Malware

What is “Malware.AI.1212294260”?

Malware Removal

The Malware.AI.1212294260 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1212294260 virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.1212294260?


File Info:

name: 23F96677547AB52739C5.mlw
path: /opt/CAPEv2/storage/binaries/7e197234d2d33defbf2e2c1bccc1efa02ba1ca93782d1e7bc41fa67f091b64f6
crc32: DD2B7D20
md5: 23f96677547ab52739c56d0372b63802
sha1: 79a8febfd02cd7ea20113a428c9d4dd8a6f4ea10
sha256: 7e197234d2d33defbf2e2c1bccc1efa02ba1ca93782d1e7bc41fa67f091b64f6
sha512: 7cf3808fc90dc57cd30824c17c42dc136bdea196924ee61a88cae7328ed8c2bde40dd0f7d004a6b0dfa45019bf663dc6a65240d52b8042f90aab6aead6449783
ssdeep: 12288:9w81KGwUSqNQFJgYIm4Q0ZqN/egbV4bfA1B0XhnDTBjWU7888888888888W8888E:9w84oYIm50Z7DQ2XNI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T186D41213F3CB5476FC8A113D40E28416AE437ABD55E1A5202C35F65E2ABC2EA6CF7D24
sha3_384: cda9a9729bc672621ef7c802267fbf876c3eda189f150aef75fb520a0945dce1cfdeaff563994dbe9e4924bd66c1740e
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 2023-01-09 18:07:51

Version Info:

0: [No Data]

Malware.AI.1212294260 also known as:

tehtrisGeneric.Malware
DrWebTrojan.Fakealert.60377
MicroWorld-eScanGen:Variant.Babar.130640
FireEyeGen:Variant.Babar.130640
ALYacGen:Variant.Babar.130640
Cylanceunsafe
ZillyaTrojan.Agent.Win32.3192386
BitDefenderThetaGen:NN.ZexaE.36308.KSWbaGoijmoj
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/PSW.Agent.OPS
ZonerProbably Heur.ExeHeaderP
APEXMalicious
CynetMalicious (score: 99)
KasperskyHEUR:Trojan-PSW.Win32.QQPass.gen
BitDefenderGen:Variant.Babar.130640
NANO-AntivirusTrojan.Win32.TrjGen.jtozao
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.10be2616
EmsisoftGen:Variant.Babar.130640 (B)
VIPREGen:Variant.Babar.130640
SophosGeneric ML PUA (PUA)
IkarusTrojan-PSW.Agent
GDataGen:Variant.Babar.130640
AviraHEUR/AGEN.1238485
Antiy-AVLTrojan/Win32.Wacatac
ArcabitTrojan.Babar.D1FE50
ZoneAlarmHEUR:Trojan-PSW.Win32.QQPass.gen
MicrosoftProgram:Win32/Wacapew.C!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R560815
MAXmalware (ai score=86)
MalwarebytesMalware.AI.1212294260
TrendMicro-HouseCallTROJ_GEN.R03BH0CC623
YandexTrojan.GenAsa!1W74I3NpB20
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.POS!tr
AVGWin32:Evo-gen [Trj]

How to remove Malware.AI.1212294260?

Malware.AI.1212294260 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment