Malware

Malware.AI.106070570 (file analysis)

Malware Removal

The Malware.AI.106070570 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.106070570 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • NtSetInformationThread: attempt to hide thread from debugger
  • Attempts to connect to a dead IP:Port (255 unique times)
  • Dynamic (imported) function loading detected
  • Manipulates data from or to the Recycle Bin
  • Authenticode signature is invalid
  • Writes a potential ransom message to disk
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Exhibits possible ransomware file modification behavior
  • CAPE detected the Conti malware family
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Malware.AI.106070570?


File Info:

name: 01D66A03A0DE2EE2EACA.mlw
path: /opt/CAPEv2/storage/binaries/2280898cb29faf1785e782596d8029cb471537ec38352e5c17cc263f1f52b8ef
crc32: 7F8AF871
md5: 01d66a03a0de2ee2eacacaa3ac98f0aa
sha1: 1bab1913533d5748e9cda388f55c446be6b770ff
sha256: 2280898cb29faf1785e782596d8029cb471537ec38352e5c17cc263f1f52b8ef
sha512: 50892810b3bd3e0ed0d94a0eacacc785f159031aafda7513c5a9cfdbafbfa4fb036fb66515ad076972ba94c5c32ad04dff0db688728ff9230eb1fa9aa88f5f96
ssdeep: 1536:G+5geBR2Q+a8M124Zl2i5SADBDg8trv4t9MBY5ytv:GDeBgQ+a8M12Y2i59hrvWMBxv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12563D64AB749EB30F59694B996FC2A17688E8938835F85C3FBD0C05A7651CC6B834F13
sha3_384: acafc9521cf92461d19de5ec41f5edc55e805e4d9893a9b0406e29c1a868c7819b56688705c5214be048753ae2040dac
ep_bytes: e89bfeffff33c0c21000cccccccccccc
timestamp: 2085-02-07 16:05:31

Version Info:

0: [No Data]

Malware.AI.106070570 also known as:

BkavW32.AIDetect.malware2
ElasticWindows.Ransomware.Conti
MicroWorld-eScanGen:Variant.Lazy.202657
FireEyeGeneric.mg.01d66a03a0de2ee2
CylanceUnsafe
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Agent.CC.gen!Eldorado
SymantecRansom.Conti!gm1
ESET-NOD32a variant of Win32/Filecoder.OLQ
APEXMalicious
KasperskyVHO:Trojan-Ransom.Win32.GenericCryptor.gen
BitDefenderGen:Variant.Lazy.202657
AvastWin32:RansomX-gen [Ransom]
Ad-AwareGen:Variant.Lazy.202657
EmsisoftGen:Variant.Lazy.202657 (B)
DrWebTrojan.Encoder.35508
Trapminemalicious.high.ml.score
GDataGen:Variant.Lazy.202657
AviraTR/Crypt.XPACK.Gen
ArcabitTrojan.Lazy.D317A1
MicrosoftRansom:Win32/Conti.AD!MTB
CynetMalicious (score: 100)
AhnLab-V3Ransomware/Win.Bluesky.R500579
BitDefenderThetaAI:Packer.FE4668891E
ALYacGen:Trojan.Heur.JP.emW@aOOc95i
MAXmalware (ai score=81)
MalwarebytesMalware.AI.106070570
RisingTrojan.Generic@AI.98 (RDML:JeugBfFDce+UD7P/+EnTCw)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:RansomX-gen [Ransom]
Cybereasonmalicious.3a0de2

How to remove Malware.AI.106070570?

Malware.AI.106070570 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment