Threat Database Trojans Trojan.Bitcoinminer.D

Trojan.Bitcoinminer.D

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 11,113
Threat Level: 80 % (High)
Infected Computers: 37
First Seen: May 5, 2017
Last Seen: May 25, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Bitcoinminer.D
Signature status: No Signature

Known Samples

MD5: ba5785ebe0330377d79af7fa3b046c70
SHA1: 6b1adbcaf8c8023e9cbc9cf8e948b4cab3c030dd
SHA256: 327E382B2FC50BBF694823871274EE0689D825E2F9BCC05F4382A93F88BB918F
File Size: 1.20 MB, 1200128 bytes
MD5: 08aee972e8fb60adeeb9d3a21b742d67
SHA1: 9de4b2c12b2ae9e2d6d5382dfdbf4538ecb10d82
SHA256: 56D3D0D5AEA2A746EC0E8ED983F60C92840B8F620536ECBE0BA551ED9D01486C
File Size: 4.05 MB, 4046848 bytes
MD5: c553140bae87cccaa5b2340a09654c35
SHA1: 8fa15e0354798c09984f228549c5ec624261c16b
SHA256: 508748F22E3D789428D08A76B76B85F6DA9BE25C6AEB64BC7DC599DEBB3C147E
File Size: 755.20 KB, 755200 bytes
MD5: 201651c778134dea80f69077afc61b44
SHA1: 4920c82731c0d5b12578c10165d36dacdc81f770
SHA256: F6ECD38C030FEAE05A7F093039E36171BDC15AA2D38FE548E24B54D63533CAD9
File Size: 1.41 MB, 1409024 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments
  • LaTaleLauncher
  • Mortal [APEX]
Company Name
  • Cola
  • Mortal [APEX]
File Description
  • LaTaleLauncher
  • Mortal [APEX]
File Version
  • 1.1.0.0
  • 1.0.0.0
Legal Copyright
  • Cola
  • Mortal [APEX]
Product Name
  • LaTaleLauncher
  • Mortal [APEX]
Product Version
  • 1.1.0.0
  • 1.0.0.0

File Traits

  • 2+ executable sections
  • imgui
  • No Version Info
  • packed
  • x86

Block Information

Total Blocks: 1,820
Potentially Malicious Blocks: 558
Whitelisted Blocks: 1,120
Unknown Blocks: 142

Visual Map

x ? x x x 0 x ? 0 x x 0 x 0 x x x x x x x x x x x 0 x x x x x x 0 0 x x x x 0 0 x x x x x ? x ? x x x x ? ? ? ? ? ? ? ? ? x x ? ? ? 0 ? 0 0 ? ? ? 0 ? ? ? ? x ? x x x x x x x x 0 x x x x x x x x x x x 0 x x x x x x x x 0 x x 0 x x x x x x x x x ? x x x 0 ? x x x x ? 0 0 0 0 0 ? ? 0 x ? x x x x x x 0 ? x x x x 0 x x x x x 0 ? ? ? ? 0 ? x 0 ? 0 ? x 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? ? ? 0 ? ? ? 0 x ? x x x x x x x x x x x x x x x x x ? x x x x x x x 0 ? ? x x x 0 ? ? ? x ? ? ? ? x ? ? x x ? x x x x 0 x x x 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? x x x x x x x x x ? ? x x ? ? x x x ? x ? ? x x ? ? x 0 x ? ? x ? ? 0 x x ? ? x ? ? x ? x ? x x x x x x 0 ? x x 0 ? 0 ? x ? 0 ? ? ? x x ? x x ? x x x 0 0 x x 0 0 x x 0 0 x x 0 0 x x 0 0 x x 0 0 x x 0 0 x x 0 0 x 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x 0 x x x x x x x x x x x ? x x x x 0 0 x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? 0 ? x x x x x 0 x x 0 x x x x x x x x x x x 0 0 x x 0 x x x x x 0 x 0 0 0 x 0 x 0 0 x x x x x x x x x x x 0 x x x x x x x x 0 x 0 x x x 0 x x x x 0 x x x x 0 x x x x x x x x x x x x x 0 x x x x x 0 x x x x x 0 0 x 0 0 x 0 0 0 x x 0 0 x x x 0 0 0 0 x 0 0 x x x x x x 0 0 x 0 0 x 0 x x x 0 x x x x x 0 x 0 x x x x x x x x x x x x x 0 x x x x x x 0 0 x x 0 x x 0 0 0 x x x x 0 0 0 x 0 x x x x x x x x x x x x x x x x x x x 0 x 0 0 x x 0 x 0 x 0 0 0 x x x x x x 0 0 x x x x x x 0 0 0 x 0 0 x x x x x x x 0 x x 0 x x x x 0 x x 0 x x x x 0 x x 0 x 0 x 0 0 0 x 0 x x x 0 0 0 x x x x x x x x x x x x x x x x 0 0 0 x x 0 x x 0 x x 0 0 x x 0 0 0 x 0 0 x x 0 0 x x 0 0 x 0 0 0 x x 0 0 0 x x 0 x 0 0 x x x 0 x 0 0 x x 0 x 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 x 0 0 0 x 0 x x x 0 0 0 0 0 x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 1 0 1 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Bitcoinminer.FD

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Network Winsock2
  • WSAStartup

Trending

Most Viewed

Loading...