Malware

Malware.AI.2035174509 (file analysis)

Malware Removal

The Malware.AI.2035174509 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2035174509 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Malware.AI.2035174509?


File Info:

name: 4F468B08364FB8FC74BA.mlw
path: /opt/CAPEv2/storage/binaries/c51e86d97fb0dfdce63e3c659ae70720b0ab2b29ceeba39aad053faab64f35b2
crc32: 99E306B9
md5: 4f468b08364fb8fc74baa0c192e5e4c6
sha1: 383a713066c9d24d169dbf6199b6945aba62f588
sha256: c51e86d97fb0dfdce63e3c659ae70720b0ab2b29ceeba39aad053faab64f35b2
sha512: ed1f911dbe5c03db42e6c857ae2674f675538811358265f26cb306fada8c59f560293f9eed28218cea2f638d399d788ac02b48d2ece1a02cae7a13f5fedcbabb
ssdeep: 49152:r48NGV/tKOlIHIoAa6/Mf1TeR/V8KqzQ+rsTb3vg0:c8NGvF4zT601SR/TaprCfX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D08533396237A1E2D004C4796F2A9722D11BFCE68C4663A76DEDF3DF243C8C447A651A
sha3_384: 6fc1c182e6ee080013a670ff155bccb01b4fdecdc433bf1ea1d464adfac6b54366295af7fca11a7adbc1ae9f6b77efa6
ep_bytes: 60be007071008dbe00a0ceff5783cdff
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: Chengdu Kungho Technology Co,. Ltd.
FileDescription: Kungho ADP-System Core
FileVersion: 1.1.0.800
InternalName:
LegalCopyright: Copyright by Kungho Technology
LegalTrademarks:
OriginalFilename: KHCore.exe
ProductName: Kungho ADP-System
ProductVersion: 1.0.0.0
Comments: 全功能版
Translation: 0x0804 0x03a8

Malware.AI.2035174509 also known as:

LionicTrojan.Win32.Fugrafa.4!c
MicroWorld-eScanGen:Variant.Fugrafa.39544
FireEyeGeneric.mg.4f468b08364fb8fc
ALYacGen:Variant.Fugrafa.39544
VIPREGen:Variant.Fugrafa.39544
SangforTrojan.Win32.Agent.Vi3f
AlibabaBackdoor:Win32/OnlineGames.08bc950e
Cybereasonmalicious.8364fb
BitDefenderThetaGen:NN.ZelphiCO.34786.QnKfamL7jlib
CyrenW32/OnlineGames.CE.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
TrendMicro-HouseCallTROJ_GEN.R002H0CGD22
BitDefenderGen:Variant.Fugrafa.39544
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastFileRepMalware [Misc]
Ad-AwareGen:Variant.Fugrafa.39544
EmsisoftGen:Variant.Fugrafa.39544 (B)
ComodoTrojWare.Win32.TrojanDownloader.Delf.gen@1xqow5
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
SentinelOneStatic AI – Malicious PE
Trapminemalicious.moderate.ml.score
IkarusBackdoor.Win32.Hupigon
GDataGen:Variant.Fugrafa.39544
AviraHEUR/AGEN.1232565
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!4F468B08364F
VBA32TScope.Trojan.Delf
MalwarebytesMalware.AI.2035174509
APEXMalicious
RisingBackdoor.Farfli!1.6542 (CLOUD)
MAXmalware (ai score=86)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGFileRepMalware [Misc]

How to remove Malware.AI.2035174509?

Malware.AI.2035174509 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment