Malware

Midie.98516 (file analysis)

Malware Removal

The Midie.98516 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Midie.98516 virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Emumerates physical drives
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Midie.98516?


File Info:

name: 8C83DC56E1A9B48BDEE0.mlw
path: /opt/CAPEv2/storage/binaries/5a5d61b3b51cb7cf4bff3a77b952e7e9fc5c769d6b1d367c4242d4c4bf1569a5
crc32: 7B5BCE7B
md5: 8c83dc56e1a9b48bdee0b92e6fabcf93
sha1: 926e5281ce5e030e9ccf1424075d1cdeb4592348
sha256: 5a5d61b3b51cb7cf4bff3a77b952e7e9fc5c769d6b1d367c4242d4c4bf1569a5
sha512: ed34ade282f0c2a134340a3c725a818a6947bdfc033df460d6e92af9b15275e1fcf88e247f0fc7674ad2cc297977f22d837a5454db7086709ed0030cda2b8949
ssdeep: 98304:zb36rqPDOTz3H0aBoJoss1GmL04Iaq/yOSlq/kRHk6UXeW3LYsfmwIi5FBui9AGH:K+bOTz3H0aBoJoss1GmL04Iaq/yXykS3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T174265CA36B06155DD09258B4720E83D355FB5E782E2ED3C3F741FE265AB02CBA624E07
sha3_384: 94d89ed94a0840943f8301f57541ab15006c674e54bb6501166c45d117ee2865f36d9e4f771e67a7da1240a0736ffc7b
ep_bytes: e8fb040000e980feffff558bec5156ff
timestamp: 2018-08-16 00:50:04

Version Info:

0: [No Data]

Midie.98516 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Midie.98516
FireEyeGeneric.mg.8c83dc56e1a9b48b
ALYacGen:Variant.Midie.98516
MalwarebytesGeneric.Malware.AI.DDS
Cybereasonmalicious.6e1a9b
BitDefenderThetaGen:NN.ZexaF.36348.@BW@aOfe4Rlj
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Softcnapp.BC potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Midie.98516
TencentTrojan.Win32.Generic.e
EmsisoftGen:Variant.Midie.98516 (B)
F-SecureHeuristic.HEUR/AGEN.1319114
VIPREGen:Variant.Midie.98516
McAfee-GW-EditionBehavesLike.Win32.Generic.rh
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1319114
XcitiumApplication.Win32.AdWare.Softcnapp.O@80ok4p
ArcabitTrojan.Midie.D180D4
ZoneAlarmHEUR:Trojan.Win32.Generic
GoogleDetected
AhnLab-V3PUP/Win.Downloader.R596563
MAXmalware (ai score=89)
Cylanceunsafe
RisingAdware.Downloader!1.BBEC (CLASSIC)
YandexTrojan.GenAsa!H1D0PP+hMfk
IkarusPUA.Softcnapp
FortinetRiskware/Softcnapp.BC
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (D)

How to remove Midie.98516?

Midie.98516 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment