Malware

Malware.AI.1211913778 information

Malware Removal

The Malware.AI.1211913778 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1211913778 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Anomalous binary characteristics

Related domains:

iplogger.org
hypercustom.top

How to determine Malware.AI.1211913778?


File Info:

crc32: A3780AAE
md5: 2252bec66525b5035b5ed9a50f11d11a
name: 2252BEC66525B5035B5ED9A50F11D11A.mlw
sha1: 6776b1d4679ef7a2f63e319fe460eaf274790a1d
sha256: 8759be706226532ae8ccbc54b40a1dbd51f8820782a2e6f429a908907566ef26
sha512: 809978a3415d230c64d651a7f2e66152125612d3ecc25b812db6e37036db2cf5c7d37ae75cefbef140b30aadd5e8ad6d8ade3dc3939f181a2131b7e57c650f4f
ssdeep: 12288:4QnyuSAWovHs1h/9lDk3Thdg1jCU3V/izhLvf/UJubSlx4XATDM/:SuSAWL9lD6ncCjXTsOXAHM/
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x120a 0x0524

Malware.AI.1211913778 also known as:

LionicTrojan.Win32.Vidar.i!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.26450
CynetMalicious (score: 100)
ALYacDeepScan:Generic.SpyAgent.6.3DC03623
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojanPSW:Win32/Vidar.f0ef4901
Cybereasonmalicious.d6e199
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.Agent.OGR
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan-PSW.Win32.Vidar.gen
BitDefenderDeepScan:Generic.SpyAgent.6.3DC03623
MicroWorld-eScanDeepScan:Generic.SpyAgent.6.3DC03623
TencentWin32.Trojan-qqpass.Qqrob.Dztu
Ad-AwareDeepScan:Generic.SpyAgent.6.3DC03623
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34088.NmW@aSIxPPb
McAfee-GW-EditionBehavesLike.Win32.Generic.jh
FireEyeGeneric.mg.80be083d6e199ea9
EmsisoftDeepScan:Generic.SpyAgent.6.3DC03623 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.Vidar.my
AviraHEUR/AGEN.1143724
Antiy-AVLTrojan/Generic.ASMalwS.33A691A
MicrosoftTrojan:Win32/Vidar.AA!MTB
ZoneAlarmHEUR:Trojan-PSW.Win32.Vidar.gen
GDataDeepScan:Generic.SpyAgent.6.3DC03623
AhnLab-V3Trojan/Win.SpyAgent.C4514567
McAfeeGenericRXON-BR!80BE083D6E19
MAXmalware (ai score=81)
VBA32suspected of Trojan.Downloader.gen
MalwarebytesMalware.AI.1211913778
PandaTrj/GdSda.A
RisingStealer.Arkei!1.B243 (CLASSIC)
IkarusTrojan-PSW.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.OGR!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Malware.AI.1211913778?

Malware.AI.1211913778 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment