Malware

Malware.AI.1418185362 (file analysis)

Malware Removal

The Malware.AI.1418185362 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1418185362 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Malware.AI.1418185362?


File Info:

name: EDC41A907F3737E89044.mlw
path: /opt/CAPEv2/storage/binaries/0521aa9314b9fd1a1073f4accb7f935fc4f01d27cd107a15fab1b0a89df6c1c0
crc32: 621E65EB
md5: edc41a907f3737e89044bb048779a51c
sha1: 473463f36a153cd53d4a34c070b9e9ad1973d66f
sha256: 0521aa9314b9fd1a1073f4accb7f935fc4f01d27cd107a15fab1b0a89df6c1c0
sha512: 191ec49df94c0414f059df765c57b8303ed90dd0ee7df5f2b1e656bde8fae283b27235480fc45480be11a3ca6b65a606e0a1ce2cb43f0064f839bf2eba0b229a
ssdeep: 384:kyl4OawQslpvfSshE6Ssi+cLRCRUiKbSO8aEQXF2KxVptYcFmVc03K:kpzGpLMNDkIX1tYcFmVc6K
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T130C2A68117480216F6250CF2993C7D575A3735CA48398BC53A9F983FFF636606BC63A9
sha3_384: c416d9c2518c50f9e31ff93704b5ace3019857123ec011803f880c8d6b93204d81b0f23d337f6cf3bccdea8b6f8bc8e9
ep_bytes: ff250020400000000000000000000000
timestamp: 2077-06-13 11:05:57

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: WebhookDeleter
FileVersion: 1.0.0.0
InternalName: Webhooks.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: Webhooks.exe
ProductName: WebhookDeleter
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.1418185362 also known as:

LionicTrojan.Win32.Zilla.4!c
MicroWorld-eScanIL:Trojan.MSILZilla.11281
FireEyeIL:Trojan.MSILZilla.11281
ALYacIL:Trojan.MSILZilla.11281
MalwarebytesMalware.AI.1418185362
ZillyaTool.I.Win32.9
K7AntiVirusUnwanted-Program ( 0057fef21 )
K7GWUnwanted-Program ( 0057fef21 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Spammer.I potentially unsafe
APEXMalicious
BitDefenderIL:Trojan.MSILZilla.11281
AvastWin32:MiscX-gen [PUP]
Ad-AwareIL:Trojan.MSILZilla.11281
SophosGeneric PUA EH (PUA)
McAfee-GW-EditionArtemis!Trojan
EmsisoftIL:Trojan.MSILZilla.11281 (B)
SentinelOneStatic AI – Suspicious PE
GDataIL:Trojan.MSILZilla.11281
GridinsoftRansom.Win32.Sabsik.sa
ArcabitIL:Trojan.MSILZilla.D2C11
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeGenericRXAA-FA!EDC41A907F37
MAXmalware (ai score=81)
TrendMicro-HouseCallTROJ_GEN.R002H09KS21
FortinetAdware/Spammer
AVGWin32:MiscX-gen [PUP]

How to remove Malware.AI.1418185362?

Malware.AI.1418185362 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment