Malware

Malware.AI.1536588249 malicious file

Malware Removal

The Malware.AI.1536588249 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1536588249 virus can do?

  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • CAPE detected the RedLine malware family
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Malware.AI.1536588249?


File Info:

name: C57DB2A22072F5D80F7D.mlw
path: /opt/CAPEv2/storage/binaries/cba1b04cf81be758847cf96fc5a565598eddab26fc66f66aa977da26af22ad76
crc32: C8435F95
md5: c57db2a22072f5d80f7d8e6493c5caab
sha1: 37343ba216314d188389f3f3f6489a6bea7eea73
sha256: cba1b04cf81be758847cf96fc5a565598eddab26fc66f66aa977da26af22ad76
sha512: c8c76f0a547d4cbb7acfce3d988cdfb90ee0600987f829bfa1d13177322e5097b9430132cfc77985d9582e93fec229fdd8bedb670f13bf7a52cc49062ffd7636
ssdeep: 1536:5WZ7rGhhCHCHmbeBv7qjf4GcSSo/y5IHE0GbZAKIm0j2bbnUf9800UtwdLE:5WZvG7CiHmKJ7qzlSXHE9m8mm6L
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T165654B613BD89A04E6FF0E747CB1101883F5F1532411E75F6EC554EE2EA3B81AA52AF2
sha3_384: 9ebedfcc1cf3a3a63db1406d10b8dd1c791270ca0396ec059fc7d1b4e1b4baaa751f936c7f71e171663a71664e328eae
ep_bytes: ff25002040006100750074006f006600
timestamp: 2095-07-26 15:36:09

Version Info:

CompanyName: Cfx.re
FileDescription: FiveM
FileVersion: 1.1.0.0
InternalName: Citizen
LegalCopyright: (C) 2015-2020 Cfx.re
OriginalFilename: citizenmp.exe
ProductName: CitizenFX
ProductVersion: 1.1.0.0
Translation: 0x0409 0x04b0

Malware.AI.1536588249 also known as:

LionicTrojan.MSIL.Agent.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen16.711
MicroWorld-eScanGen:Variant.Tedy.1541
FireEyeGeneric.mg.c57db2a22072f5d8
CAT-QuickHealTrojan.MSIL
ALYacGen:Variant.Tedy.1541
MalwarebytesMalware.AI.1536588249
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:MSIL/Generic.75974191
K7GWSpyware ( 0057a2c81 )
K7AntiVirusSpyware ( 0057a2c81 )
BitDefenderThetaGen:NN.ZemsilF.34084.zn3@aiEym6ci
CyrenW32/MSIL_Agent.CIU.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Spy.Agent.DFY
TrendMicro-HouseCallTROJ_GEN.R002C0PL821
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Agent.gen
BitDefenderGen:Variant.Tedy.1541
AvastWin32:PWSX-gen [Trj]
TencentMsil.Trojan.Agent.Sxyb
Ad-AwareGen:Variant.Tedy.1541
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0PL821
McAfee-GW-EditionGenericRXQA-AF!C57DB2A22072
EmsisoftGen:Variant.Tedy.1541 (B)
IkarusTrojan.MSIL.Spy
AviraTR/Spy.Agent.itqak
Antiy-AVLTrojan/Generic.ASMalwS.34E6859
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ViRobotTrojan.Win32.Z.Tedy.1466508
GDataGen:Variant.Tedy.1541
CynetMalicious (score: 100)
AhnLab-V3Infostealer/Win.RedLine.C4824057
McAfeeGenericRXQA-AF!C57DB2A22072
MAXmalware (ai score=88)
VBA32TScope.Trojan.MSIL
APEXMalicious
RisingStealer.RedLine!1.DA64 (CLASSIC)
SentinelOneStatic AI – Suspicious PE
FortinetMSIL/Agent.DFY!tr
WebrootW32.Trojan.Gen
AVGWin32:PWSX-gen [Trj]
PandaTrj/CI.A

How to remove Malware.AI.1536588249?

Malware.AI.1536588249 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment