Trojan

Trojan:Win32/CoinMiner.DA information

Malware Removal

The Trojan:Win32/CoinMiner.DA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/CoinMiner.DA virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/CoinMiner.DA?


File Info:

name: DF25DDF3A4D144489318.mlw
path: /opt/CAPEv2/storage/binaries/b48762de400a5e4194be0521cd740f6f6fb8a3f54b1fbb02d388b2ff3dc907d3
crc32: ABE6C189
md5: df25ddf3a4d144489318804213b479e0
sha1: 1d2e13e284936bdfbd959bb5e32884f70d2659a1
sha256: b48762de400a5e4194be0521cd740f6f6fb8a3f54b1fbb02d388b2ff3dc907d3
sha512: a2374a3d3619e0d3b74625390f0afcfd25ea7675be3b0969a228bdd07e108c327724133783fcd0f6532a6f87ba3d09a106db4e2d106180f060b8a8bb9f74e1fc
ssdeep: 24576:RGNbGFT18CtnaQH2FgDgJ4O74L/ipEB29ZNxiEBmI6BE04+sUOav:ybGgJT74o1ZH1BmIZrUOa
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T11B65F100FA839576E027057029BEA66A177C7E200F5199EFA3D43FED9E322C15735B62
sha3_384: 67a2da19e7a2ed4c4ec01fce9a7d7802e7705bb52f1aea2919405fbd67985436f22c11a5a856322cc5ea27dfba959506
ep_bytes: 558bec837d0c017505e829060000ff75
timestamp: 2017-12-30 08:57:21

Version Info:

0: [No Data]

Trojan:Win32/CoinMiner.DA also known as:

BkavW32.AIDetectMalware
LionicAdware.Win32.Generic.2!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Midie.80182
FireEyeGeneric.mg.df25ddf3a4d14448
CAT-QuickHealPUA.AgentPMF.S18904576
SkyhighBehavesLike.Win32.CoinMiner.tt
ALYacGen:Variant.Midie.80182
Cylanceunsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/grayware_confidence_100% (D)
AlibabaMalware:Win32/km_2c16e66.None
SymantecMiner.Bitcoinminer
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Adware.Adposhel.BH
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Genericrxdv-9827019-0
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderGen:Variant.Midie.80182
NANO-AntivirusRiskware.Win32.BitMiner.exfelt
SUPERAntiSpywarePUP.CoinMiner/Variant
AvastWin32:CryptoMiner-AT [Miner]
TencentTrojan.Win32.Coinminer.yg
TACHYONTrojan/W32.Snovir.1495552
EmsisoftAdware.Generic (A)
F-SecurePotentialRisk.PUA/BitcoinMiner.Gen7
DrWebTrojan.BtcMine.2547
Trapminemalicious.high.ml.score
SophosXMRig Miner (PUA)
IkarusPUA.CoinMiner
JiangminRiskTool.BitMiner.aiwl
WebrootW64.Adware.Gen
VaristW32/S-56066cff!Eldorado
AviraPUA/BitcoinMiner.Gen7
Antiy-AVLGrayWare[AdWare]/Win32.CoinMiner.fr
MicrosoftTrojan:Win32/CoinMiner.DA
XcitiumApplication.Win32.Coinminer.FR@7h5w7g
ArcabitTrojan.Midie.D13936
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Generic
GDataGen:Variant.Midie.80182
GoogleDetected
AhnLab-V3Unwanted/Win32.BitMiner.R219415
McAfeeCoinMiner-FDX
MAXmalware (ai score=83)
VBA32BScope.Malware-Cryptor.Kidep
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/GdSda.A
RisingHackTool.CoinMiner!1.B033 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Adposhel.C
FortinetRiskware/CoinMiner
AVGWin32:CryptoMiner-AT [Miner]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/CoinMiner.DA?

Trojan:Win32/CoinMiner.DA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment