Malware

About “Malware.AI.1792967389” infection

Malware Removal

The Malware.AI.1792967389 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1792967389 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (2 unique times)
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Authenticode signature is invalid
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings

Related domains:

www.pubyun.com
xmr.xmr5b.ru
wpad.local-net
win2016ok.hatenablog.com

How to determine Malware.AI.1792967389?


File Info:

name: 999EFE1D9C8B1EFD9157.mlw
path: /opt/CAPEv2/storage/binaries/01ad488f91326d157074f8bca5d87fd1eefa35714028363b53965222f9080d26
crc32: DA342629
md5: 999efe1d9c8b1efd91576da9cb86c599
sha1: 02bc0e1dfee3aa1b61cf9e1d0aa3bf047234ff8e
sha256: 01ad488f91326d157074f8bca5d87fd1eefa35714028363b53965222f9080d26
sha512: d5c516fc1ecf059e49d75d0513f785da4fb632cefd4d5a019e395a8f504fab7bca8ed514dedf5dbed4946f31d506ea8d0c980ad433409692524d7c2483b3364a
ssdeep: 12288:adBB/SBLJPTfddZMGdkvmHdf4EqonqxFZmre:adBBaBLJPDdMbuHdf4EVnAF4r
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T116C47D99FB6807F9D17BC039C952494BE2B278491B61D78F13A843AA1F272D24D3F721
sha3_384: f831e5a0dfef76d948aa2a612886c9145ecc51a242c13a619f1e37d52bc51be09a95d3123c08c788f89fd32b52ec0be7
ep_bytes: 4883ec28e8af0400004883c428e966fe
timestamp: 2018-01-26 07:49:49

Version Info:

0: [No Data]

Malware.AI.1792967389 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanApplication.Generic.3080111
McAfeeArtemis!999EFE1D9C8B
CylanceUnsafe
K7AntiVirusTrojan ( 005178441 )
AlibabaRiskWare:Win32/BitCoinMiner.44a171b3
K7GWTrojan ( 005178441 )
Cybereasonmalicious.dfee3a
SymantecPUA.Gen.2
ESET-NOD32a variant of Win64/CoinMiner.EM
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Bitminer-9819753-0
Kasperskynot-a-virus:RiskTool.Win32.BitCoinMiner.irav
BitDefenderApplication.Generic.3080111
AvastWin32:XMRStak-A [Miner]
Ad-AwareApplication.Generic.3080111
TrendMicroPUA_COINMINE.SMALY
McAfee-GW-EditionBehavesLike.Win64.Generic.hh
FireEyeGeneric.mg.999efe1d9c8b1efd
SophosXMR-Stak Miner (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin64.Trojan.Agent.SD087A
GridinsoftRansom.Win64.Gen.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
MAXmalware (ai score=70)
MalwarebytesMalware.AI.1792967389
TrendMicro-HouseCallPUA_COINMINE.SMALY
TencentWin64.Trojan.Coinminer.Hvji
IkarusPUA.CoinMiner
FortinetAdware/Miner
AVGWin32:XMRStak-A [Miner]
PandaTrj/CI.A

How to remove Malware.AI.1792967389?

Malware.AI.1792967389 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment