Threat Database Trojans Trojan.Coinminer.GCN

Trojan.Coinminer.GCN

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 14,472
Threat Level: 80 % (High)
Infected Computers: 302
First Seen: May 8, 2024
Last Seen: September 10, 2026
OS(es) Affected: Windows

The detection of Trojan.Coinminer.GCN on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise your computer's resources for malicious activities, and it's essential to understand its nature and take prompt action to remove it.

What Is Trojan.Coinminer.GCN?

Trojan.Coinminer.GCN is a type of Trojan horse malware that is primarily used for cryptocurrency mining. Trojans are malicious programs that disguise themselves as legitimate software, allowing them to infiltrate a system without being detected. The ".Coinminer" part of the name suggests that this particular Trojan is focused on exploiting system resources to mine cryptocurrency, which can lead to significant performance issues and potential damage to your hardware.

How Trojan.Coinminer.GCN Operates

Once installed on a system, Trojan.Coinminer.GCN can operate in the background, consuming CPU and GPU resources to mine cryptocurrency. It may also communicate with its command and control servers to receive updates or transmit stolen data. This type of malware can be particularly challenging to detect, as it may not exhibit the typical symptoms of a virus, such as pop-ups or ransom demands. Instead, it can silently run in the background, causing system slowdowns and increased power consumption.

Symptoms of Infection

While Trojan.Coinminer.GCN may not always exhibit obvious symptoms, there are some signs that could indicate its presence on your system. These may include slowed system performance, increased CPU or GPU usage, overheating, and increased electricity bills. You may also notice that your system is running hotter than usual, or that your fans are working more intensely. If you suspect that your system has been infected with Trojan.Coinminer.GCN, it's essential to take immediate action to remove it.

How to Remove Trojan.Coinminer.GCN

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for a more straightforward removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of the malware.
  3. Uninstall any suspicious programs or applications that may be related to the malware. Be cautious when uninstalling programs, as some may be legitimate.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another full scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Coinminer.GCN from your system requires a combination of technical knowledge and the right tools. By following the steps outlined above and using a reputable anti-malware tool, you should be able to remove the malware and restore your system to its normal state. It's also essential to take preventive measures to avoid future infections, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious when opening email attachments or downloading files from the internet. Remember, staying vigilant and proactive is key to protecting your system from malware threats like Trojan.Coinminer.GCN.

Analysis Report

General information

Family Name: Trojan.Coinminer.GCN
Signature status: No Signature

Known Samples

MD5: a62a7560938b2d84344ba051ec50bd48
SHA1: 79ede31570054d9e2290bf6893fc49a18df8abe5
SHA256: B1C9402D3FD7ECC8887F1D8D04B22FE2A2BD5F887929444C990EA607CDC1F700
File Size: 928.28 KB, 928284 bytes
MD5: d9d6dc187d1173f0148b23effcc2e2e6
SHA1: ce13594d941a9880a2de9091f9a3b6c78158a390
SHA256: 416301F9DD1FB9B85D794368527BFCDC5426B8CFAB67DA39DF9F32F6D4F00744
File Size: 951.33 KB, 951329 bytes
MD5: fa8971620f3b97117446b43524523ee1
SHA1: 5e99896a70c65e88043649f234b74b17c5cd3ee1
SHA256: DDE3BC944C6F9AD7BD6621C495BFFC647BFE613B27F3818B12ABAE8528F0CA30
File Size: 890.41 KB, 890410 bytes
MD5: fb9b4c68f6901b2e12d6fcb553c18039
SHA1: 5a415be2233494118448a51bbd875e6c40bce4eb
SHA256: 484E4C0C4FD5AA296C405890F97E7E9A81A02521F1C2A42B217EC25FCC763EFD
File Size: 1.36 MB, 1362432 bytes
MD5: 0889da9e1f8124f8f5a43bfc59a77ec6
SHA1: a18f3d450f22e3c97cc061473e875eb876da3556
SHA256: 4EDE03BF4DFCC23C3EC7E2448E1F6205E066FD3C324C039040E98F9F3267A49B
File Size: 879.65 KB, 879651 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Cheathappens
  • CheatHappens
  • Fatih Kodak
Email webmaster@f2ko.de
File Description Bat To Exe Converter
File Version
  • 2.4.4
  • 1.0000
Legal Copyright Fatih Kodak
Product Name
  • Assassins Creed Unity Trainer
  • Battlefleet Gothic Armada
  • Bat To Exe Converter
  • Rainbow Six Siege
  • RYSE Son of Rome Trainer
Product Version
  • 21751
  • 20522
  • 20393
  • 20253
  • 2.4.4
Website http://www.f2ko.de

File Traits

  • 2+ executable sections
  • HighEntropy
  • packed
  • VirtualQueryEx
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 839
Potentially Malicious Blocks: 43
Whitelisted Blocks: 578
Unknown Blocks: 218

Visual Map

? ? ? ? ? ? ? ? ? ? 0 0 ? ? 0 ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 x x 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x x 0 0 0 ? ? ? ? ? ? 0 0 ? ? 0 ? ? ? 0 x ? x x x x x 0 ? 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 ? 0 ? ? 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x x x x x x ? 0 ? x 0 0 0 0 0 x 0 ? ? x ? ? ? 0 ? 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 ? ? x ? ? 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 ? 0 0 0 0 ? 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 x ? x ? ? 0 0 0 0 0 0 ? ? ? 0 ? 0 ? ? ? 0 ? ? ? 0 ? ? ? 0 ? ? ? 0 ? 0 x ? x 0 ? 0 ? 0 ? 0 ? x ? ? ? 0 0 0 x x ? ? 0 0 ? 0 0 0 ? 0 ? ? 0 x ? ? 0 0 0 x ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 ? 0 0 ? 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 x 0 0 0 0 x 0 0 1 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 ? 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 ? 0 ? 0 0 0 0 0 ? 0 0 0 0 ? ? ? 0 0 0 ? 0 ? 0 ? 0 ? 0 0 ? 0 0 ? ? ? ? ? 0 ? 0 0 0 0 ? ? 0 0 0 0 0 0 ? ? 0 ? ? ? 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 ? 0 ? 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\9d7.tmp\golink.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\9d7.tmp\gorc.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\9d7.tmp\scilexer.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\9d7.tmp\upx.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\cheathappens\debug\battlefleet gothic armada.debug Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\cheathappens\debug\rainbow six siege.debug Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\0.ogg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\1.ogg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\3.ogg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\4.ogg Generic Read,Write Data,Write Attributes,Write extended,Append data
Show More
c:\users\user\downloads\5.ogg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\6.ogg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\7.ogg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\ch.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\help.txt Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 i�r�n��*����8\x�a�B +� �� �6 �} �� �� 7� xy �� �� ۀ>�=�����B�O�����x�%���8�5����Bx�������\�!I�RN�sb!>!wz#@�#��#�O$kF$��$¨%:�%f RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 k8��81az��B�8 �6 �v y� z �Z xy �� �a ۀT�B������1�����5����ee +Bx�<����5 � �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�x'�(�(X�)�`*J*9*�^+�[+�� RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAccessCheckByType
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcAcceptConnectPort
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePort
  • ntdll.dll!NtAlpcOpenSenderProcess
  • ntdll.dll!NtAlpcQueryInformation
Show More
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFindAtom
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtImpersonateAnonymousToken
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFile
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationAtom
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx

11 additional items are not displayed above.

Anti Debug
  • IsDebuggerPresent
Other Suspicious
  • AdjustTokenPrivileges
Process Shell Execute
  • CreateProcess
Process Terminate
  • TerminateProcess
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
User Data Access
  • GetUserObjectInformation
Keyboard Access
  • GetKeyState

Shell Command Execution

"notepad.exe" C:\Users\user\Cheathappens\Debug\Rainbow Six Siege.debug
"notepad.exe" C:\Users\user\Cheathappens\Debug\Battlefleet Gothic Armada.debug