Malware

Generic.Mulinex.735361BF (file analysis)

Malware Removal

The Generic.Mulinex.735361BF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Mulinex.735361BF virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Empties the Recycle Bin, indicative of ransomware
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Mulinex.735361BF?


File Info:

name: F8EA8B6210C6624973F2.mlw
path: /opt/CAPEv2/storage/binaries/ddce0c8719c84770c8f4cad669e3c0d1bb730617a3bc4f875168d741e5a5ae6f
crc32: B19467F9
md5: f8ea8b6210c6624973f2754b263f8bb8
sha1: cc14002ce1d150a94241d5a4e4cb92dc416af126
sha256: ddce0c8719c84770c8f4cad669e3c0d1bb730617a3bc4f875168d741e5a5ae6f
sha512: a51e3d76a1a99a485fa38eb7a8cb0ce8b38b533d7c5c199ebae61e149ea08be5de80bcdf0f0554f916ad546094d6bf9011f02d9cc20372d283d31952e5fdf729
ssdeep: 12288:U8uJm8PlnjP9Z+0fxMfB9QZv6quW+ehS/KX5vlVrA:U8uJtVRoiifB9QZvTuWLhS4vlVrA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19AC412AEA70C9873D55D8D31C913D6B15F18BD018D82094FABB8BF8D7CB46907F2960A
sha3_384: 958a8cf0775ceba612c250519b82ed9797a521091ea6cc275b0cb931fc4e0fd7bf3d3e72314b646fe32993160f5bb006
ep_bytes: 60be00804d008dbe0090f2ff5783cdff
timestamp: 2021-12-20 19:14:44

Version Info:

CompanyName: NebulaSoft
ProductName: minipad2
ProductVersion: 3.2.0
InternalName: minipad2
OriginalFilename: minipad2.exe
FileDescription: minipad2
FileVersion: 3.2.0
LegalCopyright: Copyright (c) 2007-2010 NebulaSoft
Comments: This program is a freeware!

Generic.Mulinex.735361BF also known as:

LionicVirus.Win32.Parite.mfeV
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.f8ea8b6210c66249
CAT-QuickHealPUA.BitminRI.S9338387
McAfeeGenericRXAA-AA!F8EA8B6210C6
ZillyaTrojan.CoinMiner.Win32.41451
K7AntiVirusTrojan ( 00543b431 )
BitDefenderGeneric.Mulinex.735361BF
K7GWTrojan ( 00543b431 )
ArcabitGeneric.Mulinex.DB3881BF
BaiduWin32.Trojan.Farfli.e
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecMiner.XMRig
ESET-NOD32a variant of Win32/CoinMiner.BUF
APEXMalicious
ClamAVMultios.Coinminer.Miner-6781728-2
Kasperskynot-a-virus:HEUR:RiskTool.Win32.BitMiner.gen
AlibabaRiskWare:Win32/BitMiner.8323e809
MicroWorld-eScanGeneric.Mulinex.735361BF
RisingBackdoor.Agent!1.B7E4 (CLASSIC)
Ad-AwareGeneric.Mulinex.735361BF
DrWebTrojan.BtcMine.3404
TrendMicroTROJ_GEN.R002C0DLR21
EmsisoftGeneric.Mulinex.735361BF (B)
SentinelOneStatic AI – Malicious PE
JiangminRiskTool.BitMiner.coah
AviraHEUR/AGEN.1126575
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.FlyStudio.a
KingsoftWin32.Heur.KVM099.a.(kcloud)
GridinsoftRansom.Win32.Miner.sa
GDataWin32.Trojan.PSE.5LSHNI
AhnLab-V3Unwanted/Win.BitMiner.R460818
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34114.ImLfa8yTgkbb
ALYacGeneric.Mulinex.735361BF
VBA32BScope.Trojan.Dynamer
MalwarebytesRiskWare.BitCoinMiner
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DLR21
TencentMalware.Win32.Gencirc.10cfa473
YandexTrojan.CoinMiner!M0/mevrRRuQ
IkarusWorm.Win32.Nuj
eGambitUnsafe.AI_Score_99%
FortinetW32/CoinMiner.ELG!tr.pws
WebrootW32.Malware.Gen
AVGWin32:CoinMiner-M [Trj]
Cybereasonmalicious.210c66
AvastWin32:CoinMiner-M [Trj]

How to remove Generic.Mulinex.735361BF?

Generic.Mulinex.735361BF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment