Malware

About “Malware.AI.201475953” infection

Malware Removal

The Malware.AI.201475953 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.201475953 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Collects and encrypts information about the computer likely to send to C2 server
  • Creates a hidden or system file
  • A script or command line contains a long continuous string indicative of obfuscation
  • Attempts to execute suspicious powershell command arguments
  • Uses csc.exe C# compiler to build and execute code
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.201475953?


File Info:

name: 33461D3033706346D662.mlw
path: /opt/CAPEv2/storage/binaries/54f3840c30825016d0a50b4fefd5db0390cf3dfb1cde622d463f893c0a248ce5
crc32: CE43FF4B
md5: 33461d3033706346d66280919d142dfc
sha1: 3bf6d8138c72300bcfe27c28e828b974b42ce0a0
sha256: 54f3840c30825016d0a50b4fefd5db0390cf3dfb1cde622d463f893c0a248ce5
sha512: 4265e55c0ee14960b839186fe63bc1b299f32db393f04522b6958fcc2f4f1d88e0938e3863a2ee5abbaba5224ac2d735f2784ac4e76b4be7102aa9f80e2372a2
ssdeep: 1536:9yQ9iyk2TuoXIbuMu4WwlwgumuUO8u3yMXImbWTFGdVgs5r:9yQ9iauoXuuMwguQO4NWRl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B3B339B6EE89DDE3E62153398AF5E319033DFAC11B828B1B1D3188395713591BFC6606
sha3_384: e3ed52e8595ded0826197a13557df5cb850fd4c500e1ffd1ac37db0a03bff9cf2e17b0c06be4caf4c9f1b68484442017
ep_bytes: 83ec0cc705d873400001000000e89e02
timestamp: 2021-04-19 05:29:19

Version Info:

0: [No Data]

Malware.AI.201475953 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Paph.a!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.33461d3033706346
McAfeeGenericRXKT-UU!33461D303370
CylanceUnsafe
K7AntiVirusTrojan ( 0056ae271 )
AlibabaTrojanDownloader:Win32/Rozena.464ef36f
K7GWTrojan ( 0056ae271 )
Cybereasonmalicious.033706
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Rozena.ATK
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Taranis-9870902-0
KasperskyHEUR:Trojan-Downloader.Win32.Paph.gen
AvastWin32:DropperX-gen [Drp]
TencentWin32.Trojan-downloader.Paph.Lhna
SophosMal/Generic-S
DrWebTrojan.Starter.7246
TrendMicroTROJ_GEN.R03FC0PKR21
McAfee-GW-EditionBehavesLike.Win32.PinkSbot.cm
IkarusTrojan.Win32.Powerless
GDataWin32.Trojan.Agent.1IAZME
JiangminTrojan.Generic.edvzu
WebrootW32.Trojan.Dropper
AviraTR/Rozena.vvvqh
ViRobotTrojan.Win32.Z.Paph.110281.A
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Agent.R328567
BitDefenderThetaGen:NN.ZexaF.34294.g8Y@auYNB
VBA32BScope.TrojanDownloader.Paph
MalwarebytesMalware.AI.201475953
TrendMicro-HouseCallTROJ_GEN.R03FC0PKR21
YandexTrojan.GenAsa!ZWl9JygWehA
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Paph.VHO!tr
AVGWin32:DropperX-gen [Drp]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.201475953?

Malware.AI.201475953 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment