Trojan

Trojan:Win32/Coinminer.MA!MTB (file analysis)

Malware Removal

The Trojan:Win32/Coinminer.MA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Coinminer.MA!MTB virus can do?

  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Deletes executed files from disk

How to determine Trojan:Win32/Coinminer.MA!MTB?


File Info:

name: F97B28447DA615D1A875.mlw
path: /opt/CAPEv2/storage/binaries/b2ab6563e98011958deeadd839dbaceb2f61065a8bb27fc8652da31f0c33462b
crc32: 39EA2364
md5: f97b28447da615d1a87529c5c7d88393
sha1: 2c519edbdcc0b225ca4e0d8f568b1a4242c62221
sha256: b2ab6563e98011958deeadd839dbaceb2f61065a8bb27fc8652da31f0c33462b
sha512: 292b433f984f5742acf388725b4b03b6988a5509e14200d78eb69154266170019d83604a58952ea7d366b51ee1c93c9eea611d5e5bf50b8d9c314189c4d0a247
ssdeep: 3072:6N43tke6NUoXbeYnKAlpCU4XRvevYX+Fgc8i1Oo8AOnXc:65e6NXb+AlYlh2vYXYx1zTMX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T187248D203AC0C0B2E673027516F8DBB25A7DBD725B6199CBB7E40B4E1A741D19B31B63
sha3_384: f1457ce4777840ec95f6cc8e4cfdd01ebed45ac7a9c3f5cef8f7bba4d51f52610990d57d3b72e27eef5551e668f824cd
ep_bytes: e802890000e9000000006a146880a042
timestamp: 2014-08-06 21:46:33

Version Info:

0: [No Data]

Trojan:Win32/Coinminer.MA!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.m94N
MicroWorld-eScanGen:Heur.Mint.Murphy.23
ClamAVWin.Malware.Johnnie-6876867-0
FireEyeGeneric.mg.f97b28447da615d1
CAT-QuickHealTrojan.Maener.A5
ALYacGen:Heur.Mint.Murphy.23
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.CoinMiner.Win32.669
SangforMiner.Win32.Mint_2.se2
K7AntiVirusCryptoMiner ( 0055e3fc1 )
AlibabaMalware:Win32/km_2cee3.None
K7GWCryptoMiner ( 0055e3fc1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/A-ad3710b8!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/CoinMiner.CDD
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Banker.Win32.CoinMiner.f
BitDefenderGen:Heur.Mint.Murphy.23
NANO-AntivirusTrojan.Win32.CoinMiner.ddpctq
SUPERAntiSpywareTrojan.Agent/Gen-Graftor
AvastWin32:SvcMiner-F [Trj]
TencentTrojan.Win32.CoinMiner.ha
SophosTroj/AutoG-CE
F-SecureTrojan.TR/Graftor.pqifa
DrWebTrojan.MinerENT.3
VIPREGen:Heur.Mint.Murphy.23
TrendMicroCoinminer.Win32.MALXMR.SMJA
McAfee-GW-EditionBehavesLike.Win32.Trojan.dm
Trapminemalicious.moderate.ml.score
EmsisoftGen:Heur.Mint.Murphy.23 (B)
IkarusTrojan.Win32.Maener
GDataWin32.Trojan.Coinminer.CB
JiangminTrojan/Banker.CoinMiner.b
AviraTR/Graftor.pqifa
MAXmalware (ai score=88)
Antiy-AVLTrojan[Banker]/Win32.CoinMiner
XcitiumTrojWare.Win32.Graftor.PQIF@5e7luk
ArcabitTrojan.Mint.Murphy.23
ViRobotTrojan.Win.Z.Coinminer.219648.MF
ZoneAlarmTrojan-Banker.Win32.CoinMiner.f
MicrosoftTrojan:Win32/Coinminer.MA!MTB
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.R115700
McAfeeTrojan-FESQ!F97B28447DA6
TACHYONTrojan-Spy/W32.Banker.219648.E
VBA32TrojanBanker.CoinMiner
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallCoinminer.Win32.MALXMR.SMJA
RisingTrojan.CoinMiner!1.D0E5 (CLASSIC)
YandexTrojan.PWS.CoinMiner!fEplIMpjE+o
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/CoinMiner
BitDefenderThetaGen:NN.ZexaF.36250.nuW@a8XX0Ffi
AVGWin32:SvcMiner-F [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Coinminer.MA!MTB?

Trojan:Win32/Coinminer.MA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment