Malware

Mint.Zard.5 (file analysis)

Malware Removal

The Mint.Zard.5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mint.Zard.5 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Mint.Zard.5?


File Info:

name: 938EBDBE4DDEAD50D8A7.mlw
path: /opt/CAPEv2/storage/binaries/159f98b81f5efa5081e4b2ee9080aac4927bda7ce786a224a6dd6907688fab04
crc32: F646A319
md5: 938ebdbe4ddead50d8a7c57251428711
sha1: 333a612f57d6980dd1cd719d84b0abf06f50b9a6
sha256: 159f98b81f5efa5081e4b2ee9080aac4927bda7ce786a224a6dd6907688fab04
sha512: b37e75b28a879937385b9785aef98842038469b6623698fccfeac9b78cca17492d014bd9b4132e850b12a9fc2ab9ef57a2d11bb1e59a2d92508f23c74d0f4c92
ssdeep: 24576:T/XhNyVN2h6WWkm/mGwnTeCfVYb0ZkcLmHvHQR5:zxN2ch6xHzIJCQ0wR5
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1FE35273271FAC6E0D5523535EC2B72F05968ED60DA249C9F7EA8BF093874991F97020E
sha3_384: 69b4a79871f167d7a5786774dbeece4d76b01544799f37f58f734ff89d3ac79bb105afe8407a31c72e31e7211b6282fb
ep_bytes: 558bec837d0c017505e87d030000ff75
timestamp: 2021-02-14 14:40:11

Version Info:

LegalCopyright: Copyright 1984-2021 Adobe Systems Incorporated and its licensors. All rights reserved.
ProductName: Adobe PDF Browser Control
CompanyName: Adobe Systems, Inc.
FileDescription: PDF Browser Control
FileVersion: 21.1.20138.422477
ProductVersion: 21.1.20138.422477
InternalName: AcroPDFImpl
OriginalFilename: AcroPDFImpl.dll
Translation: 0x0409 0x04b0

Mint.Zard.5 also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Senoval.n!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Mint.Zard.5
FireEyeGen:Variant.Mint.Zard.5
SkyhighBehavesLike.Win32.Dropper.th
Cylanceunsafe
AlibabaVirus:Win32/Senoval.2882420e
K7GWTrojan ( 005ab4bf1 )
K7AntiVirusTrojan ( 005ab4bf1 )
SymantecTrojan.Gen.6
ESET-NOD32a variant of Win32/Patched.NKM
AvastWin32:Patched-AWW [Trj]
KasperskyVirus.Win32.Senoval.a
BitDefenderGen:Variant.Mint.Zard.5
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
TencentTrojan.Win32.Pathced_ya.16001052
EmsisoftGen:Variant.Mint.Zard.5 (B)
F-SecureTrojan.TR/Patched.Gen
DrWebWin32.Beetle.3
VIPREGen:Variant.Mint.Zard.5
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Patched
MAXmalware (ai score=80)
GoogleDetected
AviraTR/Patched.Gen
VaristW32/Convagent.DU.gen!Eldorado
Antiy-AVLTrojan/Win32.GenKryptik
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Mint.Zard.5
ZoneAlarmVirus.Win32.Senoval.a
GDataGen:Variant.Mint.Zard.5
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.R607092
VBA32BScope.TrojanDownloader.Emotet
ALYacGen:Variant.Mint.Zard.5
RisingTrojan.Generic@AI.100 (RDML:i/qKdKmQaTrCIuRO2hPHEg)
FortinetW32/Agent_AGen.CEQ!tr
AVGWin32:Patched-AWW [Trj]

How to remove Mint.Zard.5?

Mint.Zard.5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment