Malware

MSIL/CoinMiner.ATJ (file analysis)

Malware Removal

The MSIL/CoinMiner.ATJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/CoinMiner.ATJ virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine MSIL/CoinMiner.ATJ?


File Info:

name: AD21849726A5A5D3B6B7.mlw
path: /opt/CAPEv2/storage/binaries/dddbf4a5ac45938db29e6051e58921cc853118befb6701b254dd488089fcaebf
crc32: B8D5EFEA
md5: ad21849726a5a5d3b6b7b6626a5009a5
sha1: 1509a4c75b2d0fc92ccef15485dacdfa55471ef1
sha256: dddbf4a5ac45938db29e6051e58921cc853118befb6701b254dd488089fcaebf
sha512: de49383d3eb8a87f7bfc9bad6ca7a482d520e62da7956ce772378e4362095704b0958651ddfc56ee83c060c1c4dc625404c7948cce9a304c1e884f44ce4a79a3
ssdeep: 48:64dg9TbndA9g1FXXCT/jBDLPNM1Zy2UqbScRBSz5nFCFiyB3iAZ4taUlSrX7IFKY:K9O9uB+BeyzQLSzCFxB3i2K4rXvzNt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BAC1A4219BE447B6FAB70AB1BCB35311067AFB518D378B2D1988610F6D263548922F62
sha3_384: 0b5cdefc969305efffc6208cc7cc9c6e97dcf289ea548619f0ed3bb0252b8516cb72a506141982b816bda4857619d323
ep_bytes: ff250020400000000000000000000000
timestamp: 2067-08-16 02:29:57

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: Windows1
FileVersion: 1.0.0.0
InternalName: dllhost.exe
LegalCopyright: Copyright © 2018
LegalTrademarks:
OriginalFilename: dllhost.exe
ProductName: Windows1
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/CoinMiner.ATJ also known as:

MicroWorld-eScanGen:Variant.Bulz.213348
FireEyeGen:Variant.Bulz.213348
ALYacGen:Variant.Bulz.213348
K7AntiVirusTrojan ( 0053b9231 )
K7GWTrojan ( 0053b9231 )
Cybereasonmalicious.726a5a
ESET-NOD32a variant of MSIL/CoinMiner.ATJ
APEXMalicious
BitDefenderGen:Variant.Bulz.213348
Ad-AwareGen:Variant.Bulz.213348
EmsisoftGen:Variant.Bulz.213348 (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Bulz.213348
AviraHEUR/AGEN.1240962
ArcabitTrojan.Bulz.D34164
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.CoinMiner.C3254992
MAXmalware (ai score=82)
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/CoinMiner.ATJ!tr
BitDefenderThetaGen:NN.ZemsilF.34182.am0@ay9!F2l
CrowdStrikewin/malicious_confidence_60% (W)

How to remove MSIL/CoinMiner.ATJ?

MSIL/CoinMiner.ATJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment