Malware

Midie.105613 removal

Malware Removal

The Midie.105613 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Midie.105613 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Spanish (Ecuador)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location

How to determine Midie.105613?


File Info:

name: 5944A08E1A6F87B81695.mlw
path: /opt/CAPEv2/storage/binaries/1ec9b917dedc391f6f0b0793678da836b011d1f9bb02b9ad97440dc6f04d391b
crc32: 1BDCE7B7
md5: 5944a08e1a6f87b81695ca9ff0a75a1c
sha1: 01807c94550e334181c4f3081e9143e8c732808d
sha256: 1ec9b917dedc391f6f0b0793678da836b011d1f9bb02b9ad97440dc6f04d391b
sha512: dc42f7a292b93ccd80d3c2e1e8a4080ea0707895d722428538d39f429146056d077c6750585406f3c2af52e14edc2458f7cea94c8327978394c98018328ad7a6
ssdeep: 3072:HcrNLcaL1I0AEC+hkSxO87VyXa5RK3GsiphsZVggjcGkNIVqIZ52:HcrNLJt1kSe6wGsi8b7ITsqt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12B14AED076E2C4B2C6A2763054609FE50E3FB871D970854BF37853AE1F762E24AE6316
sha3_384: f908675fca42d5f0087b43a89fd40826a152fbd55855055e2b10c2abe19842cd396d046187786d6a6e757aa98b3b56d7
ep_bytes: e850440000e979feffffcccccccccccc
timestamp: 2021-04-15 03:25:21

Version Info:

InternalName: bomgpiaruci.iwa
Copyright: Copyrighz (C) 2021, fudkat
ProductVersion: 23.54.77.27
Translation: 0x0127 0x046a

Midie.105613 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Fsysna.4!c
Elasticmalicious (high confidence)
ClamAVWin.Dropper.Tepfer-9916200-0
McAfeeLockbit-FSWW!5944A08E1A6F
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Midie.105613
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.4550e3
CyrenW32/Kryptik.FWV.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNQM
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Exploit.Win32.Shellcode.gen
AlibabaTrojan:Win32/Azorult.4563301d
NANO-AntivirusExploit.Win32.Shellcode.jjhslb
ViRobotTrojan.Win32.Z.Jaik.194560
MicroWorld-eScanGen:Variant.Midie.105613
TencentTrojan-Spy.Win32.Stealer.16000121
Ad-AwareGen:Variant.Midie.105613
SophosML/PE-A + Troj/Krypt-BO
DrWebTrojan.Siggen16.6142
TrendMicroTROJ_GEN.R002C0PLB21
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.5944a08e1a6f87b8
EmsisoftTrojan.Crypt (A)
IkarusTrojan-Ransom.StopCrypt
GDataWin32.Trojan.BSE.13HWNF8
JiangminBackdoor.Mokes.ewn
MAXmalware (ai score=85)
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Azorult.RMA!MTB
AhnLab-V3Trojan/Win.MalPE.R457622
Acronissuspicious
VBA32BScope.TrojanDropper.Convagent
ALYacGen:Variant.Midie.105613
MalwarebytesTrojan.MalPack.GS
TrendMicro-HouseCallTROJ_GEN.R002C0PLB21
RisingTrojan.Generic@ML.94 (RDMK:l42+q9zE2T2oTQqCy9mJeA)
SentinelOneStatic AI – Malicious PE
FortinetW32/Stealer.3174!tr
BitDefenderThetaGen:NN.ZexaF.34114.lu0@aONKgCHG
AVGWin32:CrypterX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Midie.105613?

Midie.105613 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment