Threat Database Trojans Trojan.Bitcoinminer.CBA

Trojan.Bitcoinminer.CBA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 15,406
Threat Level: 80 % (High)
Infected Computers: 15
First Seen: September 10, 2022
Last Seen: November 25, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Bitcoinminer.CBA
Packers: UPX x64
Signature status: No Signature

Known Samples

MD5: e33a732707ead3f82d6b06f847617ec0
SHA1: 811ff01869e43043f09c59c650c46dd35fdff71b
SHA256: 2A39B2BF80426910698232CDA48D48048D555DB9189721D49FC775E9A47D7109
File Size: 3.18 MB, 3182080 bytes
MD5: 87705ac3113aeb686358af7758bb2dde
SHA1: dec5e6c08d7188e26b4e2b8893d11a1276445bfa
SHA256: BE13DB9239EE4E6D2380BAF355F836E913DB79D4BAA6C9614B3B446C303C8FE6
File Size: 434.69 KB, 434688 bytes
MD5: dff198aec4d1c163fb423f9ed880b25f
SHA1: 9d8c859c17e725a7fd38b5c69fc9f24f09e2ac96
SHA256: 21104A321C2EAAE2A986DE96A7A74A5E6C4F9A0C76FCF2BA17C17A272C1F2398
File Size: 3.18 MB, 3182080 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File has been packed
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
Show More
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • No Version Info
  • packed
  • x64

Block Information

Total Blocks: 23,780
Potentially Malicious Blocks: 7,829
Whitelisted Blocks: 15,951
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x x x x 0 x x x 0 0 0 x x x 0 x 0 0 x 0 x x x x x x 0 0 x 0 x x x 0 0 x 0 0 x x x x x x 0 x x x 0 0 0 x x 0 0 x x x 0 x 0 0 0 x x x 0 0 0 x x x x x x x x 0 0 x 0 0 x x 0 x x x x x x x x x x x 0 x x 0 x x 0 x x x 0 x x 0 x x 0 x x x 0 x 0 x x 0 0 0 0 x x x x x x x x 0 x x 0 0 x x x x x 0 x x x x 0 x x x x 0 0 0 0 0 x 0 x x 0 0 x x x x x x 0 0 x x 0 x x x 0 0 x 0 0 x x 0 x x 0 0 x 0 x x 0 x x 0 0 x x x 0 0 0 x x x x x 0 x 0 x x x x x 0 x x x x x x 0 0 x x x 0 0 x 0 0 0 0 0 x x 0 0 0 x x x 0 0 0 0 x x 0 0 0 0 0 x x x 0 0 x x x 0 0 x x 0 x x x 0 x 0 0 x 0 x 0 0 0 0 x 0 0 x 0 0 x x x 0 0 0 0 x x x x 0 x x 0 0 0 x 0 x 0 x 0 x x x 0 0 0 x 0 x x x 0 x x x x 0 x x x x x 0 x 0 x 0 x x x 0 0 0 x x x 0 0 x 0 0 0 x 0 x x x 0 0 x 0 x x x x x x x x x x 0 x x x x x 0 x 0 x x x x x x x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 x 0 x 0 x x 0 0 x 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 x 0 0 x 0 0 0 0 0 x 0 x 0 x 0 x 0 0 x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x x 0 x 0 x x x x 0 x 0 x 0 x 0 x 0 0 x x 0 0 0 x 0 0 x x x x 0 0 0 0 0 0 x 0 x x 0 x 0 0 x x 0 0 x 0 x 0 0 0 0 0 x 0 x 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 x x x 0 x x 0 0 x x 0 x x 0 x 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 x 0 0 0 x 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 x 0 0 x 0 0 x 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x x x 0 0 x x x x x x 0 x 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 x x x x 0 x 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x x 0 0 x x 0 x 0 0 0 0 0 0 x 0 0 0 x x x 0 x x 0 x x 0 0 0 x 0 0 0 0 x x 0 0 0 0 0 x x 0 x 0 0 0 x 0 0 x 0 0 0 x 0 x x 0 x x x 0 0 0 0 x x x 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 x 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 0 0 0 0 0 x x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x x 0 0 0 0 0 0 0 x x 0 x x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x x x x 0 x 0 0 x x x x x 0 x 0 0 x 0 0 0 x 0 x x x 0 0 0 0 x 0 x x 0 0 0 x 0 0 x 0 x x x x x x x x x 0 0 0 x x 0 x x 0 0 0 0 x x x x x 0 x x 0 x 0 0 x x 0 x 0 x x 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 x x 0 x 0 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 0 x 0 0 x x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 x 0 0 x 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 x x x 0 0 x x x 0 0 0 x 0 x 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Bitcoinminer.CB
  • Bitcoinminer.CBA

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
Show More
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState

Trending

Most Viewed

Loading...