Malware

Malware.AI.1211230042 information

Malware Removal

The Malware.AI.1211230042 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1211230042 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • CAPE detected the GloomaneStealer malware family

How to determine Malware.AI.1211230042?


File Info:

name: 01AE402B71AEBD892D74.mlw
path: /opt/CAPEv2/storage/binaries/97bb145412fb29e308287706c032c2cd3364b058dcf5d15bdd44eaedbbba260a
crc32: 88121926
md5: 01ae402b71aebd892d74323686fd458e
sha1: b536548c740d302f8a52ccae1f047b71d3f4790c
sha256: 97bb145412fb29e308287706c032c2cd3364b058dcf5d15bdd44eaedbbba260a
sha512: 61ed2c93a5f22d4e5e4926c1b5d8768ced7f8d36d545a077e340002646e0a72f231591c85166f7295a1a9cf360f91e7d2094a8ceac1a063430aac1deab069081
ssdeep: 12288:MToPWBv/cpGrU3y2lrnSGwhUkhpp3Mmo7JwJTY9L5ms3txEWU3Rby8:MTbBv5rUpZtwdhpp8mo8T1MtWRb5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10DA6BE05B6858FFDC26117F50721EE20973BBC760AD35BABD350B1BE9960387B221365
sha3_384: 063141a2ad2427b1b6c176d222ace8e30939a9d27fa9181f262da713c7fd2f0b3a889e1977dc02fc1eaec79383f6acdf
ep_bytes: e866050000e978feffffcccccccccccc
timestamp: 2022-03-03 13:15:57

Version Info:

0: [No Data]

Malware.AI.1211230042 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
FireEyeGeneric.mg.01ae402b71aebd89
ALYacIL:Trojan.MSILMamut.3266
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderIL:Trojan.MSILMamut.3266
EmsisoftIL:Trojan.MSILMamut.3266 (B)
VIPREIL:Trojan.MSILMamut.3266
McAfee-GW-EditionBehavesLike.Win32.Generic.tz
SophosGeneric ML PUA (PUA)
Antiy-AVLTrojan/Generic.ASCommon.24D
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataIL:Trojan.MSILMamut.3266
CynetMalicious (score: 100)
Acronissuspicious
MAXmalware (ai score=89)
MalwarebytesMalware.AI.1211230042
APEXMalicious
Cybereasonmalicious.b71aeb

How to remove Malware.AI.1211230042?

Malware.AI.1211230042 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment