Malware

Malware.AI.1429073096 (file analysis)

Malware Removal

The Malware.AI.1429073096 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1429073096 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Collects and encrypts information about the computer likely to send to C2 server
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Malware.AI.1429073096?


File Info:

name: 99862C73C7C07C184286.mlw
path: /opt/CAPEv2/storage/binaries/de0003aacbb4379d6b2dfd96163ba7aa952fcbe5303b3ae0d84fc3df4dd4aa37
crc32: 8D716CE9
md5: 99862c73c7c07c1842865b2c616af102
sha1: ca10d4ba0e160b4c25de80c3e64207833c58020c
sha256: de0003aacbb4379d6b2dfd96163ba7aa952fcbe5303b3ae0d84fc3df4dd4aa37
sha512: 6593964427e921216d22903e265ceefbdae72625602a0604bc2411a500880aa0496b79e140ef493f1b833663a090a001cb22e68e8152c32555e23c9e4adc483d
ssdeep: 3072:bcdNlODXFOpR5j+epPksdtA2fJLlmZb+f05J+Qj65/vHTPQHdBAEujOSMkX5L+vt:bcblCXC5lpXG2nkCTQw/vzQvMrMk0kC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T140240242F6DF142CE23630B1AB86CBAC5781FCF44207072F69402A5FBBB5D1A97A2571
sha3_384: f898d6bdd7b7b4cc47d21ac3920a48c5af5f6831224a862ccf2d8d09b6d211c13205763edca1acae04e18fcf5d1ac361
ep_bytes: 60be00a045008dbe0070faff5783cdff
timestamp: 2004-12-17 14:25:59

Version Info:

0: [No Data]

Malware.AI.1429073096 also known as:

LionicRiskware.Win32.Generic.1!c
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/grayware_confidence_60% (D)
Paloaltogeneric.ml
NANO-AntivirusTrojan.Win32.Casino.coddek
APEXMalicious
DrWebAdware.Casino
ZillyaTrojan.Hematite.Win32.157
McAfee-GW-EditionRDN/CasOnline.dll
SophosMal/Behav-116
JiangminAdWare.Generic.acfy
Antiy-AVLTrojan/Generic.ASMalwS.57D391
MicrosoftTrojan:Win32/Bitrep.B
McAfeeRDN/CasOnline.dll
VBA32Adware.Casino
MalwarebytesMalware.AI.1429073096
AvastFileRepMalware
RisingTrojan.Occamy!8.F1CD (RDMK:cmRtazoVInzMoIZm92p8MJDqpyyq)
YandexTrojan.GenAsa!BfmaYpfqaNU
MaxSecureTrojan.Malware.300983.susgen
AVGFileRepMalware
PandaGeneric Malware

How to remove Malware.AI.1429073096?

Malware.AI.1429073096 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment