Malware

What is “Malware.AI.1873812731”?

Malware Removal

The Malware.AI.1873812731 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1873812731 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Malware.AI.1873812731?


File Info:

name: 1997C4CC3D6E830747DA.mlw
path: /opt/CAPEv2/storage/binaries/11389776b3a33a6df1e3e0bba388ec5aba20a7fb4999232bb8cec10d2046fea7
crc32: 5678B019
md5: 1997c4cc3d6e830747da591ff83b0265
sha1: 42a128e3a7091296d8084108fbf9617791f72e1d
sha256: 11389776b3a33a6df1e3e0bba388ec5aba20a7fb4999232bb8cec10d2046fea7
sha512: 2a5419be90ec33a360fb57da8189c9029a15edf017fc7bafcb1d604651dd63d2f3cf060586de276398cddb47e6685317f62b87b5aaf253b338529a2b635742f9
ssdeep: 3072:svSj5CBVVN1B9RXei6IZIXb5elasxswbGftw:dMBhOretS1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16FE36C181FDDD226DBDE03F5A4A6C4904AF0461179C7EB6E682D76B22F533D40E052AF
sha3_384: 07f00bf0cad3bac7715b814f29040bfb61aeec68fa1b4f8c4c21e2bc995563de451b62cc75375764e442755514743bac
ep_bytes: ff250020400000000000000000000000
timestamp: 2040-09-07 15:03:00

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: dialog test
FileVersion: 1.0.0.0
InternalName: dialog test.exe
LegalCopyright: Copyright © 2020
LegalTrademarks:
OriginalFilename: dialog test.exe
ProductName: dialog test
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.1873812731 also known as:

LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38748764
FireEyeGeneric.mg.1997c4cc3d6e8307
ALYacTrojan.GenericKD.38748764
CylanceUnsafe
ZillyaTrojan.VMProtect.Win32.58457
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000001c1 )
K7GWTrojan ( 7000001c1 )
Cybereasonmalicious.3a7091
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Packed.VMProtect.C suspicious
APEXMalicious
Paloaltogeneric.ml
BitDefenderTrojan.GenericKD.38748764
AvastWin32:Malware-gen
EmsisoftTrojan.GenericKD.38748764 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
SophosMal/Generic-S
IkarusPUA.VMProtect
AviraHEUR/AGEN.1145839
MicrosoftTrojan:Win32/Occamy.AA
GDataTrojan.GenericKD.38748764
CynetMalicious (score: 100)
McAfeeArtemis!1997C4CC3D6E
MAXmalware (ai score=82)
MalwarebytesMalware.AI.1873812731
TrendMicro-HouseCallTROJ_GEN.R002H0CAU22
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:jYDkQ7Fjk6i4b1C9mJxJMg)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.101574170.susgen
FortinetPossibleThreat
BitDefenderThetaGen:NN.ZemsilF.34182.iu0@aSWoUtn
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Malware.AI.1873812731?

Malware.AI.1873812731 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment