Malware

Midie.104115 (file analysis)

Malware Removal

The Midie.104115 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Midie.104115 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

api.2ip.ua
kotob.top
pqkl.org
mstdn.social
koyu.space

How to determine Midie.104115?


File Info:

crc32: B7261029
md5: 488c6ac2f202625901a3e02c8308cd5b
name: 488C6AC2F202625901A3E02C8308CD5B.mlw
sha1: b5366938eaabc1c295d9540df4d5d8c123221596
sha256: 9ac996c1fe696b7380021c1fbaacf8e10660f0395bbf7ecfaf4b9894e7da9c00
sha512: 94dcc1ea3c4e31e266841dff8a90237f3581a7fa59dc9ff25f334e93ff5147e495d3afaa1685a728f1c4bc2a553f6585ad016f8de1479dafb163c440ee06c0e5
ssdeep: 12288:9PZy1j67xmjLqb/Qpot1fqqbWSEuWBoVq2s82XgzRhH6JInU:h4k7xmjLqLSofqm1EL2E2CXgthHyn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: bomgpiaruci.iwa
ProductVersion: 13.54.37.21
Copyright: Copyrighz (C) 2021, fudkat
Translation: 0x0187 0x046a

Midie.104115 also known as:

K7AntiVirusTrojan ( 00589d2d1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Stop
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 00589d2d1 )
Cybereasonmalicious.8eaabc
CyrenW32/Kryptik.FUG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNIW
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Packed.Generic-9908949-0
KasperskyHEUR:Trojan.Win32.Scarsi.gen
BitDefenderGen:Variant.Midie.104115
MicroWorld-eScanGen:Variant.Midie.104115
Ad-AwareGen:Variant.Midie.104115
SophosML/PE-A + Mal/Agent-AWV
F-SecureTrojan.TR/Crypt.Agent.oganl
BitDefenderThetaGen:NN.ZexaF.34294.Rq0@aexG6VjO
McAfee-GW-EditionBehavesLike.Win32.Lockbit.jc
FireEyeGeneric.mg.488c6ac2f2026259
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.Agent.oganl
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/StopCrypt.PT!MTB
ArcabitTrojan.Midie.D196B3
GDataGen:Variant.Midie.104115
AhnLab-V3Ransomware/Win.Stop.R450862
Acronissuspicious
McAfeePacked-GEE!488C6AC2F202
MAXmalware (ai score=82)
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
RisingMalware.Heuristic!ET#91% (RDMK:cmRtazrobp+d8j9AoDfXEC8P4rQ3)
IkarusTrojan-Ransom.StopCrypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HNIZ!tr
AVGWin32:Trojan-gen

How to remove Midie.104115?

Midie.104115 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment