x20]
            //   e8????????           |                     
            //   85c0                 | test                eax, eax
            //   89c3                 | mov                 ebx, eax

        $sequence_4 = { e9???????? 8db424c0030000 8d1452 814c241000100400 8d14d6 8974242c c70207000000 }
            // n = 7, score = 100
            //   e9????????           |                     
            //   8db424c0030000       | lea                 esi, [esp + 0x3c0]
            //   8d1452               | lea                 edx, [edx + edx*2]
            //   814c241000100400     | or                  dword ptr [esp + 0x10], 0x41000
            //   8d14d6               | lea                 edx, [esi + edx*8]
            //   8974242c             | mov                 dword ptr [esp + 0x2c], esi
            //   c70207000000         | mov                 dword ptr [edx], 7

        $sequence_5 = { 8d83c8000000 c7442404???????? 891424 89442410 8b442464 057c010000 8944240c }
            // n = 7, score = 100
            //   8d83c8000000         | lea                 eax, [ebx + 0xc8]
            //   c7442404????????     |                     
            //   891424               | mov                 dword ptr [esp], edx
            //   89442410             | mov                 dword ptr [esp + 0x10], eax
            //   8b442464             | mov                 eax, dword ptr [esp + 0x64]
            //   057c010000           | add                 eax, 0x17c
            //   8944240c             | mov                 dword ptr [esp + 0xc], eax

        $sequence_6 = { 85d2 0f84bafeffff e8???????? 85c0 0f84adfeffff 83c501 8b0e }
            // n = 7, score = 100
            //   85d2                 | test                edx, edx
            //   0f84bafeffff         | je                  0xfffffec0
            //   e8????????           |                     
            //   85c0                 | test                eax, eax
            //   0f84adfeffff         | je                  0xfffffeb3
            //   83c501               | add                 ebp, 1
            //   8b0e                 | mov                 ecx, dword ptr [esi]

        $sequence_7 = { eb8c 8b5e04 83fbff 0f8438fbffff 83eb01 85db 895e04 }
            // n = 7, score = 100
            //   eb8c                 | jmp                 0xffffff8e
            //   8b5e04               | mov                 ebx, dword ptr [esi + 4]
            //   83fbff               | cmp                 ebx, -1
            //   0f8438fbffff         | je                  0xfffffb3e
            //   83eb01               | sub                 ebx, 1
            //   85db                 | test                ebx, ebx
            //   895e04               | mov                 dword ptr [esi + 4], ebx

        $sequence_8 = { 8b542404 8906 09ca 8b8be8a14700 895604 8bb42428010000 8d34ce }
            // n = 7, score = 100
            //   8b542404             | mov                 edx, dword ptr [esp + 4]
            //   8906                 | mov                 dword ptr [esi], eax
            //   09ca                 | or                  edx, ecx
            //   8b8be8a14700         | mov                 ecx, dword ptr [ebx + 0x47a1e8]
            //   895604               | mov                 dword ptr [esi + 4], edx
            //   8bb42428010000       | mov                 esi, dword ptr [esp + 0x128]
            //   8d34ce               | lea                 esi, [esi + ecx*8]

        $sequence_9 = { 8b442430 01ee 8b6c2454 11d7 31f2 31f8 89542430 }
            // n = 7, score = 100
            //   8b442430             | mov                 eax, dword ptr [esp + 0x30]
            //   01ee                 | add                 esi, ebp
            //   8b6c2454             | mov                 ebp, dword ptr [esp + 0x54]
            //   11d7                 | adc                 edi, edx
            //   31f2                 | xor                 edx, esi
            //   31f8                 | xor                 eax, edi
            //   89542430             | mov                 dword ptr [esp + 0x30], edx

    condition:
        7 of them and filesize < 1425408
}
Download all Yara Rules