Malware

What is “Malware.AI.2162319648”?

Malware Removal

The Malware.AI.2162319648 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2162319648 virus can do?

  • Creates RWX memory
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

Related domains:

hosting.freetoolss.com
shoponline123456789.blogspot.com

How to determine Malware.AI.2162319648?


File Info:

crc32: CB31442D
md5: bb3740d57933e38904aeca0ec7d78ba1
name: BB3740D57933E38904AECA0EC7D78BA1.mlw
sha1: 5ea7108d42115770ca608e41bb4ccd1f423d3094
sha256: 687be009150afc845e8c52056ccba389f328ed76459b3e2a37e3a9ec7b13c08d
sha512: 1d53f4d04b25dd2a690d0ae7a3196cf5136c48342f878079f44ea8be6eddd73ea39669d3bb9bb04dd61bc38be0845db0acc75f6955e170e9870ca016562ed36d
ssdeep: 49152:h25iWOXWlIIb6fMID2u41715Kqao5ZPbnk4uJnmcBVbqk4uJnmfIBGFmuYUabPx:h2cRXW++6fMIiL1J5KCjPbk4uJnmcB/
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: fLaSh
Assembly Version: 8.0.0.0
InternalName: SQLi v.8.5.exe
FileVersion: 8.0.0.0
CompanyName: SQLi Trush Corp
Comments: SQLi Dumper v8.0
ProductName: SQLi Dumper
ProductVersion: 8.0.0.0
FileDescription: SQLi Dumper v8.0
OriginalFilename: SQLi v.8.5.exe

Malware.AI.2162319648 also known as:

K7AntiVirusTrojan ( 005571e01 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader33.2025
CynetMalicious (score: 99)
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacGen:Variant.Razy.808283
CylanceUnsafe
ZillyaTrojan.Generic.Win32.1437512
SangforRiskware.Win32.Agent.ky
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/Bladabindi.be2bca07
K7GWTrojan ( 005571e01 )
Cybereasonmalicious.57933e
SymantecTrojan.Dropper!g4
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.EHR
APEXMalicious
AvastWin32:RATX-gen [Trj]
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Razy.808283
MicroWorld-eScanGen:Variant.Razy.808283
TencentWin32.Trojan.Generic.Pfsx
Ad-AwareGen:Variant.Razy.808283
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34266.5s0@a4Q6AHn
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DGT21
McAfee-GW-EditionGenericRXKE-OP!BB3740D57933
FireEyeGeneric.mg.bb3740d57933e389
EmsisoftGen:Variant.Razy.808283 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dldr.Agent.soikm
MicrosoftTrojan:MSIL/Bladabindi
ArcabitTrojan.Razy.DC555B
GDataGen:Variant.Razy.808283
AhnLab-V3Trojan/Win32.RL_Generic.C4007700
McAfeeGenericRXKE-OP!BB3740D57933
MAXmalware (ai score=88)
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.2162319648
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DGT21
YandexTrojan.Agent!8ziOkOZM5Yk
IkarusTrojan-Dropper.MSIL.Binder
MaxSecureTrojan.Malware.1728101.susgen
FortinetMSIL/Agent.FYL!tr.dldr
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml

How to remove Malware.AI.2162319648?

Malware.AI.2162319648 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment