Malware

About “Generic.Mulinex.70DBAFCA” infection

Malware Removal

The Generic.Mulinex.70DBAFCA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Mulinex.70DBAFCA virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Empties the Recycle Bin, indicative of ransomware
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Mulinex.70DBAFCA?


File Info:

name: A01B0FBC98FFB2B2B32D.mlw
path: /opt/CAPEv2/storage/binaries/b817890ae1252f791cba9ff8bfdda43c0dd1b9f69cd045fa78f9f5d1dade869a
crc32: 890AE373
md5: a01b0fbc98ffb2b2b32d81a579969a26
sha1: bd58c29dd6708f749bee06a2b04179fc843b1c94
sha256: b817890ae1252f791cba9ff8bfdda43c0dd1b9f69cd045fa78f9f5d1dade869a
sha512: b031d57e4df0cf796a265fb7c08f4cfb3da4ad9e151632b18eaf437cf0054e3415256f20dec6274f0c6c8e9a619ad3fb083d672b3e5a9b1d170f9d296a7a196e
ssdeep: 12288:Qg0kk4Mqqi4XuuJwtPslNP38wwio8hWs8qaOG7xw:L0qoRwtEz8wfo8LaOGdw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T125C4121F261494A1D88C8C30C9A78AB96E24FD52CD416A8FFAB47F4E3D367C0B11658F
sha3_384: 0762b12a39abb3640df976d223e597dc91b61cdda4ad1ff491ec1d75e9e88ebf33a4dd80cc7aca01b0e61925bd00b76c
ep_bytes: 60be00604d008dbe00b0f2ff5783cdff
timestamp: 2021-12-10 19:21:15

Version Info:

CompanyName: Babylon Software Ltd.
FileDescription: Babylon Setup SE
FileVersion: 10.1.0.0
InternalName: Setup Stub
LegalCopyright: Copyright © Babylon Software Ltd. 1997-2016
OriginalFilename: SetupStub.exe
ProductName: Babylon Setup
ProductVersion: 10.1.0.0
Translation: 0x0409 0x04b0

Generic.Mulinex.70DBAFCA also known as:

Elasticmalicious (high confidence)
ClamAVMultios.Coinminer.Miner-6781728-2
FireEyeGeneric.mg.a01b0fbc98ffb2b2
CAT-QuickHealPUA.BitminRI.S9338387
McAfeeGenericRXAA-AA!A01B0FBC98FF
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.c98ffb
BitDefenderThetaGen:NN.ZexaF.34084.ImLfaaJ0gGej
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecMiner.XMRig
ESET-NOD32a variant of Win32/CoinMiner.BUF
AvastWin32:CoinMiner-M [Trj]
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:RiskTool.Win32.BitMiner.gen
BitDefenderGeneric.Mulinex.70DBAFCA
MicroWorld-eScanGeneric.Mulinex.70DBAFCA
Ad-AwareGeneric.Mulinex.70DBAFCA
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
BaiduWin32.Trojan.Farfli.e
EmsisoftGeneric.Mulinex.70DBAFCA (B)
GDataWin32.Trojan.PSE.12FI8JT
JiangminTrojan.Miner.mmk
eGambitUnsafe.AI_Score_99%
AviraHEUR/AGEN.1136186
Antiy-AVLTrojan/Generic.ASCommon.FA
ArcabitGeneric.Mulinex.70DBAFCA
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
Acronissuspicious
VBA32BScope.Backdoor.Poison
ALYacGeneric.Mulinex.70DBAFCA
MAXmalware (ai score=87)
MalwarebytesRiskWare.BitCoinMiner
APEXMalicious
RisingMalware.Heuristic!ET#98% (RDMK:cmRtazoh3vev46Q77jxh0mKmVmVa)
YandexTrojan.GenAsa!CnhHeVv4fes
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.ELG!tr.pws
AVGWin32:CoinMiner-M [Trj]
PandaTrj/Genetic.gen

How to remove Generic.Mulinex.70DBAFCA?

Generic.Mulinex.70DBAFCA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment