Malware

Mint.Zard.5 (file analysis)

Malware Removal

The Mint.Zard.5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mint.Zard.5 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Mint.Zard.5?


File Info:

name: B76A962E88C4F3546D68.mlw
path: /opt/CAPEv2/storage/binaries/56a97b26e378fdf689d507fd00b811a9b5588e39244732e39615a420e2500b3f
crc32: D8062211
md5: b76a962e88c4f3546d6817743f537fb0
sha1: c1c03e546bc4dea86769daf6c3c94670c6a77bf8
sha256: 56a97b26e378fdf689d507fd00b811a9b5588e39244732e39615a420e2500b3f
sha512: 870558ba0eefeef4d760153b9f596736563d50f620bfe0702c05841c3a6e9c2b6852721d7fa7ba5c8c46e9dc2521854383d61a44547d73b93b5947b1346b63f4
ssdeep: 6144:j1dB0kb27MtsmOAdp2pK9IQbV0MORuSzQh5dwS2Pf9ra:j1dZ6MtXp24/JhcwdZcf9r
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1CD54E111BF21A075E91D503DA11ADA685EF37CAE63F4C3233B460B7E4F1AAC1D11D2A9
sha3_384: a6ee7664e244ce38df043d4047769a667bbfcdd232fec02b51cb7ada585590d3bfd5fbd62dc2615c4b9e000020560381
ep_bytes: e8d4a40000e9a4feffff8bff558bec56
timestamp: 2013-05-09 02:37:15

Version Info:

0: [No Data]

Mint.Zard.5 also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Senoval.n!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Mint.Zard.5
ALYacGen:Variant.Mint.Zard.5
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005ad28b1 )
K7GWTrojan ( 005ad28b1 )
CrowdStrikewin/malicious_confidence_90% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Patched.NKM
APEXMalicious
CynetMalicious (score: 100)
AlibabaVirus:Win32/Senoval.9bcfec4f
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
TrendMicroTROJ_GEN.R002C0XB224
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Patched
JiangminBackdoor.Convagent.ns
AviraTR/Patched.Gen
Antiy-AVLTrojan/Win32.Wacatac
Kingsoftmalware.kb.a.994
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Mint.Zard.5
GoogleDetected
AhnLab-V3Worm/Win.Sdbot.R604500
McAfeeArtemis!B76A962E88C4
MAXmalware (ai score=89)
MalwarebytesGeneric.Malware.AI.DDS
TencentTrojan.Win32.Pathced_ya.16001052
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Patched.IP!tr
DeepInstinctMALICIOUS

How to remove Mint.Zard.5?

Mint.Zard.5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment