Malware

Should I remove “Malware.AI.1715247475”?

Malware Removal

The Malware.AI.1715247475 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1715247475 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Checks for the presence of known windows from debuggers and forensic tools
  • Likely virus infection of existing system binary
  • Attempts to identify installed analysis tools by a known file location
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself

How to determine Malware.AI.1715247475?


File Info:

name: 78AAA772B24FE5836BAA.mlw
path: /opt/CAPEv2/storage/binaries/bcf046dd71fccdeef1603ec9ae5b72d28682faa723f774f06b9dd4b72fe4f3c5
crc32: C330F623
md5: 78aaa772b24fe5836baa04d938d2df52
sha1: 3e865ffc29362a965f0174cc39a5c1514f1f7f43
sha256: bcf046dd71fccdeef1603ec9ae5b72d28682faa723f774f06b9dd4b72fe4f3c5
sha512: 23fdbfea41c206735d8fa33c289d96ad02ee550c9d8853d7053b4f748afbb16f261ff610e6c53aed7b20096399bcf852d9cb2c878311b329fed29fd87eded29f
ssdeep: 3072:pFZMTfUcRGbzUCKFh0ZnyfxZY42fIPEwqa6Idn9CcbrXxuDQWVilY3QvdQCzo+p7:Mf6zTyf4DiEwqabdnXrxZYqvcIO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18F2423718A09DBF1F36B40381B4E1B0BC26DEB720D8576476BD3B42F6805326AA70D79
sha3_384: 1d645efb01e4e287424c7b10fd510c9d624ecb92e3130612a5db893531cf90f72c2e612e2b65eb50eaace271c1c8ed02
ep_bytes: 60be009044008dbe0080fbff57eb0b90
timestamp: 2008-08-31 07:00:28

Version Info:

ProductName: WinRAR
CompanyName: Alexander Roshal
FileDescription: WinRAR archiver
FileVersion: 3.80
InternalName: WinRAR
LegalCopyright: Copyright © Alexander Roshal 1993-2008
OriginalFilename: WinRAR.exe
Comments: Translation © Dmitry Yerokhin 1999-2008

Malware.AI.1715247475 also known as:

BkavW32.MosquitoQKK.Fam.Trojan
LionicTrojan.Win32.Zbot.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Kazy.11464
FireEyeGeneric.mg.78aaa772b24fe583
McAfeeArtemis!78AAA772B24F
CylanceUnsafe
ZillyaTrojan.FakeAV.Win32.44330
SangforTrojan.Win32.Generic.ky
K7AntiVirusTrojan ( f1000f011 )
AlibabaExploit:Win32/ShellCode.e14c9ec5
K7GWTrojan ( f1000f011 )
Cybereasonmalicious.2b24fe
BitDefenderThetaGen:NN.ZexaF.34232.nmKfaKE1Zghc
VirITTrojan.Win32.Zbot.BLZB
CyrenW32/S-301e7fab!Eldorado
SymantecDownloader.Lofog!gen4
ESET-NOD32a variant of Win32/Kryptik.KND
TrendMicro-HouseCallTROJ_CRYPTR.SMAM
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-557278
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Kazy.11464
NANO-AntivirusTrojan.Win32.Zbot.corir
SUPERAntiSpywareTrojan.Agent/Gen-Pervaser
APEXMalicious
TencentWin32.Trojan.Generic.Ajly
Ad-AwareGen:Variant.Kazy.11464
SophosMal/Generic-R + Mal/FakeAV-BW
ComodoMalware@#29d30mszcuffm
DrWebTrojan.Packed.21467
VIPRETrojan.Win32.Kryptik.lbu (v)
TrendMicroTROJ_CRYPTR.SMAM
McAfee-GW-EditionBehavesLike.Win32.Sality.dc
EmsisoftGen:Variant.Kazy.11464 (B)
IkarusTrojan-Spy.Win32.Zbot
GDataGen:Variant.Kazy.11464
JiangminTrojan.Generic.xkth
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.AGeneric
GridinsoftRansom.Win32.Zbot.sa
ArcabitTrojan.Kazy.D2CC8
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftWorm:Win32/Slenfbot.gen!D
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R4017
Acronissuspicious
VBA32Trojan.Zeus.EA.0999
ALYacGen:Variant.Kazy.11464
MalwarebytesMalware.AI.1715247475
AvastFileRepMalware
RisingExploit.ShellCode!8.2A (CLOUD)
YandexTrojan.GenAsa!zLGfEEkWneo
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.NAS!tr
AVGFileRepMalware
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Malware.AI.1715247475?

Malware.AI.1715247475 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment