Malware

Malware.AI.212615762 (file analysis)

Malware Removal

The Malware.AI.212615762 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.212615762 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.212615762?


File Info:

crc32: 2AD5774F
md5: 5152ee16f7485c22f5dfe04ce11e37de
name: 5152EE16F7485C22F5DFE04CE11E37DE.mlw
sha1: b11c9de712ac6e92dbb59a9e15718b8c2f1299ca
sha256: f918d968d5b40bba893b9c14d30d51281cafac81457c032dc0c870d78f3c52c6
sha512: 99ddf9c2e5da06c703b8f9e7a0ad4ddcfbba93955747e75e36115182ccf310610df83b9f0b22a54354760f21179deac44f6be5ce54cdc6b88793b62c79b6a491
ssdeep: 3072:J7FhoZJtk26pKWAJEXSbUnQrguWIlithmSp6gYtEPstYD7ExYQ5/:J7Fhaij4WA2XPvIlChBpstYDgxP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.212615762 also known as:

MicroWorld-eScanGen:Variant.Graftor.388592
Qihoo-360Win32/Trojan.ec4
ALYacGen:Variant.Graftor.388592
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan-Downloader ( 004dbcb61 )
BitDefenderGen:Variant.Graftor.388592
K7GWTrojan-Downloader ( 004dbcb61 )
Cybereasonmalicious.6f7485
BitDefenderThetaGen:NN.ZexaF.34804.nqW@aaK7Rpki
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.VB.eqsoba
RisingMalware.Undefined!8.C (TFE:5:2SnLvq5nslV)
Ad-AwareGen:Variant.Graftor.388592
EmsisoftGen:Variant.Graftor.388592 (B)
ComodoMalware@#3g0vs8jwojj75
F-SecureHeuristic.HEUR/AGEN.1109224
ZillyaTrojan.Inject.Win32.239519
McAfee-GW-EditionDownloader-FBQD!5152EE16F748
FireEyeGeneric.mg.5152ee16f7485c22
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Inject.zgm
AviraHEUR/AGEN.1109224
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.Inject
MicrosoftPWS:Win32/Zbot!ml
ArcabitTrojan.Graftor.D5EDF0
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Graftor.388592
CynetMalicious (score: 100)
McAfeeDownloader-FBQD!5152EE16F748
VBA32BScope.Trojan.Downloader
MalwarebytesMalware.AI.212615762
ESET-NOD32a variant of Win32/Injector.DPTO
TencentMalware.Win32.Gencirc.10bb273a
YandexTrojan.GenAsa!Z80l2FOhI0E
IkarusTrojan.Win32.Injector
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.DPRP!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Malware.AI.212615762?

Malware.AI.212615762 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment