Malware

Mikey.113302 (file analysis)

Malware Removal

The Mikey.113302 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mikey.113302 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Tries to unhook or modify Windows functions monitored by Cuckoo

Related domains:

www.baidu.com

How to determine Mikey.113302?


File Info:

crc32: 5B32D090
md5: a7f15b790b50684e6be4d5df5149f562
name: A7F15B790B50684E6BE4D5DF5149F562.mlw
sha1: 9e7ef5f689806f398f0f6b27c11f17f7a441faba
sha256: 8395925f2517106b0e023f3f0292ea5b3db8d541207451ee254d32ac40d8e8ed
sha512: 8fbf54b06e0c38afe1fe26ff928af06755b7fdb643cd78f290c7ee9f1f0a3b8574104e8b52bf7075acf98832de16e65caae47c01165251add14d6b94faad8c1d
ssdeep: 12288:GfBUW+9koJFPVKPfHHz5wYHuoJkn6fy3zkED9nNj/1nXFDqv3fxss6Usk+Fe:GpQ5FwHHHz5w6kn2yjkm91XFDKMNfe
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: x4f5cx8005x7248x6743x6240x6709 x8bf7x5c0ax91cdx5e76x4f7fx7528x6b63x7248
FileVersion: 1.0.0.0
Comments: Azur lane
ProductName: Azur lane
ProductVersion: 1.0.0.0
FileDescription: Azur lane
Translation: 0x0804 0x04b0

Mikey.113302 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Mikey.113302
CylanceUnsafe
BitDefenderGen:Variant.Mikey.113302
Cybereasonmalicious.90b506
CyrenW32/Agent.EW.gen!Eldorado
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
ClamAVWin.Malware.Generic-9820446-0
KasperskyVHO:Trojan.Win32.Agent.gen
NANO-AntivirusVirus.Win32.Agent.dvixmz
MicroWorld-eScanGen:Variant.Mikey.113302
Ad-AwareGen:Variant.Mikey.113302
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
BitDefenderThetaGen:NN.ZexaF.34692.YmKfaa52Fqfb
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.a7f15b790b50684e
EmsisoftGen:Variant.Mikey.113302 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.VBKrypt.dpcn
eGambitUnsafe.AI_Score_99%
MicrosoftProgram:Win32/Wacapew.C!ml
ArcabitTrojan.Mikey.D1BA96
GDataGen:Variant.Mikey.113302
McAfeeFlyagent.d
MAXmalware (ai score=83)
RisingMalware.Heuristic!ET#99% (RDMK:cmRtazoEN58fOGyhfyVm9QPnyqIE)
IkarusTrojan.Tonmye
MaxSecureVirus.Nimnul.E
FortinetW32/CoinMiner.BELF!tr

How to remove Mikey.113302?

Mikey.113302 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment