Malware

Midie.104322 (file analysis)

Malware Removal

The Midie.104322 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Midie.104322 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (6 unique times)
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Urdu (India)
  • The binary likely contains encrypted or compressed data.
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

apps.identrust.com

How to determine Midie.104322?


File Info:

crc32: 39FD9C1E
md5: ede53997334fa2dec75fdbfec88c94c0
name: EDE53997334FA2DEC75FDBFEC88C94C0.mlw
sha1: ab336738130c9864bac831ede393e9b58793c126
sha256: 10a7e00753a662d72f9b934e336a84d20262b51ae0bb619914f38b558474d0cf
sha512: c229eaf653fc6ef6feab58b45c54394b652a841031285d8e7c6850c866b627ed240e72f95b1812914690b40f1c22ef08b701519fd91084076a6ab0f77d814f73
ssdeep: 12288:1rHacLLMLUiTAPH6Sy0DmKz84tpKfWnKoVzOt:1TfST0TPtk+Kma
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: bomgpiaruci.iwa
ProductVersion: 13.54.37.21
Copyright: Copyrighz (C) 2021, fudkat
Translation: 0x0117 0x046a

Midie.104322 also known as:

K7AntiVirusTrojan ( 00589d2d1 )
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.31482
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 00589d2d1 )
Cybereasonmalicious.8130c9
CyrenW32/Kryptik.FUG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNJN
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Injuke.gen
BitDefenderGen:Variant.Midie.104322
MicroWorld-eScanGen:Variant.Midie.104322
Ad-AwareGen:Variant.Midie.104322
Comodofls.noname@0
BitDefenderThetaGen:NN.ZexaF.34294.Bq0@a4Sj5HoO
TrendMicroTROJ_GEN.R002C0RKJ21
McAfee-GW-EditionBehavesLike.Win32.Lockbit.gc
FireEyeGeneric.mg.ede53997334fa2de
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/StopCrypt.PU!MTB
GDataGen:Variant.Midie.104322
Acronissuspicious
McAfeeGenericRXAA-AA!EDE53997334F
MAXmalware (ai score=86)
VBA32Malware-Cryptor.2LA.gen
MalwarebytesTrojan.MalPack.GS
RisingMalware.Obscure!1.A3BB (CLASSIC)
IkarusTrojan-Ransom.StopCrypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.ETEM!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Midie.104322?

Midie.104322 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment