Malware

About “Generic.Mint.Zamg.8.157FE130” infection

Malware Removal

The Generic.Mint.Zamg.8.157FE130 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Mint.Zamg.8.157FE130 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Writes a potential ransom message to disk
  • Behavioural detection: Transacted Hollowing
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • STOP ransomware registry artifacts detected
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Creates a known STOP-Djvu ransomware decryption instruction / key file.
  • Creates a known STOP ransomware variant mutex
  • STOP ransomware command line behavior detected
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Mint.Zamg.8.157FE130?


File Info:

name: C71AE564B0EDC6E0E7F6.mlw
path: /opt/CAPEv2/storage/binaries/00a2c44aad289b157a90a1c0448248641737dc13141e24da22ae0498a1510396
crc32: A55B05A5
md5: c71ae564b0edc6e0e7f6b18dbb65e6ab
sha1: bf028b66fdee3ba2c15f8694270daedac362976f
sha256: 00a2c44aad289b157a90a1c0448248641737dc13141e24da22ae0498a1510396
sha512: 061ca06c816a61866a7822349b3e015de284a58c296b935e39d7a03cda50754036d4b1ccc801505e12e8b86dc8b805a41812d026a8be11b9917ed6768d7d185b
ssdeep: 6144:kXQ3tGWyr0EeH/x6sXPUIbNYJubgkf2VrOpMdrvq00iy:YQ3psSPfZbN0ubQOWP0D
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T149641282629CEB51DE8006FEC60067F49EAC5F9DD142729B3905FF2A393D094DE173A6
sha3_384: a25b92154ae89ada071a1cec3d7e6a5504009dba3f305a40b768f19705b00397f72bf9605432a4e4e9ecc02d0589e9a0
ep_bytes: 60be00e043008dbe0030fcff5783cdff
timestamp: 2018-05-26 04:29:30

Version Info:

0: [No Data]

Generic.Mint.Zamg.8.157FE130 also known as:

BkavW32.KisoxeNWAM.Trojan
LionicTrojan.Win32.Stop.4!c
CynetMalicious (score: 100)
FireEyeGeneric.mg.c71ae564b0edc6e0
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeArtemis!C71AE564B0ED
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0054a6af1 )
AlibabaTrojan:Win32/VidarStealer.08bf1dd7
K7GWTrojan ( 0054a6af1 )
Cybereasonmalicious.4b0edc
VirITTrojan.Win32.Faker.M
SymantecPacked.Generic.525
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Kryptik.GREW
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Ransom.Win32.Stop.aa
BitDefenderDeepScan:Generic.Mint.Zamg.8.157FE130
NANO-AntivirusTrojan.Win32.Stop.foipua
ViRobotTrojan.Win32.GandCrab.Gen.B
MicroWorld-eScanDeepScan:Generic.Mint.Zamg.8.157FE130
AvastWin32:Malware-gen
TencentWin32.Trojan.Raas.Auto
Ad-AwareDeepScan:Generic.Mint.Zamg.8.157FE130
EmsisoftDeepScan:Generic.Mint.Zamg.8.157FE130 (B)
ComodoTrojWare.Win32.Zpevdo.FY@835xne
F-SecureTrojan.TR/AD.InstaBot.O
DrWebTrojan.Faker.12
VIPREDeepScan:Generic.Mint.Zamg.8.157FE130
TrendMicroRansom.Win32.STOP.THCBEAI
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
Trapminemalicious.high.ml.score
SophosMal/Generic-S + Mal/GandCrab-G
IkarusTrojan.Crypt
JiangminTrojan.PSW.Azorult.aka
AviraTR/AD.InstaBot.O
Antiy-AVLTrojan[Ransom]/Win32.Stop
MicrosoftTrojan:Win32/Gandcrab.AF
ArcabitDeepScan:Generic.Mint.Zamg.8.157FE130
ZoneAlarmTrojan-Ransom.Win32.Stop.aa
GDataDeepScan:Generic.Mint.Zamg.8.157FE130
TACHYONRansom/W32.Stop.415744
AhnLab-V3Trojan/Win32.MalPe.R270054
Acronissuspicious
VBA32BScope.Trojan.Downloader
ALYacTrojan.Ransom.Stop
MAXmalware (ai score=100)
MalwarebytesTrojan.MalPack.GS
TrendMicro-HouseCallRansom.Win32.STOP.THCBEAI
RisingRansom.Stop!8.10810 (CLOUD)
YandexTrojan.Stop!TwkrHMFlgYQ
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.DQHN!tr
BitDefenderThetaGen:NN.ZexaF.34786.umGfaq2PjJnG
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generic.Mint.Zamg.8.157FE130?

Generic.Mint.Zamg.8.157FE130 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment