Malware

Application.Miner.NiceHash.2 (file analysis)

Malware Removal

The Application.Miner.NiceHash.2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Miner.NiceHash.2 virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Application.Miner.NiceHash.2?


File Info:

name: C5AE1971A686AD3E4015.mlw
path: /opt/CAPEv2/storage/binaries/0f15fd8fca42fcc895d2b1ffd8f46205075afe2a0de6617d45b209e349d0e380
crc32: DC8329D6
md5: c5ae1971a686ad3e4015c1fc399897f1
sha1: 67cbca91a1bf9df038205f8eed4f8acec274d06a
sha256: 0f15fd8fca42fcc895d2b1ffd8f46205075afe2a0de6617d45b209e349d0e380
sha512: 0a1df70681876c0de931e6138675b9c6d6f9a17f341886de02a712c679ba68ccacb82a91dc21645649b139a4239585d1a1eef3cb630dda212f17e5e2b176c41a
ssdeep: 6144:CvZcLDOQp/WJgq8Y7vu2O15BEbb4Dru9f0ydn17CMGMJp:g+SQp/WJgq81YbnQMGMJ
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1D2254A03668E7374E2EF0BFA6970C4408F3BEC197458E78EA71570E9763674486217BA
sha3_384: 5ee82ae5cd6a07039124cf618ed5313d4ef32807eddedc6d06eecad0cea12c81db7046522c08aa57965dfc97215a76db
ep_bytes: ff250020001000000000000000000000
timestamp: 2065-01-04 07:08:36

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: NHMCore
FileVersion: 1.0.0.0
InternalName: NHMCore.dll
LegalCopyright: H-BIT, d.o.o. © 2020
LegalTrademarks:
OriginalFilename: NHMCore.dll
ProductName: NHMCore
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Application.Miner.NiceHash.2 also known as:

LionicRiskware.MSIL.BitMiner.1!c
MicroWorld-eScanGen:Variant.Application.Miner.NiceHash.2
FireEyeGen:Variant.Application.Miner.NiceHash.2
SkyhighArtemis
McAfeeArtemis!C5AE1971A686
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTool.BitMiner.Win32.3715
SangforCoinMiner.Msil.Agent.Vqra
AlibabaRiskWare:MSIL/Miners.c4be8a90
CrowdStrikewin/grayware_confidence_60% (D)
ArcabitTrojan.Application.Miner.NiceHash.2
SymantecPUA.Gen.2
ESET-NOD32a variant of MSIL/CoinMiner.AA potentially unwanted
Kasperskynot-a-virus:HEUR:RiskTool.MSIL.BitMiner.gen
BitDefenderGen:Variant.Application.Miner.NiceHash.2
TencentMsil.Risktool.Bitminer.Edhl
SophosGeneric Reputation PUA (PUA)
VIPREGen:Variant.Application.Miner.NiceHash.2
EmsisoftGen:Variant.Application.Miner.NiceHash.2 (B)
IkarusPUA.MSIL.Coinminer
JiangminRiskTool.MSIL.cppa
WebrootW32.Miner
MAXmalware (ai score=76)
Antiy-AVLGrayWare/MSIL.CoinMiner
MicrosoftPUA:Win32/Presenoker
ZoneAlarmnot-a-virus:HEUR:RiskTool.MSIL.BitMiner.gen
GDataGen:Variant.Application.Miner.NiceHash.2
ALYacGen:Variant.Application.Miner.NiceHash.2
Cylanceunsafe
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.114434350.susgen
DeepInstinctMALICIOUS

How to remove Application.Miner.NiceHash.2?

Application.Miner.NiceHash.2 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment