Malware

MSIL/CoinMiner.BAH information

Malware Removal

The MSIL/CoinMiner.BAH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/CoinMiner.BAH virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Attempts to create or modify system certificates

Related domains:

z.whorecord.xyz
a.tomx.xyz
owxbaopogqab.000webhostapp.com

How to determine MSIL/CoinMiner.BAH?


File Info:

crc32: 32FCCC35
md5: a7a82dcb9d315f610c4ec6f2c6f8b9b9
name: 1.exe
sha1: f33f82a529c19ba45f1c388e57942c04e63f165e
sha256: 7b1f436078b2ac9eff71d57dafa57d0ad469f6221a6b46435c3e9de1dc34ac33
sha512: 707ae2f0a1fea910f7c881be526582882b24a99d8ae377ba6c15beb9eb9c821d9904763688b7a8e90ec91c9dddc879058f385b57deb91a57d34694a79928bee3
ssdeep: 1536:OF6wjjTuXoIR8p+sSSr19bLHGUD4+8YJdLZ:O6ijwoIR8p+ur19brBD4+Zd
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2020
Assembly Version: 1.0.0.0
InternalName: build1.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: build1
ProductVersion: 1.0.0.0
FileDescription: build1
OriginalFilename: build1.exe

MSIL/CoinMiner.BAH also known as:

FireEyeGeneric.mg.a7a82dcb9d315f61
Qihoo-360HEUR/QVM03.0.0CC7.Malware.Gen
McAfeeArtemis!A7A82DCB9D31
CylanceUnsafe
SangforMalware
Cybereasonmalicious.529c19
Invinceaheuristic
BitDefenderThetaGen:NN.ZemsilF.34084.eq0@aK4JD7i
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/CoinMiner.BAH
TrendMicro-HouseCallTROJ_GEN.R020H0AB420
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Miner.gen
AlibabaTrojan:MSIL/CoinMiner.05def2d4
TencentMsil.Trojan.Miner.Lnxw
F-SecureAdware.ADWARE/EoRezo.Gen7
McAfee-GW-EditionBehavesLike.Win32.Generic.lh
SentinelOneDFI – Malicious PE
Trapminesuspicious.low.ml.score
APEXMalicious
AviraADWARE/EoRezo.Gen7
Endgamemalicious (high confidence)
ZoneAlarmHEUR:Trojan.MSIL.Miner.gen
MicrosoftTrojan:Win32/Wacatac.D!ml
Acronissuspicious
eGambitUnsafe.AI_Score_99%
FortinetRiskware/Miner
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL/CoinMiner.BAH?

MSIL/CoinMiner.BAH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment