Malware

What is “Midie.107456”?

Malware Removal

The Midie.107456 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Midie.107456 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Midie.107456?


File Info:

name: F6A1711A033BF09890A0.mlw
path: /opt/CAPEv2/storage/binaries/c65666e160e67d7a382e252a144a16350db111341023a5980a80515e76e4acc7
crc32: 06926AF2
md5: f6a1711a033bf09890a0a7b232d07bde
sha1: 8f8ede09e7ce69a8d950977ad8c983e1294d60b2
sha256: c65666e160e67d7a382e252a144a16350db111341023a5980a80515e76e4acc7
sha512: 34f83af01de6da8d58b6d387b43e235266ca495869029cdeda0d0070349a16fa5e6fec1e4668997519840ce105a942f2676cdea8b1e03b5c71fd2b793041b90e
ssdeep: 24576:uxUI1wNDgl7fsE9oxX5bgBCgTvBs1ZjWpnnY:uXZ7joxJ+TS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B925AE13E58180F2D414267661F79B35AEB097160E25CED3B7A4DE792C22792EE3B30D
sha3_384: e526416af7522b0d52efd97bc6b5460ac116b8ca20892229909daebb19a64523654363e7a54f7ba4d7b00586c9238fe7
ep_bytes: 558bec6aff68d0b64c006884ed480064
timestamp: 2022-01-15 12:04:23

Version Info:

0: [No Data]

Midie.107456 also known as:

LionicTrojan.Multi.Generic.lx0k
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Midie.107456
FireEyeGeneric.mg.f6a1711a033bf098
McAfeeGenericRXAA-AA!F6A1711A033B
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005246d51 )
AlibabaBackdoor:Win32/Saklof.8f7401a4
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.a033bf
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/FlyStudio.OLX
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Scar-18
KasperskyHEUR:Backdoor.Win32.Saklof.gen
BitDefenderGen:Variant.Midie.107456
NANO-AntivirusRiskware.Win32.FlyStudio.hnvnjh
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.11a51471
EmsisoftGen:Variant.Midie.107456 (B)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
McAfee-GW-EditionBehavesLike.Win32.Dropper.dh
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan.BitCoinMiner.hi
eGambitUnsafe.AI_Score_99%
AviraBDS/Redcap.emtns
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojanDownloader:Win32/Emotet!ml
ViRobotTrojan.Win32.Z.Graftor.970752.B
ZoneAlarmHEUR:Backdoor.Win32.Saklof.gen
GDataWin32.Trojan.Flyagent.A
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R273919
BitDefenderThetaGen:NN.ZexaF.34182.7qW@a0uyCDfb
ALYacGen:Variant.Midie.107456
MAXmalware (ai score=86)
VBA32BScope.Trojan.Dynamer
MalwarebytesTrojan.MalPack.FlyStudio
TrendMicro-HouseCallTROJ_GEN.R002H0CB422
RisingSpyware.KeyLogger!1.65B5 (CLOUD)
YandexTrojan.GenAsa!DTDJ/jK7DWk
IkarusTrojan.Win32.FlyAgent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.65CA!tr
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Midie.107456?

Midie.107456 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment