Threat Database Trojans Trojan.Coinminer.OG

Trojan.Coinminer.OG

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 1
First Seen: November 5, 2025
Last Seen: April 11, 2026
OS(es) Affected: Windows

The detection of Trojan.Coinminer.OG indicates that your system has been compromised by a malicious threat. This type of malware is designed to secretly use your computer's resources for cryptocurrency mining, which can lead to significant performance issues and increased energy consumption. It is essential to take immediate action to remove the threat and prevent further damage.

What Is Trojan.Coinminer.OG?

Trojan.Coinminer.OG is a type of Trojan horse malware that infiltrates your system without your knowledge or consent. Trojans are malicious programs that disguise themselves as legitimate software, allowing them to evade detection and gain access to your system. The "Coinminer" part of the name suggests that this particular threat is focused on cryptocurrency mining, which involves using your computer's processing power to solve complex mathematical equations and generate digital currency.

How Trojan.Coinminer.OG Operates

Once installed, Trojan.Coinminer.OG can operate in the background, consuming system resources such as CPU and memory to perform cryptocurrency mining tasks. This can lead to a significant decrease in system performance, causing your computer to slow down, freeze, or even crash. The malware may also communicate with its command and control servers to receive updates, transmit stolen data, or download additional malicious components.

Symptoms of Infection

Some common symptoms of a Trojan.Coinminer.OG infection include slowed system performance, increased energy consumption, and unusual network activity. You may also notice that your computer is running hotter than usual, or that your fans are spinning more frequently. In some cases, you may receive warnings from your antivirus software or notice suspicious programs running in the background.

  • Unexplained increases in CPU or memory usage
  • Slow system performance or freezes
  • Increased energy consumption or heat generation
  • Unusual network activity or suspicious programs running in the background

How to Remove Trojan.Coinminer.OG

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal
  2. Perform a full scan of your system using a reputable antivirus tool, such as SpyHunter, to detect and remove the malware
  3. Uninstall any suspicious programs or applications that may be related to the infection
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons
  5. Reboot your computer and perform another full scan to ensure that the malware has been completely removed

Conclusion

Removing Trojan.Coinminer.OG from your system requires careful attention to detail and a thorough understanding of the malware's behavior. By following the steps outlined above and using reputable antivirus software, you can help to ensure that your system is clean and free from infection. It is also essential to take preventative measures, such as keeping your operating system and software up to date, using strong passwords, and being cautious when opening email attachments or downloading software from the internet. By taking these steps, you can help to protect your system from future malware infections and keep your personal data safe.

Analysis Report

General information

Family Name: Trojan.Coinminer.OG
Signature status: No Signature

Known Samples

MD5: 80486fd59461d4ff183ddc39c0049bbd
SHA1: 061f226660c6d61c7279191f988d98f51d32ce0d
SHA256: 4AFF3DD4AC6536C19D6A7D98EE1AEF4C0CE10DF7CD52162B0CAAC065B84DEAF1
File Size: 8.69 MB, 8688640 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • HighEntropy
  • No Version Info
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 15,213
Potentially Malicious Blocks: 2,676
Whitelisted Blocks: 12,537
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x x 0 x x 0 x 0 x 0 x 0 x x 0 x x x x x x x x 0 x x 0 0 x 0 x 0 x 0 0 x x 0 0 x x 0 0 x x x x 0 0 0 x x 0 0 x x 0 x 0 0 x 0 0 0 0 0 0 0 0 x x x x x 0 0 x x 0 x x x x x x x x x x x 0 0 0 0 0 0 x 0 0 0 x 0 0 0 x x x 0 x x x 0 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 x x x x x x x x x x x x x x 0 x x x x 0 x 0 x x 0 x 0 x x x 0 0 x x 0 x 0 x x 0 x x 0 x x x x 0 x x x x 0 0 0 x 0 0 0 x 0 x 0 x x x x x x x 0 0 0 0 x 0 0 0 0 x x 0 x x x x 0 0 0 0 0 0 0 x 0 x 0 x x 0 x x 0 0 x 0 0 x 0 x x 0 0 x 0 x x 0 x 0 x x x x x x x 0 x x x x 0 x x x x 0 0 0 x x x 0 x 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x x x x 0 x 0 0 x x 0 0 x 0 x x x x x x x x x x x x x x x x x x x 0 x 0 x 0 0 0 0 0 0 0 0 x 0 0 x 0 0 x 0 0 x x x 0 0 0 0 x x x 0 x 0 0 x 0 x x x x 0 0 x x 0 0 0 0 x 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 x 0 0 0 0 x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x x x x 0 0 0 0 x x 0 x x x 0 0 0 0 x 0 0 0 0 x x x 0 x x x 0 x x x x x x 0 x x 0 x x 0 0 0 0 0 0 x x x 0 x x x x x 0 x x x x x x x 0 x x x x x 0 0 0 0 0 0 0 0 x x x x x x x 0 0 0 0 0 0 x x 0 x x x x x x x x 0 x x x x x x x x 0 x 0 0 x x x x x x x x x x 0 x 0 x 0 0 x 0 0 0 x x 0 0 x 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x x x x x x x 0 0 0 0 x x x x x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 x x 0 0 x x x 0 x 0 0 0 x 0 0 x x x x x x x x 0 x x x x x 0 x x 0 x x x x x x x x 0 x x x 0 0 x x x x x x x x x 0 0 0 x 0 x x x 0 0 x 0 0 x 0 x 0 0 x 0 x 0 x 0 0 0 x 0 x x x x 0 x x 0 x 0 0 0 0 x x x 0 x 0 0 0 x x x 0 x x 0 x x x 0 0 x x x x x 0 x x x x 0 x 0 x 0 x x x 0 x 0 0 x 0 0 x 0 0 0 x 0 0 0 0 0 x 0 x 0 x x x 0 0 x x x 0 0 x 0 x x 0 0 x 0 x 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 0 x 0 x 0 x x 0 0 0 0 0 0 x 0 0 0 x x x 0 0 x 0 x 0 0 0 0 0 0 0 0 x x 0 x x 0 x 0 x 0 0 x 0 0 0 x x x x 0 0 x x 0 x x x 0 x x x x 0 x x x 0 0 x 0 x x x 0 x x x 0 x x x x 0 0 x x x 0 0 0 0 0 x 0 x x x x x 0 x x 0 0 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 x x 0 x 0 0 0 0 0 x x x 0 x x x x x x 0 0 0 x x 0 x 0 x 0 0 x x x 0 x 0 0 0 x x x x x x x 0 x x x x x 0 x x 0 x 0 x x x 0 x x x x x x x 0 x x x x x x x 0 x x x 0 x 0 x x x x x 0 0 x x x x x 0 x x 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 x 0 x x x 0 0 x 0 x x x x x 0 x x 0 x 0 x 0 x 0 x x 0 x x x x 0 x 0 x x x x 0 0 x x x x x x x 0 x 0 0 0 0 0 0 0 x 0 x x x 0 0 x 0 x x x 1 x x x x x x x x 0 x x x 0 x x 0 0 x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x 0 x 0 x 0 0 0 x x 0 x 0 0 x x x 0 x x x 0 0 x x 0 x x x x x x x x x x x x x x x x x x x x x 0 x x x x 0 0 x x 0 0 x 0 x x 0 x x x 0 0 0 x x x x x x x x x x x x x 0 x x x 0 x x x x x x 0 0 0 0 x x x 0 x 0 0 0 x x x x 0 x x x x 0 x 0 x x 0 0 x 0 x x 0 x 0 x x 0 0 0 x 1 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 x x 0 x x x x x x x 0 x x 0 x x x 0 0 0 x x 0 x 0 x x x 0 0 0 0 0 x x x 0 x x x x x 0 x x x x 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.PFZE
  • ClipBanker.DZB
  • Coinminer.OG
  • Coinminer.OGA
  • Coinminer.OGB

Files Modified

File Attributes
\device\namedpipe\pshost.134200859215599660.3628.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
c:\users\user\appdata\local\temp\__psscriptpolicytest_kb2yxgy5.rbg.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_wdy2i0gy.z53.ps1 Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 摕浬웸ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\winlogon::userinit C:\Windows\system32\userinit.exe,C:\Users\Nioqdsqn\AppData\Roaming\Folder\svchost.exe RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 튄渜웸ǜ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
Show More
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSetValueKey
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution

1 additional items are not displayed above.

Network Winsock2
  • WSAStartup
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
  • WriteConsole
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Process Terminate
  • TerminateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider
Other Suspicious
  • AdjustTokenPrivileges

Shell Command Execution

C:\WINDOWS\system32\reg.exe add "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon" /V "UserInit" /T REG_SZ /D "C:\Windows\system32\userinit.exe,C:\Users\Nioqdsqn\AppData\Roaming\Folder\svchost.exe" /F
WriteConsole: The operation co

Trending

Most Viewed

Loading...