Malware

About “Malware.AI.1128222520” infection

Malware Removal

The Malware.AI.1128222520 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1128222520 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Unconventionial language used in binary resources: Hungarian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Steals private information from local Internet browsers
  • Sets an Autoconfig URL, likely to hijack browser settings.
  • Creates a hidden or system file
  • A powershell command using multiple variables was executed possibly indicative of obfuscation
  • Suspicious use of certutil was detected
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.1128222520?


File Info:

name: 95036B684DD6DEE0F2E9.mlw
path: /opt/CAPEv2/storage/binaries/e7f0cb4e70b33b102877a3f908ce5687fca69ed53943adac80cd295ccc1c3654
crc32: B4C62A34
md5: 95036b684dd6dee0f2e9cede47eddb27
sha1: 81e763561b5d5a04fdefd655803a8a43dc5fdeb3
sha256: e7f0cb4e70b33b102877a3f908ce5687fca69ed53943adac80cd295ccc1c3654
sha512: 38e792d3eccaa81e6f9c705d2e749bf4bd69cbd994fb36efe49c923249f26809a2b3b30ee64a96564e8e7902346c0eee96d1284c60c6ed173f6b969dc59c4915
ssdeep: 3072:6gfEcEuYWqLHltRMpS7XLE9h91qmFqDkdF8RZJtOxNuZwFqLE:RuLFBQ9h9P+fSuZDI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15F24AD139B132DC2F08186F1C9D65BA45AEF6973EAB5F09FEF2019CD44E76949F80821
sha3_384: 2fc192facc9055926ee868e3806936f44c8e451b93e1e53a744a74cf2aa73d33a9624c6ac509adb00c6cb0a1fc090f85
ep_bytes: 9c608bff9090558bec6aff6858574000
timestamp: 2015-09-03 18:57:34

Version Info:

0: [No Data]

Malware.AI.1128222520 also known as:

LionicTrojan.Win32.Inject.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Zbot.IQP
FireEyeGeneric.mg.95036b684dd6dee0
CAT-QuickHealTrojanPWS.Zbot.A4
ALYacTrojan.Zbot.IQP
CylanceUnsafe
ZillyaTrojan.Inject.Win32.178800
SangforTrojan.Win32.Dorv.A
K7AntiVirusTrojan ( 0055e3991 )
AlibabaTrojan:Win32/Inject.441b948f
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.84dd6d
BitDefenderThetaGen:NN.ZexaF.34294.oqX@aWFf4YxH
CyrenW32/Trojan.ZTXI-1668
SymantecTrojan.Gen
ESET-NOD32a variant of Win32/Injector.CIJU
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.AppWizard-7495422-1
KasperskyTrojan.Win32.Inject.vhgp
BitDefenderTrojan.Zbot.IQP
NANO-AntivirusTrojan.Win32.Dwn.dwssav
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10b7151b
Ad-AwareTrojan.Zbot.IQP
TACHYONTrojan/W32.Inject.229876
SophosMal/Generic-S + Mal/Zbot-UE
ComodoMalware@#mbwg3vnfyikc
DrWebTrojan.Siggen6.23087
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_XPACK.SM1
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
EmsisoftTrojan.Zbot.IQP (B)
IkarusTrojan.Win32.Injector
GDataTrojan.Zbot.IQP
JiangminTrojan/Inject.bchq
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1128856
Antiy-AVLTrojan/Generic.ASMalwS.1444533
GridinsoftRansom.Win32.Zbot.sa
ViRobotTrojan.Win32.Z.Zbot.229876
MicrosoftPWS:Win32/Zbot!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.CryptoWall.C975615
McAfeeGeneric-FAWT!95036B684DD6
MAXmalware (ai score=85)
VBA32Trojan.Inject
MalwarebytesMalware.AI.1128222520
TrendMicro-HouseCallTROJ_XPACK.SM1
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
YandexTrojan.GenAsa!9BOSi0fVczw
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Generic.AC.29EDB6!tr
AVGWin32:Malware-gen
PandaTrj/Injector.BD
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.1128222520?

Malware.AI.1128222520 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment