Malware

What is “Malware.AI.2096991351”?

Malware Removal

The Malware.AI.2096991351 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2096991351 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Exhibits behavior characteristic of Cerber ransomware
  • Attempts to execute a binary from a dead or sinkholed URL
  • Writes a potential ransom message to disk
  • EternalBlue behavior
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Generates some ICMP traffic
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.2096991351?


File Info:

crc32: B05E335E
md5: 872c147a88daf98d812bed27d73344b9
name: 872C147A88DAF98D812BED27D73344B9.mlw
sha1: 1ddabe55e3ed812ee7cd618b3da07fea57186d5c
sha256: 5108fa546e32f372f917f2ac3c73a4c35adcd5b3cdc7643771d9da857f41e03c
sha512: ccdd514a6c4bbdb72941493a5dd46a4088ee5cc497513dec456dc7c153791747305ffa45c5c7e787b4ce69ea8b1f0721ff1b782adb63bcae1acb2175ecdbfc86
ssdeep: 3072:cLBWvxE9wuh9WnO4TbOOTFgk8FPhvRl2ga8TNcA7p1fgZFQJIkF6qyy8OtKBfj+T:c1WpEvhAHuOFMXRLNc019/6qYOtKVaT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Silosa
FileVersion: 1.08.0003
CompanyName: frEE time
ProductName: Chunderbird
ProductVersion: 1.08.0003
FileDescription: ZaaP
OriginalFilename: Silosa.exe

Malware.AI.2096991351 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10927
MicroWorld-eScanGen:Heur.PonyStealer.Fm1@eKf2OWji
FireEyeGeneric.mg.872c147a88daf98d
CAT-QuickHealTrojanRansom.Zerber
ALYacGen:Heur.PonyStealer.Fm1@eKf2OWji
CylanceUnsafe
VIPRELooksLike.Win32.Malware!vb (v)
AegisLabTrojan.Win32.Zerber.j!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0050c16b1 )
BitDefenderGen:Heur.PonyStealer.Fm1@eKf2OWji
K7GWTrojan ( 0050c16b1 )
Cybereasonmalicious.a88daf
BitDefenderThetaGen:NN.ZevbaF.34590.Fm1@aKf2OWji
CyrenW32/VBKrypt.SQ.gen!Eldorado
SymantecDownloader.Ponik
APEXMalicious
AvastWin32:VBCrypt-DIN [Trj]
ClamAVWin.Ransomware.Zerber-6913659-0
KasperskyTrojan-Ransom.Win32.Zerber.dywg
AlibabaRansom:Win32/Zerber.b1a6fb28
NANO-AntivirusTrojan.Win32.Zerber.enxkws
RisingRansom.Zerber!8.518C (CLOUD)
Ad-AwareGen:Heur.PonyStealer.Fm1@eKf2OWji
EmsisoftGen:Heur.PonyStealer.Fm1@eKf2OWji (B)
ComodoMalware@#3v8td8do614k9
F-SecureHeuristic.HEUR/AGEN.1119922
ZillyaTrojan.GenericKD.Win32.38930
TrendMicroRansom_CERBER.F117DQ
McAfee-GW-EditionPacked-KR!872C147A88DA
SophosML/PE-A + Mal/FareitVB-M
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1119922
Antiy-AVLTrojan[Ransom]/Win32.Zerber
MicrosoftRansom:Win32/Cerber!rfn
ArcabitTrojan.PonyStealer.E90D55
ZoneAlarmTrojan-Ransom.Win32.Zerber.dywg
GDataGen:Heur.PonyStealer.Fm1@eKf2OWji
CynetMalicious (score: 85)
AhnLab-V3Win-Trojan/VBKrypt.RP.X1764
McAfeePacked-KR!872C147A88DA
MAXmalware (ai score=88)
MalwarebytesMalware.AI.2096991351
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.DNZD
TrendMicro-HouseCallRansom_CERBER.F117DQ
TencentMalware.Win32.Gencirc.1149361f
YandexTrojan.Zerber!K3F9lFjnroU
IkarusTrojan.Win32.Injector
eGambitUnsafe.AI_Score_91%
FortinetW32/GenKryptik.DPDX!tr
AVGWin32:VBCrypt-DIN [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Ransom.Cerber.HwMADvwA

How to remove Malware.AI.2096991351?

Malware.AI.2096991351 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment