Malware

About “Malware.AI.1948554724” infection

Malware Removal

The Malware.AI.1948554724 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1948554724 virus can do?

  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Malware.AI.1948554724?


File Info:

name: 7CDC90EC0E0369960B50.mlw
path: /opt/CAPEv2/storage/binaries/48c8364f3fe7d5046dbc113e8524dc6c5d9aa02850979b02f2553af1f1697f0b
crc32: FEC8FC18
md5: 7cdc90ec0e0369960b50148ebf5a7886
sha1: 6ec80e97af4250134de7a21a42db41ed21e918cb
sha256: 48c8364f3fe7d5046dbc113e8524dc6c5d9aa02850979b02f2553af1f1697f0b
sha512: 860b8bb7a3f3aef13024530dfc1c1528c113f00cab20ee2313450138789081b9fb88098a18a544a2d96fea0fe861fc9196c345fe3792e5bd884fa28e495b310a
ssdeep: 384:PCN2Njrz3O7maUwvXMUH1soFr6LDbPfR422C/OL0e2u/pKOPPL3KmF9FEFuNJU7O:Q2NjH3zaUyXfH+aRoU3BvXXFC5CFRRu
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T14644D71035C4EA17C4A76F349822B3F91FE13D37695CBAB17E81B7CF9AB12007542AA5
sha3_384: b085caa8f746ebfb0dd28600661de83f96c6a1761bf8db897c0853085ff9daa2e58b5a558bdf9bd569b77c36b7f6ec00
ep_bytes: ff250020400000000000000000000000
timestamp: 2072-05-13 07:59:23

Version Info:

Translation: 0x0000 0x04b0
CompanyName: IronmanPowerShellHost
FileDescription: IronmanPowerShellHost
FileVersion: 1.0.0.0
InternalName: IronmanPowerShellHost.exe
LegalCopyright:
OriginalFilename: IronmanPowerShellHost.exe
ProductName: IronmanPowerShellHost
ProductVersion: 1.0.0
Assembly Version: 1.0.0.0

Malware.AI.1948554724 also known as:

LionicTrojan.Win32.Paph.4!c
Elasticmalicious (moderate confidence)
McAfeeArtemis!7CDC90EC0E03
MalwarebytesMalware.AI.1948554724
ZillyaDownloader.Paph.Win32.1429
SangforDownloader.Win32.Agent.Vpt8
AlibabaTrojanDownloader:MSIL/DropperX.764afb41
SymantecML.Attribute.HighConfidence
CynetMalicious (score: 100)
AvastWin32:PUP-gen [PUP]
F-SecureTrojan.TR/Dldr.Paph.mcdzq
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-R
JiangminTrojanDownloader.MSIL.aovs
AviraTR/Dldr.Paph.mcdzq
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
Cylanceunsafe
PandaTrj/Chgt.AD
IkarusTrojan-Downloader.Paph
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
AVGWin32:PUP-gen [PUP]
DeepInstinctMALICIOUS

How to remove Malware.AI.1948554724?

Malware.AI.1948554724 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment