CoinHive malware family
CoinHive is a malware family tracked by MalwareAnalyzer by Cyble across 2 publicly analyzed samples. First seen 2026-07-29, most recently 2026-08-10. Observed ATT&CK techniques include T1112.
Corpus statistics
- Publicly analyzed samples: 2
- First seen: 2026-07-29
- Last seen: 2026-08-10
- Verdicts: malicious 2
- File types: html 2
ATT&CK techniques used by CoinHive
- T1112 - 2 samples
Extracted command-and-control infrastructure
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css - 2 samples
- http://1.bp.blogspot.com/_kMUpUqMmduA/SUoAPAIYoII/AAAAAAAAAng/VyhhJGvEMHE/s1600/favicon.png - 1 sample
- http://2.bp.blogspot.com/_kMUpUqMmduA/SUoAPCvpmgI/AAAAAAAAAno/nMGxA1LugYU/s1600/linkbar.png - 1 sample
- http://4.bp.blogspot.com/_kMUpUqMmduA/SUoAO7PMo9I/AAAAAAAAAnQ/4X-qK6Yz3PA/s1600/blue4.png - 1 sample
- http://7bb09029p8luergdlanan7gx23.hop.clickbank.net/?tid=BLOGGER - 1 sample
- http://ateon.fs.googlepages.com/kodescript.js - 1 sample
- http://elvisonthemove.blogspot.com/2008_04_19_archive.html - 1 sample
- http://elvisonthemove.blogspot.com/favicon.ico - 1 sample
- http://elvisonthemove.blogspot.com/feeds/posts/default - 1 sample
- http://elvisonthemove.blogspot.com/feeds/posts/default?alt=rss - 1 sample
- http://i306.photobucket.com/albums/nn252/cebong_ipit/templateblue/authorcomment.png - 1 sample
- http://i535.photobucket.com/albums/ee355/elvisglazier/Blogger/EOTM277x1000lores.jpg - 1 sample
- http://kendhin.890m.com/kalender/bluecalend.gif - 1 sample
- http://laschicasmassexisfotos.blogspot.com/ - 1 sample
- http://laschicasmassexisfotos.blogspot.com/2011/01/tias-en-bikini-top-model-enero-2009.html - 1 sample
- http://laschicasmassexisfotos.blogspot.com/2011/01/tias-en-bikini-top-model-enero-2009.html#comment-form - 1 sample
- http://laschicasmassexisfotos.blogspot.com/favicon.ico - 1 sample
- http://laschicasmassexisfotos.blogspot.com/feeds/posts/default - 1 sample
- http://laschicasmassexisfotos.blogspot.com/feeds/posts/default?alt=rss - 1 sample
- http://laschicasmassexisfotos.blogspot.com/search/label/chicas%20bonitas%20videos - 1 sample
Recent CoinHive samples
- e293dfe1f3f0affd99d49088a5c9ac3b1b196be7f44b35ec84395285ca5bff65 - malicious (2026-08-10)
- 885b2cc83a6676664b030d72a84c462ea5bcfeaf40c78bade97c8bd31c6235a3 - malicious (2026-07-29)
Frequently asked about CoinHive
- What is CoinHive?
- CoinHive is a malware family tracked by MalwareAnalyzer by Cyble across 2 publicly analyzed samples. First seen 2026-07-29, most recently 2026-08-10. Observed ATT&CK techniques include T1112.
- How many CoinHive samples have been analyzed?
- MalwareAnalyzer by Cyble holds 2 publicly analyzed samples attributed to CoinHive, first seen 2026-07-29 and most recently 2026-08-10. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does CoinHive use?
- Across our CoinHive samples the most frequently observed techniques are T1112 (2). Counts are the number of analyzed samples in which each technique was observed.
- What file types does CoinHive use?
- CoinHive samples in this corpus are distributed as html (2).
- Does CoinHive use command-and-control infrastructure?
- Yes. 27 distinct command-and-control indicators have been extracted from CoinHive samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is CoinHive malicious?
- 2 of 2 analyzed CoinHive samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends