Malware

About “Malware.AI.2155910036” infection

Malware Removal

The Malware.AI.2155910036 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2155910036 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.2155910036?


File Info:

name: A41C55D65A84D570AED1.mlw
path: /opt/CAPEv2/storage/binaries/5771105bbc66dd9b8fc7e8dd018acc663bf82b46af612c36c154779d95968d1d
crc32: 253AFADD
md5: a41c55d65a84d570aed155d4ea8489d8
sha1: 49aadf483f3d50913eeb09b5c774528f2111b39f
sha256: 5771105bbc66dd9b8fc7e8dd018acc663bf82b46af612c36c154779d95968d1d
sha512: ee1fadcf4c78a16a17b2b2c17367729937f1a653fec60a9b20dd023bd617fd58b9238560b83656e0ce4fae34c931eaa5b3f89771048edcaf9cd6a68efec5b746
ssdeep: 98304:qCBZQ4VUEVVEtVwCbY2rFyRV++RT/QZ+nWtoiNDEX2BTynLNUerE:qMQ4V3VVEtveRIeMZ+KpN4sTyB8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T129263352D42007E4FD3ACD308559798146276F6B076BA8F81D0DFB918DB7AD682E2F0B
sha3_384: aed759c935a9ce397269ed68693278c78fb3c2c0c768157cbc9d0142e53f144460ccc831cc73cb8b3d5455c4554e89a6
ep_bytes: 60be00a0ca008dbe007075ff57eb0b90
timestamp: 2022-03-30 07:57:48

Version Info:

FileVersion: 1.0.0.3
FileDescription: 图片素材下载工具
ProductName: 找图片素材
ProductVersion: 1.0.0.3
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 绑定电脑硬件码注册的
Translation: 0x0804 0x04b0

Malware.AI.2155910036 also known as:

tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Doina.30813
FireEyeGeneric.mg.a41c55d65a84d570
McAfeeArtemis!A41C55D65A84
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 0050718d1 )
K7GWAdware ( 0050718d1 )
Cybereasonmalicious.65a84d
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Trojanx-9951053-0
BitDefenderGen:Variant.Doina.30813
AvastFileRepMalware [Misc]
Ad-AwareGen:Variant.Doina.30813
SophosGeneric Reputation PUA (PUA)
ComodoPacked.Win32.MUPX.Gen@24tbus
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Doina.30813 (B)
GDataGen:Variant.Doina.30813
AviraPUA/Agent.ajq
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Tonmye.R443913
BitDefenderThetaGen:NN.ZexaF.34742.@pKfaaFSyuaH
ALYacGen:Variant.Doina.30813
MAXmalware (ai score=83)
VBA32BScope.Trojan.Fuerboos
MalwarebytesMalware.AI.2155910036
TrendMicro-HouseCallTROJ_GEN.R002H09F822
RisingTrojan.Tonmye!8.510 (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/CoinMiner.65CA!tr
AVGFileRepMalware [Misc]

How to remove Malware.AI.2155910036?

Malware.AI.2155910036 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment