Malware

Malware.AI.2179922140 (file analysis)

Malware Removal

The Malware.AI.2179922140 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2179922140 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid

How to determine Malware.AI.2179922140?


File Info:

name: 87E519998310EFED9B01.mlw
path: /opt/CAPEv2/storage/binaries/0cb3b4f26fcb89008e5ba48bb8de819569e158b89ce1e230d4d032bdd344a694
crc32: 9C20878A
md5: 87e519998310efed9b0108c29700efde
sha1: f654155632d5faec8cf851d8a78fd02bf466e8a0
sha256: 0cb3b4f26fcb89008e5ba48bb8de819569e158b89ce1e230d4d032bdd344a694
sha512: e2679b1fb42b86fa5ab3813aeeb6afbdb23ce4b2d34592d93df464a6ce5ac837abc650af13d68cd2adb0427ccda99286fdaff9617a4784617c3d3c1081e740f3
ssdeep: 6144:54Bl2gFpN5xpS1P2h+rWZZseuQ7/1yB6ycVo0MgCz6eBMEWvAdkhKNleXrGOkhXd:afS5wGWokXYO8NZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16B54CF367BACE552C2DC4378A4E341A04AF09A04F463E7AF540D79FA6B472DD0E1A35B
sha3_384: 0a5771fea926c7056771edb8d20a72c8d813825a075db4d5a8584eb26699d8f7f658f4ee30e5fadcdfb86d92f0d31015
ep_bytes: ff2500a04500e4163504000000850000
timestamp: 2022-02-04 11:16:59

Version Info:

0: [No Data]

Malware.AI.2179922140 also known as:

Elasticmalicious (high confidence)
ClamAVWin.Packed.Generic-7672855-0
FireEyeGeneric.mg.87e519998310efed
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
McAfeeTrojan-FLBY!87E519998310
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Heur.MSIL.Krypt.3
K7GWTrojan ( 7000001c1 )
K7AntiVirusTrojan ( 7000001c1 )
BitDefenderThetaGen:NN.ZemsilF.34182.suW@aWkvnPk
CyrenW32/MSIL_Kryptik.UV.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Bladabindi.LX
TrendMicro-HouseCallBKDR_BLADABI.SMC
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
MicroWorld-eScanGen:Heur.MSIL.Krypt.3
RisingBackdoor.Njrat!1.C5D1 (CLASSIC)
EmsisoftGen:Heur.MSIL.Krypt.3 (B)
TrendMicroBKDR_BLADABI.SMC
SophosML/PE-A + Mal/VMProtBad-A
IkarusTrojan.MSIL.Bladabindi
JiangminTrojan.Generic.gmiim
AviraHEUR/AGEN.1141326
MicrosoftBackdoor:MSIL/Bladabindi.BT!bit
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataMSIL.Backdoor.Bladabindi.BV
AhnLab-V3Trojan/Win32.RL_Crypt.C3982567
ALYacGen:Heur.MSIL.Krypt.3
MAXmalware (ai score=81)
MalwarebytesMalware.AI.2179922140
APEXMalicious
TencentWin32.Trojan.Generic.Ednx
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Bladabindi.LX!tr
AVGWin32:BackDoor-AFW [Trj]
Cybereasonmalicious.98310e
AvastWin32:BackDoor-AFW [Trj]

How to remove Malware.AI.2179922140?

Malware.AI.2179922140 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment