Threat Database Trojans Trojan.Minjen

Trojan.Minjen

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 2
First Seen: June 10, 2018
Last Seen: November 9, 2018
OS(es) Affected: Windows

Trojan.Minjen is a detection name that many AV vendors use in reference to a generic Trojan that was discovered on February 22nd, 2018. The Minjen Trojan is known to create a folder under the C:\Windows\Fonts directory to hide its presence. Moreover, the Minjen Trojan creates fake instances of two legitimate process names in Windows — 'svchost.exe' and 'csrss.exe' to facilitate its operation. PC users may be infected with Trojan.Minjen when they run pirated software, open self-extracting archives and load macros from phishing documents. The Trojan.Minjen malware is designed to perform as a downloader module that connects to an encrypted server over the Internet and install a Monero miner. The Monero miner tool introduced by the Minjen Trojan is recorded to connect to .supportxmr.com. Additionally, the Minjen Trojan opens a backdoor on the composited system and connects to the following Web locations:

btc..com.cn:5317/btc.jpg
btc..com:5317/btc.jpg
btc..com:5317/minerxmr.jpg
btc..com:5317/3306.jpg

Consequent updates to Trojan.Minjen were recorded in March 2018 and September 2018. The authors of Trojan.Minjen implemented a few other features that include system information gathering (IP address lookup, geo-IP identification, OS version and default Web browser), keyboard input logging and hijacking remote desktop sessions. The Minjen Trojan may be styled as a platform that allows for heterogeneous attacks on unwary PC users that may have Bitcoin/Monero wallets and don't follow good Internet usage practices. Computer security experts warn that the Minjen Trojan can copy information saved in the system clipboard, as well as retrieve passwords saved in the local storage of your Web browser. Computers infected with the Trojan.Minjen might not perform to their full potential. You might notice processes being terminated and you may be shown alerts that you are logged into your online accounts from a remote location already. It is advised to use a trusted anti-malware suite to clean potential Trojan.Minjen infections.

Registry Details

Trojan.Minjen may create the following registry entry or registry entries:
Regexp file mask
%WINDIR%\Fonts\a\svchost.exe

Trending

Most Viewed

Loading...