Malware

Malware.AI.1854672304 (file analysis)

Malware Removal

The Malware.AI.1854672304 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1854672304 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • A named pipe was used for inter-process communication
  • Starts servers listening on 127.0.0.1:0
  • Enumerates running processes
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

Related domains:

example.org
ipv4only.arpa
aus5.mozilla.org
detectportal.firefox.com

How to determine Malware.AI.1854672304?


File Info:

name: F6C9E11A6692DD21E3A6.mlw
path: /opt/CAPEv2/storage/binaries/75cfbd0136ae7a5b7c7c31beb95b47192720d8105af8c6b240930d4bcab71c81
crc32: 246FA523
md5: f6c9e11a6692dd21e3a671beff6fa08a
sha1: 560278feb31832298a23433c890af893e22aa837
sha256: 75cfbd0136ae7a5b7c7c31beb95b47192720d8105af8c6b240930d4bcab71c81
sha512: b86586efa3ec625221776fbeac2d471d7a8dd307f85eaa3f618c39f81f22555f02d0e444b3f0ddab61071dad492f89ba6b1ce518e53cbc4ac282d0b2648c8573
ssdeep: 3072:1VBK7wxt8UQJletBt4LY3U90PZ9kuSOIvJ7m:1vK7wxt8UQJletBd3U90PnkXC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11E64E9512226BE71D825A93998DB8FFED110FD398611BA4BBB13B85A4CB35C36FC1035
sha3_384: acb71e389ca756a752e8ef0e1cafc71e99abd43efa808a943f3501ef6a93816f78a3777a651dabf845af29ddc424c432
ep_bytes: 68ecc540006897c24000e8b9b8ffff68
timestamp: 2007-01-04 22:27:51

Version Info:

LegalCopyright: [4NV|e] Poenya
Pembuat: [4NV|e]
FileDescription: An's AntiVirus
FileVersion: 2.0.0
Nama Produk: ANSAV (An's AntiVirus)
Versi Mesin: 2.0.8 +E
Virus Data Base: 7.1.4
Nama File Asli: ANSAV32.EXE
Compiler: MASM
Translation: 0x0409 0x04b0

Malware.AI.1854672304 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.f6c9e11a6692dd21
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.eb3183
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
CynetMalicious (score: 100)
AvastWin32:dUmPeX [Susp]
RisingMalware.Heuristic!ET#84% (RDMK:cmRtazqDb0cGHP+Mlj7+oUBOvt9v)
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Dropper.ft
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
Acronissuspicious
McAfeeArtemis!F6C9E11A6692
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.1854672304
APEXMalicious
YandexTrojan.Swizzor.Gen!Pac.6
AVGWin32:dUmPeX [Susp]
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Malware.AI.1854672304?

Malware.AI.1854672304 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment