Malware

Midie.104874 (B) removal instruction

Malware Removal

The Midie.104874 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Midie.104874 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Urdu (India)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to restart the guest VM
  • Uses IOCTL_SCSI_PASS_THROUGH control codes to manipulate drive/MBR which may be indicative of a bootkit
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Network activity detected but not expressed in API logs
  • Attempted to write directly to a physical drive

Related domains:

wpad.local-net

How to determine Midie.104874 (B)?


File Info:

name: 6B96FF2E195892C27ECC.mlw
path: /opt/CAPEv2/storage/binaries/7a77dc9a5829308c4c5e2f48c39551e8e88a6b458e1c0489b77d28bf2ff53eac
crc32: 9CE6892F
md5: 6b96ff2e195892c27eccc33e782cd8a9
sha1: fc16d54e0b7966c8b0ed399a2485e803a1ded3c7
sha256: 7a77dc9a5829308c4c5e2f48c39551e8e88a6b458e1c0489b77d28bf2ff53eac
sha512: a99a45e70e35fe1ea469e9b5342953bf972771fd21f7ec9b9e3ab9fa4425f6e7a9b16bcf4f0ff774be6d18c78c9afc0e31871c508b3eb69c1e9414d925b2d960
ssdeep: 12288:7RCIGOwnBL2QocTA3u91bxOXl+7Gw3sYSvulR0m:7ExdBLA3ixKl+7r7f
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14FB4021036F0B070C7A26A32EDB49B753F36B8B12670549F3768162F2E327D05AA5367
sha3_384: cde2a3d11a876a769eba27b70fb8c44322e50e8f2fbeca2d905165e5a97742c4b330c78863b74282ab1e3f91e621de28
ep_bytes: e8502a0000e989feffffcccccccccccc
timestamp: 2020-11-01 04:21:41

Version Info:

InternalName: bomgpiaruci.iwa
Copyright: Copyrighz (C) 2021, fudkat
ProductVersion: 13.54.77.27
Translation: 0x0114 0x046a

Midie.104874 (B) also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Midie.104874
FireEyeGeneric.mg.6b96ff2e195892c2
ALYacGen:Variant.Midie.104874
CylanceUnsafe
K7AntiVirusTrojan ( 00589d2d1 )
AlibabaTrojan:Win32/DiskWriter.ea762c49
K7GWTrojan ( 00589d2d1 )
Cybereasonmalicious.e0b796
CyrenW32/Kryptik.FUG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNLX
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.DiskWriter.gen
BitDefenderGen:Variant.Midie.104874
AvastWin32:CrypterX-gen [Trj]
Ad-AwareGen:Variant.Midie.104874
DrWebTrojan.PWS.Stealer.26952
EmsisoftGen:Variant.Midie.104874 (B)
IkarusTrojan-Ransom.StopCrypt
GDataWin32.Trojan.BSE.11GYDBI
MAXmalware (ai score=88)
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.AzorUlt.sa
MicrosoftTrojan:Win32/Azorult.FW!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.FSWW.R453694
Acronissuspicious
McAfeeLockbit-FSWW!6B96FF2E1958
VBA32Backdoor.Mokes
MalwarebytesTrojan.MalPack
TrendMicro-HouseCallTROJ_GEN.R002H0CKQ21
RisingTrojan.Kryptik!1.DAC3 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Lockbit.FSWW!tr
BitDefenderThetaGen:NN.ZexaF.34062.Fq0@a4o8fnbG
AVGWin32:CrypterX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Midie.104874 (B)?

Midie.104874 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment