Malware

Midie.70258 (file analysis)

Malware Removal

The Midie.70258 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Midie.70258 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to identify installed AV products by registry key
  • Attempts to modify proxy settings

Related domains:

d3vngcy706h320.cloudfront.net
bon.sonjelly.club
d2adi7hu49xk5t.cloudfront.net

How to determine Midie.70258?


File Info:

crc32: BBD8DAAA
md5: faed1272b44545c0cf21386edce590ba
name: setup.exe
sha1: 15ceafb11d422f01fad5e7b717a423531fccbfd5
sha256: 84bb5722d167c3e38aaa54d331706014552ab6c5525a677ca9bfb5c920b6b4d6
sha512: 9eb21353d1c651174cf41920dc87cb475d8e14abc48ff4156a3ed17510d847c794f81802b827ea3fa4505b5984e72b6968aa66b0de7d7e5035ab5eefa583e1ce
ssdeep: 24576:NI8J+u8D3c2yjq7Izf3zsXskf8dXNlk4IOt0d3o4BrWnd1SYTadUbSG1swhubMQQ:NIiu3xEjzVmTpoYrmd1Sw1b99hQUbh
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Midie.70258 also known as:

BkavHW32.Packed.
MicroWorld-eScanGen:Variant.Midie.70258
FireEyeGeneric.mg.faed1272b44545c0
CAT-QuickHealTrojan.SurfSodaInfo.M7
McAfeeGenericRXIV-IQ!FAED1272B445
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0055bb171 )
BitDefenderGen:Variant.Midie.70258
K7GWTrojan ( 0055bb171 )
Cybereasonmalicious.11d422
BitDefenderThetaGen:NN.ZexaF.34084.KIZ@a0vC2Fdi
F-ProtW32/Kryptik.AQV.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GYRB
GDataWin32.Trojan.Kryptik.OS
Kasperskynot-a-virus:AdWare.Win32.StartSurf.vlbj
AlibabaAdWare:Win32/StartSurf.7760b0a1
TencentWin32.Adware.Startsurf.Ehib
Endgamemalicious (high confidence)
SophosIStartSurfInstaller (PUA)
F-SecureTrojan.TR/Dropper.Gen
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Midie.70258 (B)
APEXMalicious
CyrenW32/Kryptik.AQV.gen!Eldorado
AviraTR/Dropper.Gen
MAXmalware (ai score=83)
Antiy-AVLGrayWare/Win32.Kryptik.guot
MicrosoftTrojan:Win32/Wacatac.D!ml
ArcabitTrojan.Midie.D11272
ZoneAlarmnot-a-virus:AdWare.Win32.StartSurf.vlbj
SentinelOneDFI – Malicious PE
Acronissuspicious
ALYacGen:Variant.Midie.70258
Ad-AwareGen:Variant.Midie.70258
MalwarebytesTrojan.IStartSurf
PandaTrj/Genetic.gen
RisingDropper.Generic!8.35E (TFE:dGZlOgVL5pCyOs25VA)
IkarusPUA.ICLoader
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.BVKS!tr
AVGFileRepMetagen [Adw]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM20.1.FC1B.Malware.Gen

How to remove Midie.70258?

Midie.70258 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment