PUA

Multi:BitCoinMiner-C [PUP] (file analysis)

Malware Removal

The Multi:BitCoinMiner-C [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Multi:BitCoinMiner-C [PUP] virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Multi:BitCoinMiner-C [PUP]?


File Info:

name: 3439F13F28BAA6A49E4D.mlw
path: /opt/CAPEv2/storage/binaries/a4f6728d87f675fd768ee9ca9956d80bbe7af873ecada813cafb27cc062ad765
crc32: 4B0B7339
md5: 3439f13f28baa6a49e4dc6d29bfa283b
sha1: 8a10e115c3ef4fb92634b0d50553d1844bc49c0d
sha256: a4f6728d87f675fd768ee9ca9956d80bbe7af873ecada813cafb27cc062ad765
sha512: 680f15cae7aa2d21438eab531558f235e2633a61409331d476885aa9ad8abdd00dfd58fef70c0b55a335c684c061dc48c3b329bd4fb0da45e40a556df7e1c61d
ssdeep: 24576:d/A005HEzkTONKVgVZLgyK/UQjKDAm709i+pJcxW3nPQx:dNAkzkTOGksyK/P2DAmw9FHcxW3Y
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1F8350868EA4750F5DE271830869BF37F4B31BA01C175DCB2FFA97A48B933D62150A612
sha3_384: bc23aa1acc178ed8d0d33434f75fbc4568e7560ae3280896e35766179b8500b4d0966a3a004a420b5efe87d5bb8a1889
ep_bytes: 83ec1cc7042401000000ff15c8f55000
timestamp: 1970-01-13 20:54:32

Version Info:

0: [No Data]

Multi:BitCoinMiner-C [PUP] also known as:

Elasticmalicious (high confidence)
DrWebTool.BtcMine.782
FireEyeGeneric.mg.3439f13f28baa6a4
McAfeeArtemis!3439F13F28BA
CylanceUnsafe
ZillyaTool.BitCoinMiner.Win32.40400
AlibabaRiskWare:Win32/Miners.fa8b4c52
K7GWTrojan ( 0053a0551 )
K7AntiVirusTrojan ( 0053a0551 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/CoinMiner.BF potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002H0CL321
Kasperskynot-a-virus:HEUR:RiskTool.Win32.BitCoinMiner.gen
AvastMulti:BitCoinMiner-C [PUP]
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.PUP.th
SophosBitcoin Miner (PUA)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Application.Agent.N3W3DK
AviraPUA/CoinMiner.Gen
GridinsoftRansom.Win32.Gen.sa
ViRobotAdware.Coinminer.1079808
MicrosoftPUA:Win32/CoinMiner
MalwarebytesPUP.Optional.BitCoinMiner
RisingHackTool.CoinMiner!1.CA68 (CLASSIC)
IkarusPUA.CoinMiner
FortinetRiskware/Miner
AVGMulti:BitCoinMiner-C [PUP]

How to remove Multi:BitCoinMiner-C [PUP]?

Multi:BitCoinMiner-C [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment