Trojan

What is “Trojan.CoinMiner.UPX”?

Malware Removal

The Trojan.CoinMiner.UPX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.CoinMiner.UPX virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.CoinMiner.UPX?


File Info:

name: 00B54269E9C51495110A.mlw
path: /opt/CAPEv2/storage/binaries/68a2af6945a719033fd578d0d9722661cf60c134111926b8993e50c0c073a9bf
crc32: 7229D022
md5: 00b54269e9c51495110adc08db0cb452
sha1: b434e33d07ff3b06b79506c2a767e7de72ed3230
sha256: 68a2af6945a719033fd578d0d9722661cf60c134111926b8993e50c0c073a9bf
sha512: a7b3a66be833043dd0561da8caab23597f94634b9be9f0936400f37b20a87cdaee0a48b8a84c04eadf99539efc8cd30f6f7833f815a445feda9021674c7b0167
ssdeep: 3072:SOkTGChSDMOQe6nPcKz4LIM4gjgEkLmjXlYZfpinBtsz:8TGASYBnPcKPMLLj1YtpK6z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F9A3024DF3065137E38747728D7A6F5DEA1FA7082DA9942A0F8CD34338762E18E316A5
sha3_384: f79a85baca78cb6a5a818f899c87f7a8f176499321ad178b6958d1faca710aa051c79b0f71ddb5124be6da7d6fa8cecf
ep_bytes: 60be000043008dbe0010fdff57eb0b90
timestamp: 2023-07-25 02:53:34

Version Info:

FileDescription: Windows Initialization
OriginalFilename: wininit.exe
Translation: 0xffff 0x0000

Trojan.CoinMiner.UPX also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Heur.Mint.Zard.25
ClamAVWin.Dropper.Tiggre-9845940-0
FireEyeGeneric.mg.00b54269e9c51495
McAfeeArtemis!00B54269E9C5
Cylanceunsafe
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/CoinMiner.a88932e8
Cybereasonmalicious.9e9c51
BitDefenderThetaGen:NN.ZexaF.36318.gmLfaKrX8Lni
CyrenW32/ABRisk.DNDH-9169
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/CoinMiner.CIB
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Generic
BitDefenderGen:Heur.Mint.Zard.25
AvastWin32:TrojanX-gen [Trj]
EmsisoftGen:Heur.Mint.Zard.25 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPREGen:Heur.Mint.Zard.25
TrendMicroTROJ_GEN.R002C0PGP23
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.CoinMiner
GDataWin32.Trojan-Stealer.BlackMoon.D
JiangminTrojanDropper.Injector.bgng
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Blamon.a
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Mint.Zard.25
ZoneAlarmUDS:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
VBA32TScope.Malware-Cryptor.SB
ALYacGen:Heur.Mint.Zard.25
MAXmalware (ai score=89)
MalwarebytesTrojan.CoinMiner.UPX
TrendMicro-HouseCallTROJ_GEN.R002C0PGP23
TencentWin32.Trojan.Generic.Ugil
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.WP!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.CoinMiner.UPX?

Trojan.CoinMiner.UPX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment