Malware

Malware.AI.1992172819 (file analysis)

Malware Removal

The Malware.AI.1992172819 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1992172819 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • A HTTP/S link was seen in a script or command line
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Attempts to execute suspicious powershell command arguments
  • Anomalous binary characteristics

How to determine Malware.AI.1992172819?


File Info:

name: 000FBBDD72A9B5F1E7DC.mlw
path: /opt/CAPEv2/storage/binaries/061b46beead095fece8ebd51d594ce4eb4f52c28f18e83fa101a10b262adcb8a
crc32: BC77D1AF
md5: 000fbbdd72a9b5f1e7dc8ea186beaa49
sha1: 00c8e795279d924e37ee9444422dedc1ee89edd8
sha256: 061b46beead095fece8ebd51d594ce4eb4f52c28f18e83fa101a10b262adcb8a
sha512: fc54d6c8d14a695eb74a454a2ce40aeaf534e02cc60cdd100c9d4eee94483829bd13074c5d0504a02e870868f05913bc799784c292feae9dfcb72d11b436f0ba
ssdeep: 98304:jLPgtBOuoEuLMXgaiISQw5ijaTHFgkHItipsooH9LSytJnCy:PPKBs3WLvBfaTD+ipz8VVtJnC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13A1633577DFDCC62C3E882B985F3C2E1873F9D6499165283869936C8797EA803B78407
sha3_384: 35160f2b3fd4189dd03a55f858d33327f32f04435aa80d75fa6e9d720afa8f4b770cb67867c5055e9687d245dc2681d7
ep_bytes: e800070000e9000000006a5868687240
timestamp: 2000-11-24 11:50:57

Version Info:

Comments: Pityful She Software
CompanyName: Pityful She Software
FileDescription: Pityful She Software
LegalCopyright: Pityful She Software
LegalTrademarks: Pityful She Software
ProductName: Pityful She Software
FileVersion: 8.2.3083
ProductVersion: 8.2.3083
InternalName: Pityful She
OriginalFilename: Pityful She.exe
Translation: 0x0407 0x04b0

Malware.AI.1992172819 also known as:

LionicTrojan.Win32.Stealer.trGK
Elasticmalicious (high confidence)
FireEyeGeneric.mg.000fbbdd72a9b5f1
McAfeeArtemis!000FBBDD72A9
CylanceUnsafe
SangforTrojan.Win32.Sabsik.FL
CrowdStrikewin/malicious_confidence_70% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.DCGWFSA
AvastWin32:Malware-gen
AlibabaTrojan:Win32/Generic.4a168e39
ViRobotTrojan.Win32.Z.Sabsik.4405248.B
RisingDownloader.BitsAdmin!1.D0D1 (CLASSIC)
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.BadFile.rc
SentinelOneStatic AI – Suspicious PE
APEXMalicious
eGambitUnsafe.AI_Score_99%
AviraTR/Dropper.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R449310
MalwarebytesMalware.AI.1992172819
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
Cybereasonmalicious.5279d9
Paloaltogeneric.ml

How to remove Malware.AI.1992172819?

Malware.AI.1992172819 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment