Threat Database Trojans Trojan.Coinminer.BDH

Trojan.Coinminer.BDH

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 9,828
Threat Level: 80 % (High)
Infected Computers: 10
First Seen: May 9, 2026
Last Seen: June 28, 2026
OS(es) Affected: Windows

The detection of Trojan.Coinminer.BDH on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise your computer's resources for malicious activities, and it is essential to understand the nature of the threat and take appropriate steps to remove it.

What Is Trojan.Coinminer.BDH?

Trojan.Coinminer.BDH is a type of Trojan horse malware that is primarily designed to hijack your computer's resources to mine cryptocurrency. The name suggests that it is a coin-mining Trojan, which means it uses your system's processing power to solve complex mathematical equations and generate cryptocurrency for the malware authors. This type of malware can be particularly damaging, as it can cause significant system slowdowns, increased power consumption, and reduced system lifespan.

How Trojan.Coinminer.BDH Operates

Trojan.Coinminer.BDH operates by infiltrating your system through various means, such as exploited vulnerabilities, phishing attacks, or drive-by downloads. Once inside, it establishes a connection with its command and control server to receive instructions and transmit stolen data. The malware then uses your system's resources to mine cryptocurrency, which can lead to significant system performance degradation. In some cases, the malware may also install additional components or payloads to further compromise your system.

Symptoms of Infection

Systems infected with Trojan.Coinminer.BDH may exhibit a range of symptoms, including slow system performance, increased CPU usage, and elevated power consumption. You may also notice unusual network activity, such as unexpected outgoing connections or data transmissions. In some cases, the malware may cause system crashes, freezes, or blue screens of death. If you suspect that your system is infected, it is essential to take immediate action to remove the malware and prevent further damage.

How to Remove Trojan.Coinminer.BDH

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full system scan and detect any malware components.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or plugins.
  5. Reboot your system and perform another full scan with your anti-malware tool to ensure that all malware components have been removed.

Conclusion

Removing Trojan.Coinminer.BDH from your system requires careful attention to detail and a thorough understanding of the malware's behavior. By following the steps outlined above, you can help to ensure that your system is free from this malicious threat. It is essential to remain vigilant and take proactive steps to protect your system from future malware infections, such as keeping your operating system and software up to date, using strong antivirus software, and avoiding suspicious downloads and links. By taking these precautions, you can help to safeguard your system and prevent the damage caused by Trojan.Coinminer.BDH and other types of malware.

Analysis Report

General information

Family Name: Trojan.Coinminer.BDH
Signature status: No Signature

Known Samples

MD5: 76e136caa6306c9fcca4466afc5ad8de
SHA1: ecec464de5c3d9ce4d103e36cd183702b2f11660
SHA256: 044CE80C10F4507BA40847261B885829EEAFCA657E31FF68A228E584D40F6FA2
File Size: 1.69 MB, 1688064 bytes
MD5: f47e4cae2482ee0c058e041f11884c1e
SHA1: a571e51fac5147fd157343860e453a48a9f2c639
SHA256: BFF60FAE1B82FD441A2470D683C77C0BA80EA692DFF436C09E47ED2BAB66E255
File Size: 1.69 MB, 1688064 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • No Version Info
  • ntdll
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 12,379
Potentially Malicious Blocks: 733
Whitelisted Blocks: 11,646
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 x x 0 x x 0 x x 0 x 0 x x 0 x 0 0 x 0 x x x x x x 0 x x x x x x 0 x 0 x x x 0 x x 0 x x 0 x x x x x x x 0 x x 0 x 0 0 x x x x 0 x 0 x x x 0 x x x x x 0 0 x x x 0 x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 x x 0 x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 x 0 x x 0 x x x 0 x 0 x x x 0 x x 0 0 x 0 0 x 0 x 0 x 0 0 x x 0 x x x x x 0 x 0 x 0 x x 0 x x x x x 0 x x x x x x x x x x x 0 x x x 0 x x x x x 0 x x x x 0 0 0 0 x 0 0 0 0 x x x 0 0 x 0 0 x 0 0 0 0 0 0 0 0 x x x 0 x 0 x 0 x x x x x x x x x x x x x x x x 0 x x x 0 x x x 0 0 0 x x 0 0 0 x 0 x x 0 0 x x 0 x 0 0 0 x 0 x x x x x 0 x 0 x x x x x 0 x x 0 0 0 0 x x x 0 x 0 x x 0 0 x x x x x x 0 x x 0 0 x 0 x 0 x 0 x 0 x 0 x x x x 0 0 x x x 0 x 0 0 0 x x 0 x x x x x x x x x x x 0 x 0 x x 0 x x x x x x 0 x x x 0 0 0 0 x x x x x x 0 x x x 0 0 0 0 x x x 0 0 0 x x 0 x x x x x x x x x x x x x 0 0 0 0 x x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x x 0 0 x 0 0 x 0 0 x 0 0 x 0 x 0 x 0 0 x 0 0 x 0 0 x 0 0 0 x x 0 0 0 x 0 x 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.FHM
  • Agent.IFAC
  • Coinminer.BDH
  • EDRFreeze.A
  • Filecoder.XU
Show More
  • Keylogger.XB
  • Trojan.Agent.Gen.CDI
  • Trojan.Kryptik.Gen.DIF
  • Trojan.Kryptik.Gen.DZD

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtClose
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
Show More
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...