Threat Database Trojans Trojan.Coinminer.GII

Trojan.Coinminer.GII

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 2,798
Threat Level: 80 % (High)
Infected Computers: 276
First Seen: May 20, 2024
Last Seen: January 6, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Coinminer.GII
Signature status: No Signature

Known Samples

MD5: da951be2792f73607099cf8dcfa783e4
SHA1: cc7fda1664b62e4fdb6d7704235badeb3f80592f
SHA256: 2030500893D7692CD7117BC14C61DFA3F832B31CA6F16D4C9F67B5D6DD9EAAF2
File Size: 4.52 MB, 4516352 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description Usermode Font Driver Host
File Version 10.0.19041.4355 (WinBuild.160101.0800)
Internal Name fontdrvhost.exe
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename fontdrvhost.exe
Product Name Microsoft® Windows® Operating System
Product Version 10.0.19041.4355

File Traits

  • HighEntropy
  • x64

Block Information

Total Blocks: 11,491
Potentially Malicious Blocks: 1,473
Whitelisted Blocks: 10,018
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 x 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 x x x x x x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x 0 0 0 0 0 x x 0 x 0 x 0 x x 0 x x x x x x x x x x x 0 0 x x x x 0 0 x x x x x x x 1 1 0 0 x x x 1 1 0 1 0 0 x x x x x x 0 0 x x x x 0 0 x x x 0 x 0 x x 0 x x x x x 0 0 x 1 1 x x x 0 x x x x 0 0 x 0 x x 0 0 x x x 0 0 1 x x 0 x 0 0 x x x 1 x x x 0 x x x x x 0 0 0 x x 0 1 x x x x 1 x x x x x x x x x x x x x x x 1 x x x x x x 0 x 0 0 0 0 x x x 1 1 x 1 1 1 0 x 1 x x x 1 x 0 x x x x x 0 0 0 0 0 x 1 x x x x x x x x x x x x x x 0 0 x x 0 x x x x x x x x x x x x x x 0 x 0 x x 0 x x x x x x x 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x x 0 x 0 x 0 x x x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 x x 0 x x x x x x x 0 x 0 0 x 0 0 x x x x 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x x x x x x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 x 0 0 0 0 0 0 0 x x x 0 0 x x x 0 x x x 0 x x x 0 0 x 0 x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x x 0 0 x 0 0 x 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 1 1 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 x 0 0 0 0 x 0 0 x 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x 0 0 0 x 0 0 0 x x x x x x x 0 x x x x x x x x x x x 0 x x 0 0 x 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 x 0 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 0 0 x 0 0 x 0 x 0 x x 0 0 0 0 0 0 x x x 0 x x 0 0 x x 0 0 0 0 0 0 x x 0 x 1 x 0 0 x 0 0 0 0 0 0 x 0 x 0 0 x x x x x 0 x x x 0 x 0 0 0 0 0 0 0 0 x 0 0 x x 0 x x x x x x x x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 x x x x 0 x 0 x x 0 x x 0 x x x x x 0 x x x x 0 0 0 0 x 0 0 0 0 x 0 x x 0 x 0 x 0 x 0 x 0 x 0 x 0 0 1 0 0 0 0 x x 0 x x x x x x x 0 x x x x 0 x x x 0 0 0 0 x x 1 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 x x x x x 0 0 x x x x x 0 x 0 0 0 0 x 0 0 0 0 x x 0 0 x 0 x x x x x 0 0 0 0 0 0 x x 0 0 0 0 0 x 0 x 0 0 x x 0 x x x 0 x x 0 0 x 0 x x x x 0 x x x 0 0 0 x x x x x 0 x x x x x x 0 0 x 0 x 0 0 0 x x 0 x 0 0 x x x x x x x x x 0 x 0 x x x x x 0 x 0 x x 0 0 0 x x 0 0 x x x 0 x x x 0 x 0 x x x x x 0 0 x x x 0 0 x x x x 1 x 0 x 0 0 x 0 x x x x x x x 0 0 x 0 0 x x x x 0 x x 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 x 0 x 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 x 0 x 1 1 0 0 0 0 x 0 0 0 0 x x x x x 0 0 x 0 x 0 0 x 0 x 0 0 x x x x 0 0 0 x x x 0 x x 0 0 0 0 x 0 0 0 x x 0 x x 0 x x x x x x x x 0 x x x 0 0 0 0 0 0 x 0 0 0 0 x x 0 0 x x 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 x 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x x x x 0 0 x 0 x x x 0 0 x 0 0 x 0 x 0 x 0 x x 0 0 x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 x x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x x x 0 0 0 x 0 x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 x 0 x 0 0 0 0 0 0 1 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 x 0 0 0 0 x 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Coinminer.GII

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
Show More
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletion
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetIoCompletion
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
Network Winsock2
  • WSAStartup
User Data Access
  • GetComputerName
  • GetUserName

Trending

Most Viewed

Loading...