Malware

About “Malware.AI.1699256461” infection

Malware Removal

The Malware.AI.1699256461 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1699256461 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the PoisonIvy malware family
  • CAPE detected injection into a browser process, likely for Man-In-Browser (MITB) infostealing
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.1699256461?


File Info:

name: 821DE9CDB8ABA78BE0FA.mlw
path: /opt/CAPEv2/storage/binaries/3eed4e526d21a75564a92f091d23e843aeaaeda9875b709144906974e1005cde
crc32: 1D620FDA
md5: 821de9cdb8aba78be0fa8822833e8fbb
sha1: 5af9845a7e79bca9d91e985f724a47efdf3216f6
sha256: 3eed4e526d21a75564a92f091d23e843aeaaeda9875b709144906974e1005cde
sha512: 0d98aa4909840ba3935cb8007886a760c69956c4dc67955b6dfdec624ebf6b2651243060523fd02a7dc141d31aeb80fc2512fd67367de6ebe50724b39af8222f
ssdeep: 384:DFyH905eSH8E1xvqXCO25ywHwAax4knONrb7olVkZQ6zPVfv:DFxRO25ux4K2b0TQ7F
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T184C27E01659598B0C4278ABD8C07A25CE379786633F7269FEFA90E0D3C5E7402D5EDA3
sha3_384: 148ea09b875116497c3b1841501736ee46026b42edd51633e4b31e4d2297d01898aba62f2a6830850b037cea70150a87
ep_bytes: 660599006683e8076683f0059066f7d0
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Malware.AI.1699256461 also known as:

LionicWorm.Win32.Fearso.lGmx
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Inject.QV
FireEyeGeneric.mg.821de9cdb8aba78b
ALYacTrojan.Inject.QV
CylanceUnsafe
ZillyaDropper.Agent.Win32.109468
K7AntiVirusTrojan ( 00164e181 )
AlibabaVirTool:Win32/PePatch.f01b98da
K7GWTrojan ( 00164e181 )
Cybereasonmalicious.db8aba
CyrenW32/Backdoor.GDJB-8080
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyPacked.Win32.PePatch.lc
BitDefenderTrojan.Inject.QV
NANO-AntivirusTrojan.Win32.PePatch.cwnynv
AvastWin32:Evo-gen [Trj]
TencentWin32.Packed.Pepatch.Dwsz
Ad-AwareTrojan.Inject.QV
EmsisoftTrojan.Inject.QV (B)
ComodoBackdoor.Win32.Bifrose.~BAAD@93bu
DrWebBackDoor.Bifrost.905
VIPRETrojan.Inject.QV
TrendMicroBKDR_POISON.QH
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.mh
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/EncPk-FL
SentinelOneStatic AI – Malicious PE
GDataTrojan.Inject.QV
JiangminBackdoor/PoisonIvy.bdc
WebrootVir.Tool.Gen
AviraDR/Delphi.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwFH.E1
ArcabitTrojan.Inject.QV
ViRobotBackdoor.Win32.Poison.27136.C
ZoneAlarmPacked.Win32.PePatch.lc
MicrosoftVirTool:Win32/DelfInject.gen!X
GoogleDetected
AhnLab-V3Trojan/Win32.Poison.C44396
Acronissuspicious
McAfeeGenericRXAA-AA!821DE9CDB8AB
TACHYONBackdoor/W32.Poison.27136
VBA32Backdoor.Bifrose
MalwarebytesMalware.AI.1699256461
TrendMicro-HouseCallBKDR_POISON.QH
RisingBackdoor.Buzus!8.58AC (TFE:3:FTRZgesduKG)
YandexTrojan.GenAsa!5hA9LvtOAQc
IkarusTrojan-Downloader.Win32.WMS
MaxSecureTrojan.Malware.799692.susgen
BitDefenderThetaAI:Packer.4B7D63931F
AVGWin32:Evo-gen [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Malware.AI.1699256461?

Malware.AI.1699256461 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment