Malware

About “Malware.AI.1502603520” infection

Malware Removal

The Malware.AI.1502603520 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1502603520 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Malware.AI.1502603520?


File Info:

name: 31A94E12CE2E904DF908.mlw
path: /opt/CAPEv2/storage/binaries/bfed1afec761fd70b13a7ff7cbef12edab1cb995676d93f5659115acc5f4b1db
crc32: F66CEE12
md5: 31a94e12ce2e904df908d32ede59c17d
sha1: 8bf7ffc647725b0cb9ecdcbb2bc6d91af68bb5a6
sha256: bfed1afec761fd70b13a7ff7cbef12edab1cb995676d93f5659115acc5f4b1db
sha512: 26484dbd4665896c195b1e2c32bbc9bf1209c64e6a3579a8360a54aa4fd56029f28e73afa62aeb025d8ca55beb689bba243b11d18a13c58fde4f234658fe8b1c
ssdeep: 3072:yV3cNQO1DeSm7pdJzNA2rmt/aLYDOu0l1kTl92OlIeumjmdJw000000j00PVyBER:8pOwSm7pzS2a1Bn0PkTUEydC000000jP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B414CF30F3DAC66AE72F537C043A6C2013A69D69D2D2E61F3CC53A1819BB740469766F
sha3_384: 75fc8784bab1515e503234a057b5dd72884c6b4f918bc36b024433c317fe2a1bafd5bede9475129c867498dcd75383f6
ep_bytes: ff250020400000000000000000000000
timestamp: 2012-03-13 18:51:32

Version Info:

Translation: 0x0000 0x04b0
FileDescription: WindowsApplication1
FileVersion: 1.0.0.0
InternalName: Injector.exe
LegalCopyright: Copyright © 2012
OriginalFilename: Injector.exe
ProductName: WindowsApplication1
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.1502603520 also known as:

LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.31a94e12ce2e904d
McAfeeArtemis!31A94E12CE2E
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (W)
K7GWRiskware ( 0015e4f01 )
K7AntiVirusRiskware ( 0015e4f01 )
CyrenW32/MSIL_Troj.BMF.gen!Eldorado
ESET-NOD32a variant of MSIL/DllInject.ET potentially unsafe
APEXMalicious
KasperskyUDS:DangerousObject.Multi.Generic
NANO-AntivirusTrojan.Win32.DllInject.yvcdp
AvastWin32:Malware-gen
SophosMal/Generic-R + Mal/MSIL-AX
ComodoMalware@#j8cjlcwros0d
F-SecureHeuristic.HEUR/AGEN.1223037
ZillyaTrojan.DllInject.Win32.13749
TrendMicroTROJ_GEN.R002C0RFE22
McAfee-GW-EditionArtemis!Trojan
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1223037
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftBackdoor:Win32/Bladabindi!ml
CynetMalicious (score: 99)
MAXmalware (ai score=94)
MalwarebytesMalware.AI.1502603520
TrendMicro-HouseCallTROJ_GEN.R002C0RFE22
RisingTrojan.Generic/MSIL@AI.96 (RDM.MSIL:BMrLwFgn4WQ752p7/5a19w)
IkarusTrojan-Dropper
MaxSecureTrojan.Malware.1728101.susgen
FortinetMSIL/Injector.RKU!tr
AVGWin32:Malware-gen
Cybereasonmalicious.647725

How to remove Malware.AI.1502603520?

Malware.AI.1502603520 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment